POS Notices and Alerts POS Notices and Alerts

Privacy Policy — POS Notices and Alerts

Effective date: August 4, 2026

POS Notices and Alerts ("the app") is developed and operated by dinkbit ("we", "us"). This policy explains what data the app processes when a merchant installs it on their Shopify store, and why.

Our role: we're a data processor, not a controller

The merchant who installs this app is the data controller for their customers' personal data — they decide what data exists and why. We act only as a processor, on the merchant's instructions, strictly to provide the app's functionality described below. We don't use customer data for our own purposes, and a customer's primary relationship for any privacy question is with the merchant they bought from, not with us.

What the app does

The app lets a merchant configure rules that show their point-of-sale (POS) staff a success, warning, or critical alert on the customer-details screen when a customer matches a condition the merchant defines — for example, a tag, time since last purchase, or a custom field value. The app has no server of its own: it reads data live from Shopify's own systems each time it's needed and stores its configuration inside the merchant's Shopify store, not on any server we operate.

What data we access, and why

With the merchant's authorization (via the standard Shopify app-install permission grant), the app reads the following data through Shopify's Admin API:

We do not access payment details, and we do not request or use any data beyond what's listed above.

What we store, and where

The app stores almost nothing on servers we operate. Instead:

We do not maintain a customer database of our own, and no customer name, email, or personal detail is ever written to any server we operate.

Aggregate usage analytics (separate from any merchant's data)

Separately, we record limited, non-customer-identifying usage statistics about the app itself — how many merchants use it, how many rules they configure, and which plan they're on — to a private internal dashboard we use to understand adoption. These events include only the store's domain/ID, a rule count, and a condition type; they never include any end-customer's name, email, or other personal data, and are never shown to any merchant or made public.

Third parties

We don't sell, rent, or share customer data with any third party. The only party the data ever passes through is Shopify, whose own Admin API the app queries directly — Shopify's own privacy practices govern that layer, described at Shopify's Privacy Policy.

Optionally, a merchant using this app's Shopify Sidekick integration may ask Sidekick questions about their notice rules and their activity. Sidekick runs inside Shopify's own admin, using the same Shopify Admin API access described above — we do not receive a copy of anything asked or answered there.

Data processing agreement (for merchants)

By installing and using this app, you (the merchant) and dinkbit agree to the following, for as long as the app stays installed:

Your rights (data subject requests)

If you're a customer of a merchant using this app, you have the right to access, correct, or request deletion of your personal data. Because we act only as the merchant's processor (see above), the right place to start is the merchant themselves — they control what data exists and can direct us accordingly. As described above, we don't hold any customer name, email, or personal detail outside of what's read live from Shopify at the moment it's needed, so there's very little for us to independently look up. You can also reach us directly at [email protected] with any question, and we'll respond or route it to the merchant as appropriate.

Changes to this policy

If how the app handles data changes, we'll update this page and the effective date above.

Contact

Questions about this policy: [email protected].