Aptum Checkout Protection

Data retention

Effective October 1, 2026. This page lists everything Aptum Checkout Protection keeps, where, and for how long. It supplements the privacy policy.

DataWhereKept for
Shop domain, offline access token, refresh token, token expiry, granted scopeFirestore (Google Cloud)While the app is installed. Deleted when Shopify reports the uninstall (app/uninstalled), and again on Shopify's shop/redact request about 48 hours later.
Checkout rule (title, enabled, fail-closed) and the merchant's signing keyThe merchant's Shopify store, not our serversControlled by the merchant in Shopify admin (Settings → Checkout → Checkout rules), where the rule can be turned off or deleted at any time.
Web request logs (time, IP address, URL, user agent)Cloud Logging (Google Cloud)30 days, then deleted automatically.
Support emailsOur business emailUntil the request is resolved, then up to 24 months for follow-up, unless you ask us to delete them sooner.
Buyer names, emails, phone numbers, addresses, orders, paymentsNever collectedNot applicable.

Deletion on request

A merchant can delete everything we hold for their store by uninstalling the app. To ask for deletion without uninstalling, or for a copy of what we hold, write to support@aptum.ai. We act within 30 days. Shopify customer data and redaction requests are confirmed automatically because the app holds no buyer records.


Aptum, LLC · 12604 Hallstatt Dr, Manor, TX 78653