Scope
This policy explains how PDPKit processes information when a merchant installs, opens, subscribes to, or requests support for the PDPKit Shopify app. It does not replace Shopify's own privacy terms for information Shopify controls.
Information PDPKit processes
- Shopify shop identity and lifecycle information, including the shop's
myshopify.comdomain and installation or uninstallation timestamps. - OAuth session information supplied by Shopify and required to authenticate the app. Depending on the session Shopify issues, this can include an access credential, expiry and scope metadata, locale, and basic authorized-user fields.
- Subscription and entitlement information, including normalized plan, billing interval and status, and synchronization times.
- Standard service and security metadata processed by the hosting stack, such as request time, requested route, HTTP status, network address, and diagnostic error details. Operational error events can be associated with the Shopify shop domain so a failed installation or billing synchronization can be diagnosed.
- Information a merchant voluntarily includes in a support request relayed by Shopify to PDPKit's support mailbox.
Information PDPKit does not request
PDPKit requests zero Shopify Admin data scopes. It does not request or copy product, order, customer, inventory, theme-file, or checkout data through the Shopify Admin API. Block content and visual settings remain in Shopify Theme Editor rather than the PDPKit application database.
How information is used
The limited information above is used to authenticate merchants, maintain installation state, verify Shopify-hosted subscriptions, enforce plan access, keep the service secure, diagnose failures, and respond to support requests. PDPKit does not sell personal information or use it for third-party advertising.
Service providers and disclosure
Information is processed through Shopify to provide app authentication, installation, theme settings, and subscriptions; through DigitalOcean to host the application and database in New York, United States, and to process associated network and operational logs in connection with hosting; and through the email provider that receives support messages relayed by Shopify. Information may therefore be processed outside a merchant's country. It may also be disclosed when required by law, to protect rights or service security, or as part of a business transfer subject to appropriate safeguards.
Retention and security
Installation and billing records are kept while the app is installed and until Shopify's post-uninstall shop-redaction request is processed. Active Shopify sessions are removed when PDPKit receives and processes an app-uninstalled webhook. When PDPKit authenticates and processes Shopify's subsequent mandatory shop-redaction request, it deletes the shop's remaining session, installation, and normalized billing records. Support correspondence is retained only as needed to handle the request and meet security or legal obligations. PDPKit does not configure long-term forwarding or a separate archive of DigitalOcean runtime logs; those logs remain subject to the hosting provider's standard transient availability. PDPKit uses access controls and encrypted network transport, but no internet service can promise absolute security.
Cookies and local storage
Shopify and the embedded application stack may use cookies or browser storage that are necessary for authentication, security, and app operation. An evergreen countdown block may save its end time in that visitor's browser session storage for the current browser session; PDPKit does not send that value to its backend. PDPKit storefront scripts do not load third-party advertising or analytics resources.
Requests and policy changes
To request access, correction, or deletion, use Shopify's Get support action for PDPKit and begin the subject with "Privacy request". Do not include customer or confidential information in the initial message. PDPKit will arrange an appropriate verification channel when needed. Material policy updates will be posted on this page with a revised effective date.
Read the support and privacy-request instructions