No Big Suite

Stackproof Bundles

Data practices

Stackproof stores the minimum merchant installation data needed to authenticate the embedded app and reject duplicate webhooks. It does not retain customer or order payloads.

This technical disclosure describes the current implementation. It is not the publisher's legal privacy policy.

At a glance

Personal data stored
Yes — see the exact records below.
Uninstall behavior
Product-owned records are deleted on uninstall.
External egress
Runtime data stays between the Shopify APIs and the app's Cloudflare Worker and D1 database. No additional analytics or advertising service receives it.

Shopify installation sessions

Purpose
Authenticate a shop and, for online sessions, its associated Shopify user.
Location
Cloudflare D1
Retention
Shop domain, OAuth token, scopes, and optional Shopify user identifier remain for the active installation and are deleted on uninstall or shop-redaction.

Webhook replay receipts

Purpose
Prevent the same signed webhook from being processed twice.
Location
Cloudflare D1
Retention
Webhook identifier, topic, and shop domain expire after 24 hours.

Offer rules

Purpose
Configure bundle, volume, and gift behavior for Shopify Functions.
Location
Shopify-owned app metafields
Retention
Rules follow the Shopify installation and metafield lifecycle; Stackproof does not copy them into D1.