CartShield Logo CartShield Shopify App Privacy Policy

Privacy Policy

Last Updated: October 10, 2026 • Effective Date: October 10, 2026

1. Introduction & Overview

CartShield: Checkout Rules & Validation ("CartShield", "we", "our", or "the App") is developed and operated by ModApps Development ("ModApps-Dev"). This Privacy Policy describes how we handle store, merchant, and customer data when you install and use the CartShield app on your Shopify store.

CartShield is built natively upon Shopify Functions (purchase.validation.run). Validation rules execute server-side in Shopify's WebAssembly sandbox. This zero-bloat architecture ensures our app never collects, stores, or sells personally identifiable customer information.

2. Information We Collect

We collect and process only the minimal store configuration data necessary to execute validation rules and provide merchant dashboard functionality:

  • Merchant Store Identifiers: Store myshopify domain (e.g. store.myshopify.com), access token (securely encrypted), and store owner contact email.
  • Rule Configurations: Validation rule definitions (such as PO Box regex patterns, target collections, SKU dependencies, minimum order amounts, and custom error messages) saved to Shopify Metafields.
  • Aggregated Block Telemetry: Anonymized counts of validation events (e.g. total rules evaluated, total invalid orders intercepted) displayed on the merchant dashboard.
Privacy Guarantee: CartShield does NOT store customer credit card numbers, payment tokens, phone numbers, or residential addresses on any third-party external server. Address evaluations occur ephemerally in Shopify's memory during the checkout validation function run.

3. How Information Is Used

We use collected data solely for the following legitimate business purposes:

  • Synchronizing merchant validation rules to store metafields for sub-5ms edge evaluation.
  • Displaying rule management and validation logs in the Shopify Admin.
  • Managing billing status and subscription tiers via Shopify's Recurring Application Charges API.
  • Providing prompt merchant support and troubleshooting rule configurations.

4. Shopify Webhooks & Data Deletion Compliance

In accordance with Shopify's Mandatory Webhooks and Data Privacy standards, CartShield implements and responds automatically to all GDPR compliance endpoints:

  • customers/data_request: Generates reports if any customer-linked record exists (CartShield holds zero customer records).
  • customers/redact: Purges any customer references within 48 hours.
  • shop/redact: Immediately deletes all store sessions, rule records, and cached configs within 48 hours of app uninstall.

5. Data Retention & Security

All database connections are secured via TLS 1.3 encryption in transit and AES-256 at rest. Rule records are retained only for the duration of your app installation. Upon app uninstallation, all merchant configuration data is scheduled for permanent deletion within 48 hours.

6. Contact Us

If you have any questions or inquiries regarding our privacy practices or data handling, please contact our privacy compliance team:

Email: support@modapps.dev

ModApps Development • Amman & Global Operations