Zippy is an app for merchants who use Shopify to power their stores. It adds a delivery-serviceability checker that lets shoppers confirm whether a store delivers to their pincode or zipcode, and blocks checkout for pincodes a merchant does not serve. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with your Shopify-supported store.
Personal Information the App Collects
When you install the App, we access certain information from your Shopify account under the following permissions (scopes):
read_script_tags / write_script_tags: read and add the storefront script that renders the delivery-checker widget.
read_products: read products and collections so serviceability rules can target them.
read_locations: read store locations used in delivery configuration.
read_themes: read theme information to place the widget correctly.
read_customer_address: read the buyer's delivery postal code at checkout so our checkout-validation function can block orders to pincodes the merchant does not serve.
From the merchant we also collect account information such as name, email address, store URL, and plan.
Protected Customer Data (buyer postal codes)
To provide the serviceability check, the App processes the buyer's delivery postal code / pincode. This is the only protected customer data we access. During checkout, our validation function reads the postal code solely to compare it against the merchant's serviceability list and does not store it. Postal codes submitted to the storefront widget may be recorded in lookup logs for up to 90 days for analytics and abuse prevention, after which they are deleted. We do not access buyer names, emails, phone numbers, or payment details, and we do not sell personal information.
We also use “Cookies” (small data files stored on your device, including a pincode cookie that remembers your last-checked pincode) and privacy-respecting product analytics that may collect data such as IP address, browser type, referring/exit pages, and date/time stamps to operate and improve the App. Learn more about cookies at http://www.allaboutcookies.org.
How Do We Use Your Personal Information?
We use the information we collect to provide and operate the App — including checking delivery serviceability and enforcing checkout rules — to support and communicate with merchants, and to maintain, secure, and improve the Service. We do not use this information for third-party targeted advertising.
Sharing Your Personal Information
We share information only with service providers who help us run the App (for example, our hosting and infrastructure providers and Shopify), and where required to comply with applicable laws and regulations, to respond to lawful requests, or to protect our rights. We do not sell personal information.
Data Security
We protect data with least-privilege access, encryption in transit (HTTPS), restricted access to production systems and secrets, network firewalling, and regular patching. Access to protected customer data is limited to the delivery postal code required for the serviceability check.
Data Breach Notification
We maintain a documented security incident response process. In the event of a security incident affecting personal or protected customer data, we will investigate and contain it promptly, notify Shopify without undue delay and within 24 hours of confirmation, notify affected merchants, and notify data-protection authorities and affected individuals where required by law (for example, within 72 hours under the GDPR).
For European residents
If you are a European resident, you have the right to access the personal information we hold about you and to ask that it be corrected, updated, or deleted; contact us using the details below. We process information to perform our contract with you and to pursue our legitimate business interests described above. Your information may be transferred and processed outside Europe, including in Canada, the United States, and India.
Data Retention
We retain merchant account and configuration data for as long as the App is installed. Postal-code lookup logs are retained for up to 90 days. On uninstall, or on a valid deletion request, we delete the associated data in line with Shopify's data-erasure requirements.
Changes
We may update this privacy policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons.
Contact Us
For more information about our privacy practices, questions, or complaints, contact us by e-mail at support@risingsigma.com or via the "Get Help" section in the App.