Privacy policy
What we collect, why, for how long, where it lives and how to reach us. Written to answer the questions Shopify asks of every app, in plain words.
Last updated: 19 September 2026
1. Who we are
Checkout Master is a Shopify app operated by Checkout Master, based in Taiwan (“we”, “us”). It adds blocks to a store's checkout, thank-you, post-purchase and customer account pages, styles the checkout, and hides or renames delivery and payment options at checkout.
This policy covers the app and this website. When you install the app on your Shopify store, you decide what data your store shares with us; we process it on your behalf and on your instructions. In the language of privacy law, you are the controller of your store's data and we are a processor. Shopify's own handling of your data is covered by Shopify's privacy policy.
2. Information from your store, through Shopify
When you install the app, Shopify gives us access to a limited set of your store's data. We ask only for what the features need, and Shopify shows you the full list before you approve the install. What we read and keep:
- Your store's identity and settings. Its
.myshopify.comaddress, name, contact email, plan, currency, timezone, primary language and country. Kept for as long as the app is installed. - Staff who use the app. When a staff member opens the app, Shopify tells us their name, email address, locale and whether they own the account, so the app can sign them in. We also record which staff member made each change to a block or rule, as an anonymous Shopify user ID that we cannot turn back into a name.
- Products, shipping settings, markets and checkout settings. Read when you build a block, a rule or a style, so the app can show you your own catalogue and shipping rates. We keep only the references you chose (for example, the product a block offers), not a copy of your catalogue.
- Checkout styling. Each time your checkout styling changes, in the app or in Shopify's checkout editor, we keep a snapshot so you can see the history and restore an earlier version.
- Orders, reduced to totals. To show you how an upsell block performs, Shopify sends us each new order. We keep only per-block daily counts: the number of orders, units and revenue, and the cost of goods at the time. We do not store the order, its ID or anything about the buyer. See section 4.
- Product and shipping changes. Shopify notifies us when a product is deleted, archived or set to draft, or when a shipping profile changes, so we can warn you when a block or rule stops working. We keep the warning, not the notification.
We read, and never store, a few more things while you use the app: the last 60 days of orders that contained an upsell, when you open that list on a block's analytics tab. They are shown on screen and forgotten.
3. Information you give us directly
- What you build. Blocks, rules and styles, with the names, text, images and settings you enter. Images are uploaded to your own Shopify Files, not to our servers.
- Support, feedback and feature requests. The message, the reply-to email address you give (pre-filled with your store's contact email), your store address and the page you sent it from. Sent to our support inbox and kept in our database so we can follow up.
- The onboarding survey. Optional answers about your experience with checkout apps, what you want from the app and where you heard about us, together with your store's plan, country and the category of products it mostly sells.
- Setup progress. Which quick start steps you have ticked on the home page, when you finished it, and whether you dismissed it. Three notes about the app's own screens; they say nothing about you or your buyers.
- Settings. Your language for the app and whether you want to be emailed when something stops working.
- Meetings and email. If you book a meeting or email us, what you send us is handled by Google Calendar and our email provider under their terms.
4. Information about your customers
Nothing a buyer does at checkout reaches our servers. Blocks are drawn by Shopify's checkout extension system and rules run inside Shopify as checkout functions. We hold no names, email addresses, phone numbers, addresses or payment details of your customers, and we have not asked Shopify for access to them: when Shopify sends us an order, those fields are already removed.
There are two places where a customer's own action produces something we keep:
- The post-purchase page, shown only after payment when you have a post-purchase block. The page asks our server for the offer and the survey, sending the buyer's language, the destination country and which products are in the order, so we can pick an offer that makes sense. It tells us when the offer or survey was shown, and when the offer was accepted. Each of those is recorded as a per-block daily count; the checkout's reference number is hashed so we can avoid double counting and cannot be used to find the order.
- Post-purchase survey answers. When a buyer submits the survey, we keep the option they chose and, if they picked “Other”, the text they typed, against the block and the hashed checkout reference. The answer is also written to the order in your Shopify admin, where it belongs to you. We do not keep who answered. If a buyer types personal details into the free-text field, we cannot connect them to a person, but the text is kept until you delete the block's answers or uninstall the app.
