Skip to content

Privacy

Last updated: July 14, 2026

Overview

Stackable ("Stackable", "we", "us") is a Shopify app that computes bulk and volume discounts for merchants. This policy explains what data we collect when a merchant installs Stackable, why we collect it, and - just as importantly - what we deliberately do not collect.

This policy covers the Stackable app and this website. It does not cover Shopify's own handling of your store or your customers' data, which is governed by Shopify's own privacy policy.

Information we collect

When a merchant installs Stackable, we collect and store:

  • Shop-identifying information: your shop domain, Shopify shop ID, and Shopify plan.
  • The email address associated with your Shopify account, used to install and administer the app.
  • For traceability, the name, email, and Shopify staff ID of whichever team member performs an action inside Stackable (e.g. publishing or pausing a campaign), resolved from the session token Shopify issues to that admin session - so your team can see who changed what.
  • The discount campaign configuration you create: campaign names, offer types, tiers, schedules, and related settings.
  • Your store currency, timezone, and locale, used to display and compute discounts correctly.
  • Session and authentication data required by the Shopify app framework to keep your admin session secure.
  • Aggregate, order-level analytics for orders where one of your Stackable discounts applied: the order ID, order total, currency, and which discount(s) applied and for how much.
  • If you submit our contact form or a "notify me" waitlist form (for example on our wholesale/B2B page), the name, email, and message you provide there.

What we do not collect

We do not collect or store your customers' names, email addresses, shipping or billing addresses, phone numbers, or payment details as part of our discount analytics. Our order-attribution data (above) is limited to order IDs and totals - it never becomes a customer-level record.

One nuance worth stating plainly: Shopify's order webhook that tells us an order occurred briefly delivers the full order payload, which can technically include customer details Shopify attaches to that payload. We hold that raw payload only long enough to extract the order total and match it to the discount(s) that applied, then delete it automatically. We do not read, index, or build any customer profile from it.

Shopify mandatory compliance webhooks

As a public Shopify app, Stackable subscribes to the three webhooks Shopify requires every app to support:

  • customers/data_request - Shopify sends this when a customer asks a merchant what personal data has been collected about them. Because we do not retain storefront customer PII beyond the brief processing window described above, our response is typically that we hold none.
  • customers/redact - Shopify sends this when a customer's personal data should be deleted. Same as above: there is typically nothing customer-identifiable in our systems to redact by the time this arrives.
  • shop/redact - Shopify sends this automatically about 48 hours after a shop uninstalls Stackable. On receipt, we hard-delete the shop record and everything that cascades from it (campaigns, offers, analytics, activity history).

Sub-processors

We use the following service providers to run Stackable. Each processes data only as needed to provide their service to us. This list is kept identical to the sub-processor list in our Data Processing Addendum:

Vercel
Hosting and infrastructure for the app and this website (United States).
Supabase
Managed Postgres database - stores the shop, campaign, and analytics data described above (United States region).
Shopify
The platform Stackable runs on - authentication, billing, and the storefront/checkout APIs the discount engine relies on (processed per Shopify's own global infrastructure).
Resend
Transactional email - sends contact-form and waitlist notifications (United States).
Google Analytics
Aggregate website traffic analytics on this marketing site, only after you accept analytics cookies - see our Cookie Policy (United States).
Google (Gemini API)
AI provider for the in-app campaign assistant and Scripts Rescue. When you describe a discount in the assistant, the text you type is sent to draft a matching campaign, along with catalog names from your store (collection titles, product tags, product titles) so the draft targets the right products. When you paste a Shopify Script into Scripts Rescue, the script text is sent so we can rebuild it as a matching campaign. We never send customer personal data - no names, emails, orders, or addresses (United States).
OpenAI
Fallback AI provider for the in-app campaign assistant and Scripts Rescue, used only if the primary provider is unavailable. Processes the same typed request and catalog names (collection titles, product tags, product titles), or the pasted Script text, no customer personal data (United States).

Data retention

  • Shop, campaign, and analytics data is retained for as long as Stackable is installed on your store.
  • If you uninstall, your data is retained briefly (in case you reinstall) and then hard-deleted once Shopify sends the shop/redact webhook described above.
  • Raw webhook payloads that may contain customer detail are purged automatically shortly after being processed into the aggregate analytics described above - they are never a long-term store.
  • Contact-form and waitlist-form submissions are used to respond to or act on your request and are not retained as a marketing list.

Security

We use industry-standard measures to protect the data we hold: encrypted connections (TLS) between every component, database credentials scoped to what the app actually needs, and administrative access limited to the people who need it to operate the service. No system is 100% secure, and we cannot guarantee absolute security - but we treat merchant data as something we are trusted with, not something we own.

Your rights

You can request a copy of the data we hold about your shop, ask us to correct it, or ask us to delete it (which happens automatically when you uninstall, per the retention section above) by contacting us at the address below. We will respond to any request within 30 days.

California and other US state privacy rights

We do not sell or share personal information, and we do not use it for cross-context behavioral advertising. If you are a California resident (or a resident of another US state with a similar privacy law), you have the same rights described in "Your rights" above: to know what personal information we hold, to request its deletion, and to opt out of any sale or sharing - which, again, we do not do. To exercise any of these rights, contact us at the address below.

Children's privacy

Stackable is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect personal information from anyone under 16.

International data transfers

Our sub-processors listed above may process data outside your country. Where that happens, it relies on the safeguards those providers maintain (including Standard Contractual Clauses where applicable). See our Data Processing Addendum for more detail.

Business transfers

If Stackable is involved in a merger, acquisition, or sale of assets, your data may be transferred to the successor entity as part of that transaction. If that happens, it will remain governed by this policy (or a materially similar one), and we will give you notice before your data becomes subject to a different policy.

Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected in the "Last updated" date above; continued use of Stackable after a change means you accept the updated policy.

Contact us

Questions about this policy or your data? Email us - see the Contact page for our support address.

AI-assisted features

Stackable includes optional AI-assisted features: the in-app campaign assistant, which turns a plain-English description into a draft discount campaign, and Scripts Rescue, which reads a Shopify Script you paste and rebuilds it as a matching campaign you can verify.

When you use these features, the text you provide is sent to our AI sub-processors (listed in the Sub-processors section) to generate the suggestion. For the assistant, that is the request you type plus catalog names from your store (collection titles, product titles, and product tags) so the draft targets the right products. For Scripts Rescue, it is the Script text you paste. We send only what you provide for that purpose, and we do not send storefront customer personal data - no customer names, emails, orders, or addresses.

These features are for configuring discounts, not for processing personal data. Please do not include customer names, emails, or any personal data in what you type or paste. A discount Script is pricing logic and should not contain customer information.

Our AI sub-processors process this input under paid API terms that do not use it to train their models, and retain it only briefly for their own safety and abuse-prevention purposes. We do not keep a copy of the assistant conversation. When you rebuild a Script with Scripts Rescue and create a campaign from it, we keep that script attached to the campaign you created so you have a record of what it was recreated from; it is deleted with the rest of your data when you uninstall.

AI suggestions are a starting point, not a guarantee. You review and verify every campaign, including in the built-in simulator, before it goes live.

We use essential cookies to run this site, and, only with your permission, analytics cookies to understand traffic. Read our Cookie Policy.