Privacy policy. This page is ready
HideIt; Checkout · Last updated 6 August 2026
HideIt; Checkout (“the app”) lets Shopify merchants hide, rename and reorder payment and delivery methods at checkout using rules they define. This policy explains what data the app accesses, what it stores, how long it keeps it and how to have it deleted.
The app is operated by Edition. For any privacy question or request, contact our support team.
The app stores only what it needs to authenticate with your store and to run the rules you configure:
myshopify.com domain, the API access tokens Shopify issues to the app (encrypted at rest), the access scopes you granted, and installation state. Used solely to make API calls to your own store.Rules are evaluated inside Shopify’s own checkout by Shopify Functions. Cart contents, customer attributes, addresses and order totals are read in Shopify’s infrastructure at checkout time and are never transmitted to, logged by, or stored on our servers.
The tag and collection lists you configure in your rules are passed to the checkout functions as part of their configuration, stored in app-owned metafields on the checkout customizations inside your store — not in our database. The app does not read or copy your product catalog or customer records; tag and collection membership is checked by Shopify itself at checkout time.
read_discounts — evaluate discount-based rule conditions.write_payment_customizations, write_delivery_customizations — create and manage the checkout customizations the app installs on your behalf, including the app-owned configuration metafields the checkout functions read.The app does not build customer profiles. It stores no customer names, email addresses, phone numbers, shipping addresses or order contents on its servers. Because no customer-level data is retained, a customers/data_request or customers/redact request from Shopify requires no export or erasure on our side — we acknowledge the request and hold nothing to return or delete.
The app subscribes to app/uninstalled and app_subscriptions/update (installation and plan state) and to Shopify’s three mandatory compliance topics. Every webhook payload is verified with an HMAC signature before it is processed.
Application servers and the managed PostgreSQL and Redis instances are hosted on DigitalOcean. Subscription billing is handled entirely by Shopify — the app never sees or processes your payment card details.
shop/redact request, at which point all remaining data for your shop — rules, conditions and rule counters — is deleted.Shopify access tokens and refresh tokens are encrypted at rest with AES-256-GCM. All traffic to the app is served over TLS. Incoming webhooks and storefront requests are authenticated with constant-time HMAC verification, and the embedded admin verifies a Shopify session token on every request.
Depending on where you are based you may have the right to access, correct, export or erase the personal data we hold about you, and to object to or restrict its processing. Since the data the app holds is limited to your store record and your own rule configuration, these requests are usually satisfied by uninstalling the app or by emailing support.
If this policy changes, we update this page and the “last updated” date above. Material changes affecting how merchant or customer data is handled will also be communicated in the app.
Last updated 6 August 2026