Privacy Policy — POS Notices and Alerts
Effective date: August 4, 2026
POS Notices and Alerts ("the app") is developed and operated by dinkbit ("we", "us"). This policy explains what data the app processes when a merchant installs it on their Shopify store, and why.
Our role: we're a data processor, not a controller
The merchant who installs this app is the data controller for their customers' personal data — they decide what data exists and why. We act only as a processor, on the merchant's instructions, strictly to provide the app's functionality described below. We don't use customer data for our own purposes, and a customer's primary relationship for any privacy question is with the merchant they bought from, not with us.
What the app does
The app lets a merchant configure rules that show their point-of-sale (POS) staff a success, warning, or critical alert on the customer-details screen when a customer matches a condition the merchant defines — for example, a tag, time since last purchase, or a custom field value. The app has no server of its own: it reads data live from Shopify's own systems each time it's needed and stores its configuration inside the merchant's Shopify store, not on any server we operate.
What data we access, and why
With the merchant's authorization (via the standard Shopify app-install permission grant), the app reads the following data through Shopify's Admin API:
- Customer data: tags, name, email address, the date of the customer's last order, and the values of any customer metafields the merchant has chosen to build a rule around (for example, a membership-expiration date). This is read at the moment a staff member looks up a customer in POS, or a merchant loads the app's settings page, and is used only to evaluate whether the merchant's configured rules match that customer.
- Order/spend data: for a small, bounded sample of customers a rule has recently matched (see "What we store," below), the customer's lifetime order count and amount spent, and their last order date. This is used only to answer a merchant's own questions about their rules' activity (for example, via the app's Shopify Sidekick integration) and is never used for advertising, profiling, or any purpose beyond that.
- Shop data: the store's domain and currency, used to operate the app correctly (for example, to build a link back into the app, or to format currency).
We do not access payment details, and we do not request or use any data beyond what's listed above.
What we store, and where
The app stores almost nothing on servers we operate. Instead:
- Rule configurations (title, message, severity, and the condition that triggers each rule) are stored as data owned by the app installation, inside the merchant's own Shopify store (as Shopify "metaobjects"). This is Shopify's infrastructure, not ours.
- A bounded activity sample: to show a merchant how often a rule has fired, the app stores a count, a last-matched timestamp, and a rolling list of up to 50 Shopify customer IDs a rule most recently matched (automatically dropping the oldest as new matches come in). This list contains only Shopify's own customer identifiers — not names, emails, or any other detail — which are looked up live, on demand, only when the merchant explicitly asks a question that needs them (for example, through Sidekick).
- If the app is uninstalled, all of the above — every rule and every activity sample — is deleted automatically, because it's stored as data owned by the app installation and Shopify removes it when the installation is removed.
We do not maintain a customer database of our own, and no customer name, email, or personal detail is ever written to any server we operate.
Aggregate usage analytics (separate from any merchant's data)
Separately, we record limited, non-customer-identifying usage statistics about the app itself — how many merchants use it, how many rules they configure, and which plan they're on — to a private internal dashboard we use to understand adoption. These events include only the store's domain/ID, a rule count, and a condition type; they never include any end-customer's name, email, or other personal data, and are never shown to any merchant or made public.
Third parties
We don't sell, rent, or share customer data with any third party. The only party the data ever passes through is Shopify, whose own Admin API the app queries directly — Shopify's own privacy practices govern that layer, described at Shopify's Privacy Policy.
Optionally, a merchant using this app's Shopify Sidekick integration may ask Sidekick questions about their notice rules and their activity. Sidekick runs inside Shopify's own admin, using the same Shopify Admin API access described above — we do not receive a copy of anything asked or answered there.
Data processing agreement (for merchants)
By installing and using this app, you (the merchant) and dinkbit agree to the following, for as long as the app stays installed:
- Roles. You're the data controller for your customers' personal data. dinkbit is a data processor, acting only on your instructions as expressed through the app's configuration (the rules you set up) and its documented functionality.
- Scope of processing. dinkbit processes only the categories of data described in "What data we access, and why" above, solely to provide the app's alerting functionality — nothing else.
- No sub-processors beyond Shopify. The only party involved in processing your data is Shopify itself, the platform the app runs on and reads data from. dinkbit doesn't share your customers' data with any other third party.
- Security measures. Data is accessed only over Shopify's encrypted API connections. Accounts with access to the app's configuration or diagnostic tooling require strong, unique passwords and two-factor authentication where available — see our security incident response policy for how we handle a suspected breach.
- Duration and deletion. Processing continues for as long as the app is installed. All app-owned data (rule configurations and the bounded activity sample described above) is deleted automatically when you uninstall the app, since it's stored inside your own Shopify store.
- Your instructions. How you configure the app's rules — what conditions to match, what alerts to show — is your instruction to us for how to process data. If you need us to stop, uninstalling the app is sufficient and immediate.
- Assistance. If one of your customers contacts you with an access, correction, or deletion request, reach us at [email protected] and we'll assist — though as described above, we hold no persistent copy of their data to independently act on.
- Questions. Contact [email protected] for anything related to this agreement.
Your rights (data subject requests)
If you're a customer of a merchant using this app, you have the right to access, correct, or request deletion of your personal data. Because we act only as the merchant's processor (see above), the right place to start is the merchant themselves — they control what data exists and can direct us accordingly. As described above, we don't hold any customer name, email, or personal detail outside of what's read live from Shopify at the moment it's needed, so there's very little for us to independently look up. You can also reach us directly at [email protected] with any question, and we'll respond or route it to the merchant as appropriate.
Changes to this policy
If how the app handles data changes, we'll update this page and the effective date above.
Contact
Questions about this policy: [email protected].