Cruxtab Cart Gifts

Privacy Policy

Last updated: 2 September 2026 · Effective: 2 September 2026

Cruxtab Cart Gifts (“the App”) is a Shopify app that adds a cart drawer, gift and reward progress bars, volume discounts, upsells and bundles to a merchant’s online store. This policy explains what data the App collects, why it collects it, who it is shared with, how long it is kept, and how to have it deleted.

The short version. The App stores the merchant’s store settings and offer configuration, plus aggregate performance events for those offers. It does not collect shopper names, email addresses, phone numbers, shipping addresses or payment details, it does not build profiles of individual shoppers, and it never sells or rents data or uses it for advertising.

1. Who we are

The App is built and operated by Cruxtab (“we”, “us”, “our”), the data controller for the purposes described below. You can reach us at [email protected].

This policy covers the App only. It does not cover the merchant’s own storefront, Shopify’s platform, or any other app installed on the same store — each of those has its own privacy policy.

2. Our role: controller and processor

3. What we collect

3.1 Store and merchant account data

Received from Shopify when the App is installed and while it is in use:

3.2 Store catalogue data

The App requests read-only access to products. When a merchant selects a product, variant or collection for a gift, upsell, bundle or discount rule, we store its Shopify ID together with a copy of its title and image URL, so the admin screens and the storefront can render without an extra API call. We never write to, modify or delete catalogue data.

3.3 Merchant-authored configuration

Everything the merchant sets up in the App: cart drawer appearance and copy, reward tiers and thresholds, volume discount rules, upsell and bundle rules, announcement and terms text, custom CSS, and support widget settings.

3.4 Order data

The App subscribes to Shopify’s orders/create webhook so it can tell the merchant which orders its offers actually influenced. From each order payload we read and retain only:

FieldWhy
Order IDDe-duplicating conversion events
Order total and currencyAttributed revenue reporting
Line item variant IDsMatching against configured gifts and upsells
Discount titlesRecognising discounts created by the App

Customer name, email address, phone number, billing and shipping address, and payment information are present in that payload but are not read, stored or logged by the App.

Order access is classified by Shopify as protected customer data and is granted to the App only after Shopify’s own approval process. The same webhook keeps the order counter shown on the App’s billing page up to date.

3.5 Storefront performance events

When a shopper interacts with the cart drawer or an offer, the App may record an aggregate event: an impression, a reward unlock, an add-to-cart, a discount redemption, or a conversion. Each event holds the event type, which feature and rule produced it, an optional monetary value and currency, an anonymous Shopify cart token used to group one shopping session into a funnel, and a timestamp.

These events are not linked to a named person and are not used to profile, re-target or track shoppers across sites. Sending is subject to consent — see section 7.

3.6 Billing data

Subscriptions are handled entirely by Shopify’s Billing API. We store the Shopify charge ID, plan, subscription status and period dates. We never see or store card numbers or any other payment credentials.

3.7 Technical logs

Our servers keep short-lived operational logs (request paths, timestamps, error traces, webhook receipts) for security, debugging and abuse prevention.

4. What we do not collect

We do not sell, rent or share personal information for cross-context behavioural advertising, and we do not use merchant or shopper data to train machine learning models.

5. How we use the data

The App checks Shopify’s Customer Privacy API before sending any storefront event. If analytics processing has not been allowed for that visitor, nothing is sent, and anything queued before a refusal is discarded rather than transmitted. Consent is re-checked when a shopper answers a consent banner. Where the Customer Privacy API is not present at all, no consent framework is active for that visitor’s region and events are sent — mirroring how Shopify’s own surfaces behave.

Conversions are recorded server-side from Shopify’s order webhook rather than from the browser, so that figure stays accurate regardless of ad blockers or analytics consent. That record contains only the order fields listed in section 3.4.

8. Cookies and browser storage

The App sets no advertising or tracking cookies. On the storefront it uses the browser’s own sessionStorage and localStorage for strictly functional purposes, and that data stays in the shopper’s browser:

In the Shopify admin, the App relies on Shopify’s own session cookies for authentication.

9. Sharing and sub-processors

We share data only with the providers needed to run the service:

ProviderPurpose
Shopify Inc.Platform, authentication, product and order APIs, billing
MongoDB AtlasManaged database hosting for App data
Our hosting providerRunning the App servers
Merchant-chosen support widget Loaded only if the merchant configures one in Settings; that vendor’s own privacy policy then applies

We may also disclose data where required by law, or as part of a merger or acquisition — in which case this policy continues to apply until it is replaced and you are notified.

10. International transfers

Data may be processed in countries other than your own. Where data leaves the UK or EEA, transfers are covered by an adequacy decision or by Standard Contractual Clauses with the provider concerned.

11. Retention and deletion

A merchant can request deletion at any time, without waiting for the uninstall window, by writing to [email protected].

12. Security

Data is transmitted over TLS and stored in a managed database with access restricted to the people who need it to operate the service. Shopify webhooks are verified by HMAC signature before being processed, and admin requests are authenticated with Shopify session tokens. The App requests the narrowest set of Shopify permissions it can work with: product access is read-only, and the only write scope is the one needed to create the discounts that make rewards apply at checkout.

No system is perfectly secure. If a breach affecting personal data occurs, we will notify affected merchants and the relevant supervisory authority as required by law.

13. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. Residents of California and similar jurisdictions have rights to know, delete, correct, and to opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined. We do not discriminate against anyone for exercising a right.

If you are in the UK or EEA and believe we have not handled your data properly, you may complain to your local data protection authority.

14. Children

The App is a business tool for merchants and is not directed at children. We do not knowingly collect personal data from anyone under 16.

15. Changes to this policy

We may update this policy as the App changes. The “last updated” date at the top reflects the most recent revision. Where a change materially affects how we handle personal data, we will notify merchants in the App or by email before it takes effect.

16. Contact us

Questions, requests or complaints about this policy or about data the App holds:

Cruxtab
Email: [email protected]
App: cart-gifts.cruxtab.com