Privacy Policy
Last Updated: October 10, 2026 • Effective Date: October 10, 2026
1. Introduction & Overview
CartShield: Checkout Rules & Validation ("CartShield", "we", "our", or "the App") is developed and operated by ModApps Development ("ModApps-Dev"). This Privacy Policy describes how we handle store, merchant, and customer data when you install and use the CartShield app on your Shopify store.
CartShield is built natively upon Shopify Functions (purchase.validation.run). Validation rules execute server-side in Shopify's WebAssembly sandbox. This zero-bloat architecture ensures our app never collects, stores, or sells personally identifiable customer information.
2. Information We Collect
We collect and process only the minimal store configuration data necessary to execute validation rules and provide merchant dashboard functionality:
- Merchant Store Identifiers: Store myshopify domain (e.g.
store.myshopify.com), access token (securely encrypted), and store owner contact email. - Rule Configurations: Validation rule definitions (such as PO Box regex patterns, target collections, SKU dependencies, minimum order amounts, and custom error messages) saved to Shopify Metafields.
- Aggregated Block Telemetry: Anonymized counts of validation events (e.g. total rules evaluated, total invalid orders intercepted) displayed on the merchant dashboard.
3. How Information Is Used
We use collected data solely for the following legitimate business purposes:
- Synchronizing merchant validation rules to store metafields for sub-5ms edge evaluation.
- Displaying rule management and validation logs in the Shopify Admin.
- Managing billing status and subscription tiers via Shopify's Recurring Application Charges API.
- Providing prompt merchant support and troubleshooting rule configurations.
4. Shopify Webhooks & Data Deletion Compliance
In accordance with Shopify's Mandatory Webhooks and Data Privacy standards, CartShield implements and responds automatically to all GDPR compliance endpoints:
customers/data_request: Generates reports if any customer-linked record exists (CartShield holds zero customer records).customers/redact: Purges any customer references within 48 hours.shop/redact: Immediately deletes all store sessions, rule records, and cached configs within 48 hours of app uninstall.
5. Data Retention & Security
All database connections are secured via TLS 1.3 encryption in transit and AES-256 at rest. Rule records are retained only for the duration of your app installation. Upon app uninstallation, all merchant configuration data is scheduled for permanent deletion within 48 hours.
6. Contact Us
If you have any questions or inquiries regarding our privacy practices or data handling, please contact our privacy compliance team:
Email: support@modapps.dev
ModApps Development • Amman & Global Operations