Privacy Policy
Privacy Policy
Section titled “Privacy Policy”This Privacy Policy explains how data is handled when merchants install and use the app and when customers submit support requests through app-powered support workflows.
By installing or using the app, or by submitting support requests through app-powered support surfaces, you acknowledge this Privacy Policy.
1. What this policy covers
Section titled “1. What this policy covers”This policy covers personal data processed through app features, including:
- storefront support request submissions,
- ticket conversations and replies,
- internal support operations (assignment, status changes, private notes, timeline events),
- customer and order context used to resolve support requests.
This policy does not replace Shopify platform policies and does not cover independent third-party processing outside enabled integrations.
2. Roles and responsibilities
Section titled “2. Roles and responsibilities”- Merchant (store owner): data controller for customer support data in the store context.
- App provider: data processor/service provider operating support workflows on behalf of the merchant.
- Agents: authorized users under the merchant account with role-based permissions.
3. Data categories processed
Section titled “3. Data categories processed”The app may process the following categories of data:
- Customer identity and contact data: customer ID, name, email (as available via Shopify APIs).
- Ticket data: ticket number, source, subject, description, status, priority, category, linked order reference, timestamps.
- Conversation data: public customer/agent messages and private internal notes/events used for support operations.
- Order context: linked order IDs and order references used in support handling.
- Agent account data: agent name, email, role, permission settings.
- Operational data: assignment changes, status transitions, workflow events, saved views/filter preferences.
- Technical/service data: session/authentication data, diagnostics, and operational logs needed for service reliability and security.
4. How data is used
Section titled “4. How data is used”Data is processed to:
- create and manage support tickets,
- send customer support updates and ticket-created notifications,
- route and assign tickets to agents,
- apply support workflows/macros and internal actions,
- provide support inbox views, filters, and reporting features,
- maintain traceability for security, dispute handling, and service integrity.
- comply with legal obligations and platform requirements.
5. Legal bases
Section titled “5. Legal bases”Depending on jurisdiction and use case, processing may rely on:
- contractual necessity,
- legitimate interests,
- legal obligations,
- and, where required, valid consent.
Merchants are responsible for determining and documenting the lawful basis applicable to their store operations.
6. Data sharing and subprocessors
Section titled “6. Data sharing and subprocessors”Data may be shared with service providers/subprocessors only where needed to operate the app and provide support functionality, including:
- Shopify platform APIs/infrastructure,
- hosting and infrastructure providers,
- email delivery/SMTP providers used for support notifications,
- operational service providers needed for reliability/security.
Data may also be disclosed when required by law, legal process, or to protect rights, safety, and service integrity.
7. Retention and deletion
Section titled “7. Retention and deletion”Data is retained only as long as reasonably required for support operations, security, dispute handling, fraud prevention, and legal compliance.
Merchants should define and document:
- retention periods by data type,
- deletion/anonymization rules,
- legal-hold exceptions where required.
Important implementation note:
- On app uninstall, access is revoked and session records are cleaned up.
- Deletion/redaction of support datasets is handled through privacy/compliance workflows (for example, customer redaction and shop redaction requests), where applicable.
8. Security controls
Section titled “8. Security controls”Security measures are designed to reduce risk and protect data, including:
- role-based permission controls for agents,
- separation of private internal notes from customer-visible replies,
- support-event/audit-style history records for key actions,
- controlled embedded app access patterns.
No system can guarantee absolute security. Merchants should maintain their own access, policy, and operational controls.
9. Privacy rights
Section titled “9. Privacy rights”Depending on applicable law, data subjects may have rights such as:
- access,
- correction,
- deletion,
- restriction or objection,
- portability.
Requests should include sufficient identifying information to verify identity and locate relevant records.
Where applicable, privacy requests can be handled through Shopify privacy/compliance mechanisms and/or the contact channel below.
10. Merchant obligations
Section titled “10. Merchant obligations”Merchants are responsible for:
- publishing compliant store-facing privacy notices,
- aligning support terms and privacy disclosures,
- configuring agent permissions appropriately,
- handling privacy rights requests in accordance with applicable law.
11. Children’s data
Section titled “11. Children’s data”The app is intended for business use by merchants and is not intended for direct use by children.
12. Changes to this policy
Section titled “12. Changes to this policy”This Privacy Policy may be updated from time to time. Updated versions are effective when posted unless a different date is stated.
13. Contact
Section titled “13. Contact”For privacy questions or requests related to the app, contact:
rockstarui.com/contact