Privacy policy
Last updated June 22, 2026
This Privacy Policy explains what data Rulify ("the App", "we", "us") collects, how we use it, and the choices you have. It applies to merchants who install the App and to the shoppers whose checkout data passes through it.
Data we collect
To provide the service we collect and store:
- Store information — your Shopify domain, store ID, and the access token Shopify grants on install.
- Configuration — the rate scenarios, conditions, and zones you create.
- Checkout data — at checkout Shopify sends us the cart contents and destination address so we can evaluate rules. This is processed in real time to return rates.
- Debug logs — on paid plans we retain a record of rate requests and the rules that matched, for the retention period of your plan.
How we use data
We use the data solely to operate the App: evaluating your rules at checkout, returning shipping rates, displaying debug information to you, and providing support. We do not sell your data or use it for advertising.
Shopper data
Checkout payloads contain shopper information such as the destination address and cart contents. We use this only to compute rates for that request. We do not store data keyed to individual shoppers, build shopper profiles, or market to shoppers. On paid plans a checkout payload may be retained inside a debug log for your plan's retention window and is then deleted automatically.
Data sharing
We share data only with infrastructure providers needed to run the App (hosting and database), and with Shopify as part of the checkout integration. These providers process data on our behalf under appropriate safeguards. We may disclose data if required by law.
Data retention
We retain your store data for as long as the App is installed. Debug logs are kept according to your plan — 7 days on Pro and 30 days on Premium; the free plan stores no debug logs. When you uninstall, we deactivate your store immediately and permanently erase your store record and all associated scenarios, zones, and logs when Shopify sends the redaction request, approximately 48 hours after uninstall.
GDPR & data requests
We honor Shopify's mandatory compliance webhooks. A shop-redaction request permanently deletes the store and all its data; a customer-redaction request purges the store's debug logs (the only place a shopper address may appear). Because we store no customer-identifiable data, a customer-data request returns nothing to assemble. If you or a shopper wishes to access or delete personal data, contact us and we will respond in line with applicable law.
Security
Access tokens and configuration are stored securely, and all requests are authenticated. Communication with Shopify is verified with HMAC signatures. No method of transmission is perfectly secure, but we take reasonable measures to protect your data.
Changes
We may update this policy from time to time. The date above reflects the latest revision. Material changes will be communicated where appropriate.
Contact
For privacy questions or requests, email us at hello@lisive.com.