Privacy policy. This page is ready

Privacy policy

HideIt; Checkout · Last updated 6 August 2026

HideIt; Checkout (“the app”) lets Shopify merchants hide, rename and reorder payment and delivery methods at checkout using rules they define. This policy explains what data the app accesses, what it stores, how long it keeps it and how to have it deleted.

The app is operated by Edition. For any privacy question or request, contact our support team.

What we store

The app stores only what it needs to authenticate with your store and to run the rules you configure:

  • Store record — your myshopify.com domain, the API access tokens Shopify issues to the app (encrypted at rest), the access scopes you granted, and installation state. Used solely to make API calls to your own store.
  • Your rules — rule names, the payment or delivery methods they target, their conditions and values, priority and enabled state. This is configuration you author; it contains no personal data unless you type it into a rule yourself.
  • Aggregate rule counters — a daily count of how many times each rule matched, used for the analytics shown in the app. These counters contain no customer, cart or order identifiers.

What we access but never store

Rules are evaluated inside Shopify’s own checkout by Shopify Functions. Cart contents, customer attributes, addresses and order totals are read in Shopify’s infrastructure at checkout time and are never transmitted to, logged by, or stored on our servers.

The tag and collection lists you configure in your rules are passed to the checkout functions as part of their configuration, stored in app-owned metafields on the checkout customizations inside your store — not in our database. The app does not read or copy your product catalog or customer records; tag and collection membership is checked by Shopify itself at checkout time.

Access scopes and why we request them

  • read_discounts — evaluate discount-based rule conditions.
  • write_payment_customizations, write_delivery_customizations — create and manage the checkout customizations the app installs on your behalf, including the app-owned configuration metafields the checkout functions read.

Customer personal data

The app does not build customer profiles. It stores no customer names, email addresses, phone numbers, shipping addresses or order contents on its servers. Because no customer-level data is retained, a customers/data_request or customers/redact request from Shopify requires no export or erasure on our side — we acknowledge the request and hold nothing to return or delete.

Webhooks we subscribe to

The app subscribes to app/uninstalled and app_subscriptions/update (installation and plan state) and to Shopify’s three mandatory compliance topics. Every webhook payload is verified with an HMAC signature before it is processed.

Where data is processed

Application servers and the managed PostgreSQL and Redis instances are hosted on DigitalOcean. Subscription billing is handled entirely by Shopify — the app never sees or processes your payment card details.

Retention and deletion

  • When you uninstall the app, the stored store record — including your access tokens — is deleted immediately.
  • Roughly 48 hours after uninstall Shopify sends a shop/redact request, at which point all remaining data for your shop — rules, conditions and rule counters — is deleted.
  • You can request deletion of your data at any time by emailing support; we action such requests without undue delay.

Security

Shopify access tokens and refresh tokens are encrypted at rest with AES-256-GCM. All traffic to the app is served over TLS. Incoming webhooks and storefront requests are authenticated with constant-time HMAC verification, and the embedded admin verifies a Shopify session token on every request.

Your rights

Depending on where you are based you may have the right to access, correct, export or erase the personal data we hold about you, and to object to or restrict its processing. Since the data the app holds is limited to your store record and your own rule configuration, these requests are usually satisfied by uninstalling the app or by emailing support.

Changes to this policy

If this policy changes, we update this page and the “last updated” date above. Material changes affecting how merchant or customer data is handled will also be communicated in the app.

Last updated 6 August 2026