Privacy Policy

Effective date: Aug 5, 2026
Last updated: Aug 5, 2026

Encore (“the app”, “we”, “us”) is a Shopify app that shows product offers to
shoppers on a merchant’s storefront and reports on how those offers performed.
This policy explains what data the app collects, why, how long it is kept, and
how to have it deleted.

Encore is operated by Merqio.App.
Questions about this policy or about your data: support@merqio.app.


1. Who this policy is for

Two groups of people are described here, and the app treats them differently:

  • Merchants — the Shopify store owners and staff who install and configure
    Encore.
  • Shoppers — the customers of those stores, who may see an Encore offer while
    browsing or checking out.

Encore is a data processor acting on the merchant’s instructions for shopper
data. The merchant remains the data controller for their own customers.


2. What the app accesses from Shopify

When a merchant installs Encore, they grant these access scopes. Each is listed
with the reason it is needed:

ScopeWhy the app needs it
read_products / write_productsRead product, variant, image, and price data to build and display offers
read_inventoryAvoid offering products that cannot be fulfilled
read_locationsInterpret inventory availability per location
write_discountsCreate and maintain the automatic discount that applies an offer’s configured discount to the upsold item
write_ordersAdd an accepted post-purchase offer to the order the shopper just placed
read_customersAssociate an offer view with a customer record so merchants can see repeat behaviour

Encore never requests or receives payment card details. Post-purchase offers
are charged by Shopify against the payment method already used for the order;
the card data never passes through the app.


3. What the app stores

Data synced from the merchant’s Shopify store

Shop details, products, product variants, collections, orders, and customer
records, kept in sync through Shopify webhooks. This is stored so the app can
resolve which product an offer refers to and match an order back to the offer
that produced it.

Data the merchant creates in the app

Offers, customer journeys, journey steps, targeting rules, and cart drawer
configuration. This is the merchant’s own configuration and contains no shopper
personal data.

Data collected when a shopper sees an offer

  • Which offer was shown, on which surface, and when
  • Whether the shopper added the offered product
  • The cart’s contents as product and variant identifiers, the cart total, and
    item quantity — used to decide whether an offer’s targeting conditions are met
  • The buyer’s country code, on the checkout and thank-you surfaces only
  • Shopify’s cart token and checkout token, which are per-session
    identifiers used to match a later order back to the offer a shopper saw
  • A link to the Shopify customer record, where one exists

Encore does not collect shopper names, email addresses, phone numbers,
shipping addresses, payment details, IP addresses, or browsing history outside
the pages where an offer is displayed. It does not use cookies or advertising
identifiers, does not build cross-store profiles, and does not track shoppers
between merchants.


4. How the data is used

Shopper data is used only to:

  1. Decide which offer, if any, to show a given shopper.
  2. Attribute a completed order back to the offer that led to it, so the merchant
    can see which offers earned revenue.
  3. Apply the discount the merchant configured for an offer.

Data is not used to train machine-learning models, is not sold, rented,
or shared for advertising, and is not used for any purpose beyond serving the
merchant who collected it.


5. Who else the data goes to

RecipientPurpose
ShopifySource of the data and the platform the app runs on
Gadget (gadget.dev)Application hosting, database, and logging

No other subprocessors receive shopper data. If that changes, this policy will be
updated before the change takes effect.


6. Retention and deletion

Encore implements Shopify’s three mandatory privacy webhooks.

shop/redact — 48 hours after a merchant uninstalls. Everything the app
stored for that shop is deleted: offers, journeys, journey steps, journey
conditions, targeting rules, cart drawer configuration, and all impression and
conversion records.

customers/redact — when a shopper exercises their right to erasure. The
link between that shopper’s Shopify customer record and any offer view is
removed, and the cart and checkout tokens on the affected records are cleared.

The impression and conversion rows themselves are retained in de-identified
form — they hold counts and amounts, not personal data, once the identifiers
above are removed. This is deliberate: deleting them would silently change a
merchant’s historical revenue reporting every time a shopper requested erasure.
If you require full deletion of these rows rather than de-identification, contact
us at support@merqio.app.

customers/data_request — when a shopper asks what data is held. Shopify
requires this to be provided to the store owner, not returned over the webhook.
Encore assembles everything it holds for that shopper and we deliver it to the
store owner within the 30 days Shopify allows.

Merchants may request deletion at any time without uninstalling, by contacting
support@merqio.app.


7. Security

Data is transmitted over TLS. Requests from a storefront are authenticated using
Shopify’s App Proxy signature; requests from checkout and post-purchase
extensions are authenticated using Shopify-signed session tokens verified against
the app’s secret. Every record is scoped to the shop that owns it, and access
control is enforced at the database query level so one merchant’s data cannot be
read by another.


8. Your rights

Depending on where you live, you may have the right to access, correct, delete,
or export your personal data, to object to or restrict its processing, and to
lodge a complaint with a supervisory authority.

Shoppers should contact the store they purchased from — that merchant is the
controller of their data. The merchant’s request reaches us automatically through
Shopify’s privacy webhooks.

Merchants can contact [PRIVACY CONTACT EMAIL] directly.

Under the GDPR, our lawful basis for processing is the performance of our
contract with the merchant, and the merchant’s own lawful basis for processing
their customers’ data.


9. International transfers

Data is stored on infrastructure operated by our hosting provider in USA.
Where data is transferred out of the UK, EEA, or Switzerland, the transfer relies
on the applicable safeguards, including the European Commission’s Standard
Contractual Clauses.


10. Children

Encore is a business tool and is not directed at children. We do not knowingly
collect personal data from anyone under 16.


11. Changes to this policy

If this policy changes materially, we will update the date above and notify
merchants through the app or by email before the change takes effect.


12. Contact

Merqio.App
support@merqio.app