Privacy policy
Who we are and what this policy covers
Gift Receipt ("the app," "we," "us") is a Shopify application that lets a merchant send a gift receipt by email to the person who receives a gift order. This policy explains what personal information the app handles, why it handles it, and what choices merchants and gift recipients have.
Gift Receipt is operated by Gift Receipt LLC, an Illinois limited liability company. Contact details are at the end of this policy.
The app takes a data minimization approach. It collects the categories of personal information described below and uses them for the purposes listed below.
Our role, and the merchant's role
For personal information about a merchant's customers, including gift recipients, the merchant is the controller of that information and the app acts as a processor on the merchant's instructions. For information about the merchant's own account, we act as the controller. This distinction matters for where an individual should direct a request, and is explained under "Requests and rights" below.
The personal information the app handles
Information read from Shopify
When a merchant installs Gift Receipt, the app requests access to order and fulfillment data through Shopify's official APIs. Where an order has been marked as a gift, the app reads:
- the gift recipient's email address, and their name where the buyer provides one
- the name the buyer chose to sign the gift with, and any gift message the buyer wrote
- the items on the order and the order number
- the order's fulfillment and delivery status
Shopify classifies this as protected customer data, and the app operates under Shopify's requirements for handling it.
The app does not receive payment card numbers or other payment credentials.
Information the merchant provides
- the store name, domain, and contact email associated with the installation
- settings the merchant chooses, such as a logo image address, an accent color, the address of the merchant's own returns or exchange page, a customer service email address, and the address of the merchant's own newsletter signup page with a short message shown beside it
Tracking technologies
The app does not use cookies, pixels, or similar tracking technologies to identify or follow visitors, on a merchant's storefront or in the Shopify admin, apart from the session cookies Shopify requires for an embedded app to function. It sets no cookie of its own, stores no visitor identifier, and keeps no record of an individual visit.
Where the gift option is displayed, the app records that it was displayed, as a running total for that store, that day, and that place on the store. The request that does this carries nothing but the name of the place the option appeared. Nothing about the visitor is sent, stored, or derived, and the resulting count cannot be traced back to a person, a session, or a device. A shopper's browser is asked to remember, for the duration of their visit, that the option has already been counted once, so that reloading a page does not count it again; that is a single value in the browser's own temporary storage, it is never read by us, and it leaves nothing behind after the visit.
How the app uses this information
Gift recipient information is used to send one transactional email, the gift receipt, when the order reaches a delivered status, or a set number of days after fulfillment if no delivery status is reported.
Order information is used to apply a "Gift" tag to gift orders in the merchant's Shopify admin so the merchant can identify them, and to list gift orders inside the app so the merchant can see whether a receipt has been sent.
Merchant information is used to operate the merchant's account, provide support, and administer billing.
The gift receipt email is designed to show the sender's name, the order number, and the items, and to omit pricing information, so that the recipient is not shown what the gift cost.
Gift receipt emails are transactional. We do not add gift recipients to a merchant's marketing list, or to any marketing list of our own, unless the recipient expressly opts in. Where an opt-in is offered, the recipient's consent is recorded.
We do not use personal information for targeted advertising, remarketing, or profiling, and we do not carry out automated decision-making that produces legal or similarly significant effects.
Service providers
To operate the service, personal information is shared with the providers below, each processing it on our instructions and under contract:
- Resend, our email delivery provider, receives the gift recipient's email address and the contents of the gift receipt, in order to deliver that email.
- Railway, our application hosting and database provider, stores the application data described under "What is stored" below.
- Shopify is the platform the app runs on and the source of the order data described above.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Personal information may also be disclosed where necessary to comply with applicable law, to respond to a lawful request such as a subpoena or court order, or to establish, exercise, or defend legal claims.
What is stored, and for how long
The app's own database stores merchant authentication sessions, merchant settings, and order-level records used to track whether a gift receipt has been sent for a given order, which is what prevents a duplicate email. The merchant settings are a logo image address, an accent color, the address of the merchant's own returns or exchange page, a customer service email address, and the address of the merchant's own newsletter signup page with a short message of up to 50 characters. The order-level records hold the store's domain, an order reference, and timestamps.