One block, the order note, writes what the buyer types into the note field of their own order in Shopify. That text goes to Shopify, not to us.
5. How we use it
- To run the app: sign in your staff, draw your blocks, apply your rules and styles, and keep them in sync with your store.
- To show you how your blocks perform, as daily totals.
- To warn you, in the app and by email, when a block or rule has stopped working.
- To answer your support requests and improve the app based on feedback and the onboarding survey.
- To send one goodbye email if you uninstall (section 9).
We do not sell data, share it with advertisers, build profiles of your customers, or use it to train machine-learning models.
6. How long we keep it
| What | Kept until |
|---|---|
| Staff sign-ins | The app is uninstalled, then deleted immediately. |
| Blocks, rules, styles, style history, analytics counts, survey answers, warnings, activity history, settings, onboarding answers and setup progress | 48 hours after uninstall, when Shopify asks us to erase the store. Reinstalling within those 48 hours keeps everything as it was. |
| Support and feedback messages | Database copy: erased with the store, as above. The copy in our support mailbox is kept so we can refer back to past conversations; ask and we will delete it. |
| Post-purchase survey answers | Erased with the store, or earlier when you delete the block. |
| Server logs | Our hosting provider keeps request logs for a short period, typically days, for debugging. They contain your store address, and for the post-purchase page the buyer's IP address, which their browser sends when it asks our server for the offer or the survey. We do not read those logs for anything but debugging and never link an address to a person or an order. |
7. Where it is stored and who helps us process it
The app and its database run in Singapore. We use these providers to run the service; each is bound by its own terms and processes data only to provide its service to us:
| Provider | What for | Where |
|---|---|---|
| Shopify | The platform the app runs on; source of all store data | Global |
| Fly.io | Application hosting and logs | Singapore |
| Neon | Postgres database | Singapore (AWS ap-southeast-1) |
| Resend | Sending the emails described in section 9 | United States |
| Cloudflare | Hosting this website and its request logs | Global edge network |
| Google (Gmail, Calendar) | Our support inbox and meeting bookings | Global |
We are not established in the European Union or the United Kingdom. If your store is in the EU, the UK or another region that restricts where personal data may be sent, installing the app transfers your store's data to Singapore and to the providers above. Where a legal safeguard for such a transfer is required, we rely on the standard contractual clauses and on the data-processing terms in Shopify's Partner Program Agreement. Contact us if you need a signed data-processing agreement.
8. Your rights, and your customers' rights
Depending on where you are, you may have the right to access, correct, delete or restrict the use of personal data about you, to receive a copy of it, or to object to how it is used. Email us (section 12) and we will answer within 30 days. You can also delete everything we hold by uninstalling the app: it is erased 48 hours later.
For your customers, Shopify passes requests to us automatically. When a customer asks your store for their data or for erasure, Shopify notifies every app the store uses. Because we hold no data that identifies a customer, our answer to both is that there is nothing to return and nothing to erase. Survey answers are kept without any link to the person who wrote them, so they cannot be found by name, email or order; if you want a specific answer removed, tell us the block and the approximate time and we will remove it.
If you believe we have not handled your data properly, you can complain to the data protection authority in your country. We would appreciate the chance to help first.
9. Emails we send
- Warnings when a block or rule has stopped working, sent to your store's contact email. Switch them off in the app's settings.
- Replies to your support, feedback and feature requests.
- One goodbye email when you uninstall, to your store's contact email, asking what we could have done better. It is sent once and never followed up.
We send no newsletters and no marketing beyond that goodbye email, and we never email your customers.
10. This website
This site sets no cookies of its own, runs no analytics and does no tracking. If you pick a language from the dropdown, that choice is stored in your browser (in localStorage) so you land on the right language next time; it never leaves your device. Cloudflare, which hosts the site, keeps standard request logs.
The “Book a meeting” button opens Google’s booking page in a window on top of ours. Nothing loads from Google until you click it; once it is open, Google may set its own cookies inside that window under its own terms.
11. Changes to this policy
When we change what we collect or how we use it, we update this page and its date. For changes that affect you materially, we will also tell you inside the app. Earlier versions are available on request.
12. Contact
Questions, requests about your data, or anything else: [email protected]. A real person reads every message and aims to reply within one day.