Privacy policy
Last updated August 19, 2026
Giraffe Shipping is a Shopify app that calculates shipping rates at checkout from rules a merchant writes. This policy describes the personal data the app processes on a merchant’s behalf, why it processes it, and how long it is kept.
Our role
The merchant who installs Giraffe Shipping is the controller of their customers’ personal data. We are a processor: we act on the merchant’s instructions and use their data only to provide the app to them. We do not sell personal data, share it with advertisers, or use it to build profiles of individuals.
What we process
| Data | Why | Stored? |
|---|---|---|
| Shipping destination of a cart at checkout — country, region, postal code and city | Shopify sends us each cart while a customer is checking out, and we return the shipping rates the merchant’s rules produce. The destination is what decides which rule matches. | Yes, for 30 days, so the merchant can see what was quoted and catch a cart that was offered no rate. |
| Cart contents — item quantities, weights, prices, vendors, SKUs, product tags and types, and whether each item needs shipping | Rules can price on weight, order total, product, vendor, product tag or product type, so the cart has to be summarised to price it. | Yes, aggregated, for 30 days, alongside the destination. |
| Subscription status — whether the store has an active subscription to this app, and the dates on which one started or ended | The app is paid, and a rule may only be offered to real customers on a subscribed store. Shopify bills the store and holds the plan and payment details; this app only asks Shopify whether a subscription is active. It never sees a payment method. | Yes, until the app is uninstalled. No personal data, and nothing about the merchant’s customers. |
| Product catalogue — for each product, its Shopify product ID, its tags and its product type | Rules can apply to a product’s tags or type. Shopify does not include either in the cart it sends us at checkout, and looking them up while a customer waits is not possible within the time checkout allows, so the app keeps its own copy and updates it when a product changes. | Yes, until the app is uninstalled. No personal data — products, not people. No titles, descriptions, prices, images or inventory are stored. |
| Shop and installation data — the store domain, its Shopify shop ID, its timezone, its Shopify access token, and the shipping rules the merchant writes | Required to authenticate with Shopify, to resolve dates in the store’s own timezone, to price carts, and to ask Shopify whether the store has an active subscription to this app. | Yes, until the app is uninstalled. |
What we do not process
Giraffe Shipping does not request or receive customer names, email addresses, phone numbers, or Shopify customer records. It does not request the read_customers permission. It does not process payment details of any kind — payments are handled entirely by Shopify checkout and never reach this app.
It does not read a store’s orders. It does not request the read_orders permission, so no past order, and no shipping address on one, is ever available to this app.
The rate records we keep for 30 days carry no customer identifier, no name, no street address, no phone number and no email address. They are reduced to a country, region, postal code and city before they are written, which means a stored record cannot be traced back to an individual by us.
How long we keep it
- Rate records: 30 days. Deleted automatically; no action is needed from the merchant.
- Shipping rules, shop record, access token and product catalogue: kept while the app is installed. The product copy carries no expiry of its own — a copy that expired would silently stop a rule matching — so it is removed only on uninstall.
- After uninstall: Shopify notifies us 48 hours after the app is removed, and we then delete the shop record, its rules, its product data, its rate records and its session data from the live database.
- Backups: 8 days. Our database provider takes one encrypted snapshot a day and keeps the most recent eight. Deletion removes data from the live database immediately, but a copy remains in those snapshots until it ages out, which takes at most eight days. Snapshots are restored only to recover from data loss, never to look up a merchant or a customer.
Who else processes this data
- Google Cloud Platform — hosts the application.
- MongoDB Atlas — hosts the database.
- Shopify — besides being the source of the data above, Shopify handles all billing for this app: it hosts the plan page, takes payment, and answers our query asking whether a given store is subscribed. That query sends the store’s Shopify shop ID and nothing else.
We use no analytics, advertising, or tracking services, and we embed no third-party scripts in a merchant’s storefront or checkout.
Security
Data is encrypted in transit using TLS and encrypted at rest, including backups. The app provides no screen anywhere that displays one merchant’s data to us, so reaching production data at all means signing in to the server or the database directly. Both are restricted to staff who need them, protected by strong passwords and two-factor authentication, and both record an access log of those sign-ins and of changes made through them. Production and test environments are kept separate: no real merchant or customer data is used in development.
Requests from customers
A customer who wants to know what data is held about them, or to have it erased, should contact the merchant they bought from — the merchant is the controller and Shopify passes such requests to us on their behalf. We respond to Shopify’s customers/data_request and customers/redact notifications. Because our records hold no customer identifier, there is in practice no customer-specific data for us to return or erase.
Automated decisions
The app calculates a shipping price automatically from a cart’s destination and contents, according to rules the merchant wrote. It does not profile, score, or make predictions about individuals, and makes no decision with a legal or similarly significant effect on any person.
Changes to this policy
We update this policy whenever the app changes what data it processes, why, how long it is kept, or who else processes it. The date at the top reflects the most recent change.
Contact
Questions about this policy, or about the data Giraffe Shipping processes: [email protected].