Privacy Policy

Loyalty Box · last updated 2026-09-30 · Terms of Service

What this app stores

Loyalty Box gives your logged-in customers points on paid orders and lets them turn points into a discount code. The app keeps the following, keyed to your shop domain:

What this app does not collect

From orders, the app reads only the order ID, order number, customer ID, the product subtotal after discounts, whether it is a test order, when it was created, and whether one of the app's own reward codes was used on it. From refunds and cancellations it reads only the refund ID, the order ID, and the product subtotal that was refunded, to take back points. It does not read or store customers' names, email addresses, postal addresses, or phone numbers.

Guest checkouts earn no points, so no entry is created for them.

To slow down abuse, requests from the storefront widget are rate-limited by network address. That address is kept only in the app's memory, is cleared within a minute after a ten-minute window ends, and is never written to the database. The widget sets no cookies.

We do not receive payment information.

We do not use your data or your customers' data to train models, and we do not sell or share it.

Who receives it

Shopify, which sends us paid orders, refunds, and cancellations, and in which the app creates discount codes when a customer redeems points. Those codes are part of your store's discounts.

Railway (railway.com), which hosts the app and its PostgreSQL database in the Netherlands. Railway processes data only to host the service.

There are no other processors. No email service, analytics service, advertising network, or error-reporting service receives your data or your customers' data.

How long it is kept

The points ledger stays while the app is installed, because it is what your customers' balances are made of.

When you uninstall the app, Shopify sends a shop/redact request 48 hours later. On that request we delete everything we hold for your shop. Discount codes already created stay in your store's discounts.

You can ask for deletion sooner by emailing us.

Requests from customers

If a customer asks your store for their data, open Customers in the app and enter their customer ID: you see their balance and every points entry, including the orders that earned points and the discount codes they redeemed.

If a customer asks to be deleted, Shopify forwards a customers/redact request. We find their ledger entries by their customer ID and by the orders listed in the request, and delete those entries. Their points balance is gone after that. Discount codes already created stay in your store's discounts, where you can delete them.

Changes

If what we store changes, this page changes with it before the change ships. The date at the top of this page is the last time that happened.

Contact

Questions, or a deletion request: beobjoong@gmail.com