Where a merchant supplies a customer service email address, that address is also used as the reply-to address on gift receipt emails, so that a recipient who replies reaches the merchant rather than us.
Where a merchant supplies a newsletter signup address, the gift receipt email invites the recipient to sign up on the merchant's own page. The link is exactly the address the merchant entered. The app adds nothing about the recipient to it, not their email address, their name or the order number, and does not record whether the recipient follows it. A recipient who chooses to sign up gives their details directly to the merchant, or to the merchant's mailing list provider, under that merchant's own privacy policy. The app never adds a gift recipient to any mailing list.
The app's database does not store gift recipients' contact details. The recipient's email address, the name the buyer signed the gift with, and the gift message are read from the Shopify order at the time the gift receipt is sent, and are not copied into the app's database.
Where a buyer supplies gift details at checkout, those details are saved to the order in the merchant's own Shopify store, where they remain under the merchant's control and subject to the merchant's retention practices.
Order-level records are deleted 90 days after the gift receipt is sent, on an automated schedule.
The app also keeps a small monthly summary for each store, so that a merchant can compare one trading period against another beyond the 60 days of order history Shopify makes available to apps. Each summary is a single row per store per calendar month, holding only the store's domain, the month, order and gift-order counts, order and gift revenue totals, and the store's currency. It contains no order references and no personal data of any kind, and therefore identifies no individual. Because of that, these summaries are kept for as long as the app remains installed rather than being deleted at 90 days, and they are deleted when Shopify sends a shop redaction request.
The app also keeps a count of how often the gift option was shown to shoppers, so that we can tell whether the option is appearing on a store at all, and support a merchant whose installation is not working as expected. Each row is a single per-store, per-day, per-location tally, holding only the store's domain, the date, the name of the place the option appeared, and a whole number. It holds no order reference, no customer or recipient information, and no identifier of any kind for the person whose visit was counted, and therefore identifies no individual. Because of that, these counts are kept for as long as the app remains installed rather than being deleted at 90 days, and they are deleted when Shopify sends a shop redaction request.
Merchant account information is retained while the app remains installed, and is deleted on request or when Shopify sends a shop redaction request.
Application logs may contain limited operational information, including order references, and are retained by our hosting provider under its own retention period.
Requests and rights
Shopify's mandatory privacy requests
The app implements Shopify's required privacy webhooks. When Shopify sends a customer data request, a customer redaction request, or a shop redaction request, the app responds and deletes or reports the relevant data as required.
Individual requests
Because the app processes a merchant's customer data on that merchant's behalf, a gift recipient's request is usually best directed to the store the order was placed with, and we will assist that merchant in responding. An individual may also contact us directly, using the details at the end of this policy, and we will route the request appropriately.
Europe and the United Kingdom
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have the right to access the personal information held about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. You also have the right to lodge a complaint with your local supervisory authority.
We process personal information in order to perform a contract with a merchant, and on the basis of our legitimate interest in operating and supporting the app, and the merchant's legitimate interest in serving its customers.
Personal information may be transferred to and stored in the United States, where our hosting and email providers operate.
California
If you are a California resident, you may have the right to know what personal information is collected about you and how it is used and disclosed, to request its deletion or correction, and not to be discriminated against for exercising those rights. As stated above, we do not sell personal information and do not share it for cross-context behavioral advertising.
Security
Personal information is encrypted in transit and at rest, access to production systems is restricted to authorized personnel, and test and production environments are kept separate. Our Data Protection and Security Practices document describes these measures in more detail and is available on request.
No system can be guaranteed completely secure, and we cannot warrant the security of information transmitted to us.
Children
The app is provided to merchants for business use and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time to reflect changes to our practices, operational updates, or legal or regulatory requirements. Updates will be posted at this address and the "Last updated" date above will be revised. Where a change is material, we will take reasonable steps to notify merchants.
Contact
Questions about this policy, or about personal information the app handles:
Email: hello@giftreceipt.app
Postal:
Gift Receipt LLC
1 N 1st St, 7th Fl
Phoenix, AZ 85004
United States