Loyalty Runner (the "App") is a loyalty and rewards program that Shopify merchants install on their store. It awards points to the merchant's customers and lets those customers redeem rewards. This policy explains what data the App accesses, why, and how it is handled.
When a merchant installs the App, we access — through Shopify's APIs and only to the extent the merchant has approved — the following:
We store the minimum needed to run the program: a customer identifier, the customer's points ledger (points earned and spent), tier, and reward redemptions. We do not sell customer data or use it for advertising.
We do not share customer data with third parties except:
We honour Shopify's mandatory compliance webhooks:
customers/data_request — we compile the loyalty data we hold
for a customer so the merchant can fulfil an access request.
customers/redact — we delete the loyalty data we hold for that
customer.
shop/redact — 48 hours after a merchant uninstalls, we delete
the store's data.
Access to the App's backend is authenticated (Shopify session tokens / signed requests). Data is transmitted over HTTPS. Store-credit conversions and point debits are recorded in an append-only ledger for integrity.
We may update this policy; material changes will be reflected by a new effective date at the top of this page.
Questions about this policy or your data: edward@meginteractive.com.