Privacy Policy
Discountly by F12 Labs ยท Last updated: September 28, 2026
1. Introduction
Discountly ("we", "our", "the app") is a Shopify application that lets merchants create volume pricing, product and order discounts, free gifts, buy X get Y offers and shipping discounts. This policy explains what data the app collects, how it is used, where it is stored and how it is protected.
2. Data We Collect
Discountly collects and processes only what it needs to run discounts:
- Store data: the store's Shopify domain, the access token Shopify issues when the app is installed, and the store's Discountly plan.
- Staff data: the Shopify staff user ID, name and email of staff who use the app, to apply staff roles and to record who changed a discount in its audit trail.
- Discount settings: the discounts the merchant builds, including the products, collections, tags and metafields they target, and product names and images for the matching-products preview.
- Order data for Analytics: for each order, the order ID and number, date, totals, currency, sales channel, order tags and which discounts applied. We do not store the customer's name, email, address or payment details for orders.
- Customer data, only when a merchant targets specific customers: the customer's Shopify ID and display name (name and email), saved in that discount so the merchant can see who it applies to.
To decide whether a shopper qualifies for a discount, the app reads the logged-in customer's ID, tags and segment membership from Shopify at the moment it's needed. That information is used for the decision and is not stored.
We do not collect payment information, passwords, shipping addresses or browsing history.
3. How We Use Data
- To create and keep the store's discounts in sync with Shopify.
- To show discounts, free gifts and pricing on the storefront and at checkout.
- To apply eligible discounts to draft orders for the merchant's staff.
- To report revenue and orders from the merchant's discounts in Analytics.
- To control which staff can view or change discounts, and keep a change history.
We do not use data for advertising and we do not build profiles of shoppers.
4. Where Data Is Stored
- Our database: discount settings, staff roles and audit history, the store's session, and the Analytics order records.
- Shopify: the discounts themselves, discount settings the storefront reads (shop and product metafields in the app's own
$app:discountifynamespace), and hidden properties on cart lines and draft orders that mark free gifts and applied discounts.
5. Why We Access Store Data
The app requests these access scopes:
write_products: read products and collections for targeting, and save which products each discount matches.write_discounts: create, update and remove the Shopify discounts behind each rule.write_draft_orders: apply eligible discounts and free gifts to draft orders.read_themes: check whether the app's cart embed and product page blocks are installed on the live theme.write_metaobjects,write_metaobject_definitions: read the store's metaobjects used for targeting, and store the app's own settings.read_customers: let merchants choose specific customers or segments for a discount, and check a shopper's tags and segments to decide eligibility.read_orders: record orders and the discounts applied to them for Analytics.
6. Storefront and Browser Storage
On the storefront, the app's cart embed talks to the app through Shopify's app proxy on the store's own domain. It marks free-gift cart lines with hidden line properties so a gift a shopper removes isn't added back. The app does not use cookies, and it stores no personal data in the browser's local or session storage.
7. Data Sharing
We do not sell, rent or share store or customer data with third parties. Data is processed only by Shopify and by our hosting and database providers, who process it on our behalf to run the app.
8. Data Retention
- Data is kept while the app is installed, so the merchant's discounts, history and Analytics stay available.
- When the app is uninstalled, the store's access session is deleted immediately.
- Shopify notifies us 48 hours after uninstall, and we then delete all of the store's data: discounts, staff roles, audit history, settings and Analytics records.
9. GDPR and Data Requests
Discountly handles Shopify's privacy requests automatically:
- Customer data request: we identify the discounts that name the customer and the Analytics records for their orders, and the merchant can view the same data in the app.
- Customer erasure: we remove the customer from every discount that names them, and delete the Analytics records for the orders Shopify asks us to erase.
- Store erasure: after uninstall, all of the store's data is deleted as described above.
Merchants and shoppers can also send access or deletion requests to the email below.
10. Security
All traffic uses HTTPS. Storefront requests go through Shopify's app proxy, which signs every request so the app can verify it came from Shopify. Admin access requires an authenticated Shopify session, and on the Pro plan staff roles limit who can view or change discounts.
11. Changes to This Policy
If this policy changes, we update the date at the top of this page.
12. Contact
For privacy questions or data requests, contact us at:
Email: support@ftwelvelabs.com
This privacy policy applies to the Discountly Shopify application.