Fluxora Logo
Install App
Home/Privacy/Guard Checkout
Shopify App Store ComplianceGuard Checkout

Guard Checkout Privacy Policy

This Privacy Policy explains how Guard Checkout ("the App"), developed and operated by Fluxora("we", "us", or "our"), collects, uses, evaluates, and protects information when installed on your Shopify-supported store or when interacting with your store's checkout flow.

Last Updated: September 2, 2026 • Version 1.0 • Effective Immediately

Guard Checkout Privacy Summary

  • Real-time In-Memory Validation: Cart and checkout attributes (items, quantities, postal codes, payment methods) are evaluated in real-time via Shopify Functions to enforce rules without persistent buyer profiling.
  • No Sensitive Payment Storage: We never collect, process, or store credit card numbers, CVVs, or full payment credentials. All payments remain securely processed by Shopify.
  • Strict Zero Data Selling: We do not sell, rent, trade, or monetize merchant store configurations or buyer checkout information to any third parties or advertising networks.
  • Shopify Mandatory Webhooks & GDPR Compliant: We fully honor Shopify's privacy webhooks for automated data requests, customer redaction, and complete store deletion upon app uninstallation.

1. Overview & Purpose of the App

Guard Checkout is a Shopify merchant application designed to provide checkout rules, cart validation, order value thresholds, address restrictions (such as blocking PO Boxes or non-deliverable postal codes), payment method gating, and customer tag-based checkout controls.

The App utilizes Shopify Functions (WASM backend execution) and Checkout UI Extensions to evaluate rules seamlessly and securely within Shopify's native checkout infrastructure.

2. Personal & Store Information We Access and Process

To provide checkout validation and management features, the App accesses certain data provided through Shopify's official APIs and during checkout interactions:

A. Merchant Account Information

When you install the App, we collect merchant details needed to authenticate and manage your subscription:

  • Shop domain (e.g. your-store.myshopify.com), primary store email, and store owner name.
  • Store currency, timezone, and primary location information.
  • Active subscription plan status and Shopify Billing API reference IDs.

B. Real-Time Checkout & Cart Data (Evaluation Only)

When a customer initiates checkout on your storefront, the App's Shopify Functions evaluate checkout attributes against the merchant's configured rules:

  • Cart line items, variant IDs, product quantities, and subtotal amounts (to check min/max purchase limits).
  • Shipping address country, province/state, and postal/ZIP code (to validate delivery zones or block PO Boxes).
  • Selected payment method and delivery method (to enforce payment gating or shipping restrictions).
  • Customer tags or B2B company identifiers (to evaluate VIP or wholesale rule exceptions).

C. Rule Configuration & Telemetry Data

  • Merchant-defined validation rules, error message texts, allowlists, and blocklists.
  • Aggregated validation counts, rule execution logs, and diagnostic telemetry for error debugging.
Explicit Notice on Financial & Payment Credentials:

Guard Checkout does NOT collect, process, or store credit card numbers, CVVs, bank account credentials, or raw payment tokens. All monetary transactions and sensitive payment fields are handled exclusively and securely by Shopify and authorized payment gateways.

3. How We Use the Information

We process collected information solely for legitimate operational purposes directly related to delivering the App's features:

  • Enforcing Checkout Rules: Evaluating cart criteria and preventing invalid orders or disallowed transactions before checkout completion.
  • Displaying Checkout Messages: Rendering real-time validation warnings and localized guidance banners to shoppers during checkout.
  • Configuration Management: Storing merchant preferences, rule metafields, and active protection toggles in your store dashboard.
  • Billing & Account Administration: Processing app subscriptions and usage tiers via Shopify Billing API.
  • Support & Security: Troubleshooting technical issues, diagnosing rule conflicts, monitoring uptime, and preventing abusive or fraudulent activity.

4. Information Sharing & Third-Party Sub-Processors

We do not sell, rent, trade, or monetize merchant or buyer personal information. We only share data with trusted sub-processors strictly necessary to operate the service:

  • Shopify Platform: App functionality is natively integrated with Shopify via APIs, webhooks, and Shopify Functions.
  • Cloud Hosting & Database Infrastructure: Secure cloud infrastructure providers (e.g. AWS / Supabase / Render) that employ industry-standard encryption, strict access control, and ISO/SOC certifications.
  • Legal Compliance: We may disclose information if required by applicable law, regulation, subpoena, or lawful government request, or to protect the safety, security, and rights of our merchants and the public.

5. Shopify Mandatory Webhooks & Data Retention

In full compliance with Shopify App Store requirements and global data protection regulations, Guard Checkout implements Shopify's mandatory GDPR/privacy webhook endpoints:

customers/data_request

Upon receiving a verified request from Shopify on behalf of a customer, we provide any associated data logs within 30 days.

customers/redact

Upon receiving a customer redaction request from Shopify, any temporary records or logs referencing the customer are permanently purged.

shop/redact

Within 48 hours of an app uninstallation, all store settings, rule configurations, and OAuth access tokens are permanently deleted from our databases.

6. International Data Transfers & European Residents (GDPR)

If you or your customers are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have explicit rights under the General Data Protection Regulation (GDPR), including:

  • The right to access personal information we hold about you.
  • The right to request rectification of inaccurate data.
  • The right to request erasure ("Right to be Forgotten") of your personal data.
  • The right to data portability and restriction of processing.

Data processed by the App may be transferred to and stored in secure data centers located in the United States and Canada. We ensure appropriate safeguards, including Standard Contractual Clauses (SCCs), to protect cross-border data transfers.

7. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with rights to know what personal information is collected, request deletion, and opt out of any sale or sharing of personal data.

We do not sell personal information or share personal information for cross-context behavioral advertising.

8. Data Security

We take data security seriously and employ administrative, technical, and physical safeguards designed to protect merchant and checkout data from unauthorized access, loss, or alteration:

  • All communications between Shopify, our backend, and browser interfaces are encrypted using Transport Layer Security (TLS 1.2 / 1.3 / HTTPS).
  • Stored configuration data is encrypted at rest using AES-256 standard encryption.
  • OAuth access tokens are securely managed and restricted using the principle of least privilege.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our operational practices, app features, or legal and regulatory obligations. Any updates will be posted on this page with an updated "Last Updated" timestamp.

10. Contact Us & Privacy Inquiries

If you have any questions about this Privacy Policy, wish to exercise your data privacy rights, or have questions regarding Guard Checkout compliance, please contact our team:

Email: support@fluxorapro.com

Privacy Inquiries: privacy@fluxorapro.com

Application: Guard Checkout (Shopify App)

Publisher: Fluxora Team (https://fluxorapro.com)

Response Time: Privacy requests are acknowledged within 48 hours.