Privacy Policy

Last Updated: August 3, 2026

This Privacy Policy describes how Bravas Checkout Customizer (the “App”) collects, uses, and discloses your personal information when you install or use the App in connection with your Shopify-supported store (the “Merchant Store”).

By installing the App, you agree to the collection and use of information in accordance with this policy. For the purposes of this Privacy Policy, “you” refers to the merchant installing the App, and “customers” refers to the end-users shopping at the merchant’s store.

1. Information We Collect from Merchants

To provide, configure, and maintain the App’s capabilities on your store, we collect and store the following merchant information:

  • Shopify Account Details: Shop domain, store owner name, email address, physical address, phone number, and plan type (Regular or Shopify Plus).
  • App Configuration Settings: Data you input into the App dashboard to set up widgets (e.g. Announcement Bar, Reward Bar, Custom Fields, Cart Attributes, Trust Badges, Social Icons).
  • Access Credentials: Shopify API access tokens that allow the App to read/write specific data layers in accordance with the permissions granted upon installation.

2. Information We Access/Process from Your Customers

The App operates on the checkout, thank-you, and order-status pages of your store. To render widgets dynamically and run server-side order validations, we access the following Customer data through Shopify’s APIs:

  • Checkout and Cart Data: Cart contents, total weight, total order price, currency, and line-item prices (used to evaluate validation rules and calculate progress targets for the Reward Bar).
  • Customer Profile Attributes: Customer tags, default shipping address country/state/zip code (used to evaluate display conditions, address restrictions, and customer gates).
Note on Customer Privacy: The App does NOT persist or store any personally identifiable information (PII) of your customers (such as their full names, detailed home addresses, phone numbers, or payment credentials) on our database servers. This data is only processed transiently in-memory to execute the checkout widgets and validation rules.

3. Usage & Analytics Collection

We collect aggregated, non-personally identifiable analytical data when customers interact with checkout widgets on your storefront:

  • Widget Impressions: The number of times a custom checkout widget is loaded and viewed.
  • Widget Clicks/Actions: Clicks on call-to-action buttons, upsell products, or applied discount codes to compile conversion rate metrics for your merchant dashboard.

4. Purpose of Data Processing

We use the collected and accessed information for the following business purposes:

  • To render, execute, and display customized checkout blocks, upsells, and widgets on the checkout flow.
  • To enforce merchant-defined validation rules (e.g. age verification checks, zip code address restrictions, and item limit checks) before payment completion.
  • To compile conversion analytics reports showing how widgets perform.
  • To manage subscriptions and process billing charges via Shopify’s Billing API.
  • To provide customer support and troubleshoot installation issues.

5. Data Retention & Automatic Store Pruning

We enforce strict data minimization principles. If you decide to uninstall the App:

  • 48-Hour Deletion (2-Day Rule): We automatically trigger a background cleanup worker that permanently purges your store credentials, database sessions, configurations, and analytical logs from our servers within 2 days.
  • All associated database records will be irreversibly erased from our SQLite databases and active system replica nodes.

6. Third-Party Data Disclosures

We value your privacy and do not sell, trade, or rent your store data or customer information to third-party marketers. Data is only shared with our infrastructure subprocessors required to maintain app availability:

  • Fly.io Inc.: Our hosting and infrastructure provider. All application instances and database replicas are safely housed in secure, isolated containers managed via Fly.io.

7. Shopify GDPR Mandatory Webhooks

The App fully complies with Shopify’s mandatory GDPR compliance requirements. Our systems process Webhooks as follows:

  • Customer Data Request (`customers/data_request`): Since the App does not store customer profile records or personal details on its database, we do not hold any personal data to return. We will confirm this immediately to Shopify upon request.
  • Customer Data Deletion (`customers/redact`): Since we do not retain customer personal records, no manual redacting is necessary. Any transient session cache is cleared automatically.
  • Shop Data Deletion (`shop/redact`): Upon uninstallation, all store data is automatically deleted within 2 days as described in Section 5. Any incoming shop redaction webhook will be resolved with a confirmation of deletion.

8. Legal Rights (GDPR & CCPA)

Depending on your location, you may have rights under the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA) to access, correct, or permanently delete the personal data we hold about you as a merchant. You can exercise these rights by contacting us directly.

9. Cookies and Local Storage

We use session tokens and local storage inside your Shopify Admin dashboard area to authenticate your merchant session and persist your settings while you customize checkout. We do not drop tracking cookies, advertising pixels, or local storage items on your store’s customer-facing checkout page.

10. Minors

The App is designed and intended for use by merchants, and is not directed at children. We do not knowingly collect personal information from individuals under the age of 18.

11. Contact Us

If you have any questions, comments, or requests regarding this Privacy Policy, please contact us:

  • Email: support@bravas.io
  • Support: Live Chat inside the App Admin Dashboard
  • Address: Bravas App Team, Tokyo, Japan