Privacy Policy
Stickdeal ("we", "our", "the app") is a Shopify app published by The Click Collective that helps merchants run volume, companion and bundle deals (Quantity Discount, Add & Save and Bundle Builder) with configurable storefront widgets.
_Last updated: September 21, 2026_
1. Overview
This Privacy Policy describes how Stickdeal collects, uses, stores, and protects information when you install and use the app on your Shopify store. By installing the app you agree to the practices described below.
We have built Stickdeal to be data-minimal by design: we do not collect, store, or process personal data belonging to your store's shoppers, beyond the aggregate order totals described in section 2.2, which carry no shopper identifiers.
2. Information We Collect
2.1 Store information (merchant data)
When you install Stickdeal, we collect:
- Shop identifier: your
.myshopify.comdomain - Shop contact email (when available): used only for support communication
- Shopify session and access token: stored encrypted at rest so we can call Shopify Admin APIs on your behalf
2.2 Configuration data
Information you create inside the app:
- Offer configuration (quantity discount / Add and save settings, targeting, status, sync state)
- Widget style tokens (layout, colors, copy, and related look settings)
- Billing subscription snapshots (plan name, status, Shopify charge identifiers) needed to enforce plan limits
- Operational audit events (for example plan-enforcement actions)
- Attributed order aggregates (order id, order name, order total treated as USD for metering): used only to enforce monthly additional-revenue plan caps. We do not store shopper names, emails, or addresses.
- Aggregate funnel metrics (views, clicks, converted orders, revenue) keyed by offer id: anonymous counters shown in the admin. No shopper identifiers are stored with these counters.
2.3 Information we explicitly do NOT collect
- Customer names, emails, phone numbers, IP addresses, or shipping addresses
- Full customer order history beyond the aggregate attribution fields above
- Payment card or banking information
- Shopper browsing behavior or analytics tied to individuals
Checkout pricing runs inside Shopify Functions on Shopify's infrastructure. Theme widgets read offer feeds from Shopify metafields. Widgets may POST anonymous counter increments (view/click) to Stickdeal via the Shopify App Proxy; those requests do not include shopper personal data.
3. How We Use Information
We use the information we collect solely to:
1. Authenticate your store with the Shopify Admin API 2. Store and sync your offer and widget configuration 3. Apply discounts and cart transforms via Shopify Functions 4. Enforce plan caps and process app billing through Shopify Billing 5. Meter Stickdeal-attributed placed-order revenue for plan limits 6. Compute and display aggregate offer funnel metrics in the admin 7. Respond to support requests
We do not sell, rent, or share your data with third parties for marketing or advertising.
4. Shopify Permissions (Access Scopes)
Stickdeal requests the following Shopify access scopes:
| Scope | Why we need it |
|---|---|
read_products |
Product and collection pickers; resolve handles for storefront widgets |
write_discounts |
Create and manage the automatic discount that powers deal math |
write_cart_transforms |
Cart Transform for Add and save one-line merge |
read_orders |
Attribute Stickdeal-influenced placed orders for monthly revenue plan caps |
read_app_proxy / write_app_proxy |
Receive anonymous view/click counters from storefront widgets via App Proxy |
You can revoke these scopes by uninstalling the app.
5. Data Storage and Security
- Where data lives: Application data is stored in Supabase (PostgreSQL). Shopify session tokens are encrypted at rest.
- In transit: Connections use TLS (HTTPS).
- Hosting: The app is hosted on Fly.io.
- Access: Internal access to production data is limited to the app's developers on a least-privilege basis.
No system is perfectly secure. If we become aware of a breach that affects you, we will notify you without undue delay.
6. Data Retention and Deletion (keep vs wipe)
| Event | What we keep | What we wipe |
|---|---|---|
| While installed | Store row, offers, widget themes, subscription snapshots, audit logs, encrypted sessions, attributed-order aggregates and monthly usage periods for plan metering, aggregate funnel metrics | — |
app/uninstalled |
Store row and merchant config (offers, themes, billing/audit/usage history) marked inactive / soft-uninstalled | All Shopify Session rows for the shop; local Discount / Cart Transform GIDs cleared; active offers set inactive. Shopify removes app-owned Discount, Cart Transform, and app metafields on its side after uninstall. |
shop/redact (~48 hours after uninstall) |
Nothing for that shop | Hard-delete the store row and cascaded offers, widget themes, subscriptions, audit logs, usage periods, and attributed orders; any remaining sessions |
orders/create |
Aggregate attributed revenue/order counts for the billing period; shopify order id for idempotency; anonymous funnel conversion counters per offer | No shopper PII from the order payload is retained beyond those aggregates |
customers/data_request / customers/redact |
N/A — we hold no shopper PII | Respond 200 confirming we store no customer personal data |
You can also request manual deletion at any time by emailing the address in Section 9.
7. Sub-processors
| Provider | Purpose |
|---|---|
| Shopify | Merchant authentication, billing, Functions, webhooks |
| Supabase | Database hosting |
| Fly.io | Application hosting |
Each provider maintains its own security and privacy program.
8. International Data Transfers and Legal Bases
Stickdeal is operated from Canada and may transfer data to data centers where our sub-processors operate. Where applicable laws require a legal basis, we rely on contractual necessity to provide the app, legitimate interest to operate and secure it, and consent where installing the app constitutes consent under your jurisdiction.
9. Your Rights and Contact
If you are a merchant using Stickdeal, you may request a copy, correction, or deletion of the data we hold about your store, or withdraw consent by uninstalling the app.
Email: hello@theclickcollective.io
We aim to respond within 1 business day.
10. Children's Privacy
Stickdeal is a B2B tool for Shopify merchants. It is not directed at children under 13, and we do not knowingly process data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision.