ComplyGate — Privacy Policy
ComplyGate ("the app") lets Shopify merchants stop specified products being shipped to states, provinces or countries they have chosen to restrict, enforced inside Shopify's checkout. This policy explains what data the app processes and why.
Data we process
The app reads the store's product catalogue — product ids, titles, tags and collection membership — so it can work out which products each restriction covers. It stores the merchant's restrictions (product groups, blocked ISO region and country codes, and the message shown to a buyer), any CSV matrices the merchant imports, and a change log of every edit that affects checkout behaviour. It stores the store's myshopify domain and the access token Shopify issues for the app.
Data we do NOT collect
ComplyGate holds no customer personal data of any kind: no names, emails, addresses, payment details, order records or identifiers. It does not request the read_orders, read_customers or read_all_orders permissions, and cannot access them.
When a buyer reaches checkout, the delivery country and state code are compared against the merchant's rules inside Shopify's own function runtime. That comparison runs on Shopify's infrastructure; the address is never transmitted to, logged by, or stored on our servers. This is also why the app cannot offer a log of blocked checkouts, and it does not pretend to.
What we write to your store
One checkout validation (a Shopify Function) and one configuration metafield on that validation, containing the merchant's rules as product ids, region codes and messages. The validation is created with failure-blocking disabled, so if the function cannot run an order is allowed through rather than blocked.
Permissions
read_products (product, collection and tag matching), read_validations and write_validations (installing and configuring the checkout validation). Nothing else.
Data retention and deletion
Uninstalling the app removes the checkout validation with it, so checkout is immediately unimpeded, and enforcement is switched off locally. All stored data for the shop is permanently deleted in response to Shopify's shop redaction webhook. The customer data request and customer redaction webhooks are acknowledged and have nothing to report, because no customer data is held.
Legal responsibility
ComplyGate ships no pre-filled legal rule packs and makes no representation that any configured restriction is correct or sufficient for any jurisdiction. The merchant defines and owns the rules.
Third parties
No data is sold or shared. There are no third-party trackers, analytics or cookies.
Contact
Fleeta Limited — sales@fleeta.co.uk