Privacy Policy
Effective August 19, 2026
Ecom Upsell Cross sell helps Shopify merchants configure product, cart, and post-purchase upsell offers. The app stores merchant configuration, limited order and refund attribution identifiers, and aggregate performance data without building customer profiles or retaining buyer identity or contact details.
Information we process
- Merchant store information needed to install and operate the app, including the myshopify.com domain, installation state, granted scopes, settings, and encrypted Shopify access tokens.
- Upsell configuration selected by the merchant, including Shopify product and variant identifiers, placement, discount, schedule, status, and priority.
- Aggregate storefront events such as offer views and add-to-cart counts, with short-lived event identifiers used only to prevent duplicate counting.
- Shopify order, order-line, refund, product, variant, quantity, currency, amount, and timestamp data needed to make attribution and refunds idempotent and calculate aggregate performance. Order, order-line, and refund identifiers are retained for those purposes. Privacy webhooks temporarily queue requested order identifiers until processing completes. Customer IDs, buyer names, email addresses, telephone numbers, postal addresses, raw order payloads, IP addresses, and payment data are not stored.
- Information a merchant voluntarily sends when requesting support.
How we use information
We use this information to authenticate merchants, operate and secure the app, publish offers and discounts, enforce plan limits, calculate aggregate analytics, answer support requests, and meet legal obligations. We do not sell personal information or use app data for advertising.
Storefront and customer data
Storefront events contain only offer, revision, placement, and aggregate event information. They are not used to identify shoppers across visits or stores. Shopify order access is used only to attribute upsell line items and calculate aggregate revenue.
Retention
- Raw storefront deduplication events are retained for 7 days.
- Daily aggregate metrics and the supporting order, order-line, and refund attribution records are retained for up to 30 days on Free and up to 24 months on Pro. Customer data request exports are retained for 30 days. Privacy jobs retain requested raw order identifiers only until processing completes. Keyed, non-reversible order tombstones are retained without raw order identifiers until shop deletion to prevent delayed webhooks from recreating redacted records.
- Merchant settings and offer configuration are retained while the app is installed and for any period required by applicable law.
- Operational logs and error traces are retained for up to 30 days and are configured without customer personal information.
When the app is uninstalled, its local access token is invalidated, scheduled processing and Shopify API calls for that store stop, and data is deleted or anonymized under Shopify privacy webhooks and applicable retention obligations.
Service providers and transfers
Shopify provides the commerce platform, authentication, APIs, theme editor, and billing surfaces. Cloudflare provides application hosting, database, network, and security infrastructure. These providers process data under their own contractual and security commitments and may process it in multiple jurisdictions.
Security
Cloudflare D1 encrypts stored data at rest and protects data in transit with TLS. Shopify access and refresh tokens are additionally encrypted with application-layer AES-GCM. Administrative requests require Shopify authentication, webhook signatures are verified, and access is limited to data needed to operate the app. No storage or transmission method can guarantee absolute security.
Privacy requests
Shopify sends mandatory customer data request, customer redaction, and shop redaction webhooks to the app. Customer data request exports are available to authenticated merchant admins on the in-app Support page for 30 days. Customer redaction deletes stored records linked to the Shopify order IDs supplied in the webhook and recalculates affected aggregates. For other access, correction, or deletion requests, use the support options in Shopify Admin. Never send access tokens or customer personal data through support.
Changes and contact
We may update this policy when the app, legal requirements, or service providers change. The effective date identifies the latest version.
Open Shopify Admin and search for the app named exactly Ecom Upsell Cross sell.
Open Shopify Admin