Data retention
Effective October 1, 2026. This page lists everything Aptum Checkout Protection keeps, where, and for how long. It supplements the privacy policy.
| Data | Where | Kept for |
|---|---|---|
| Shop domain, offline access token, refresh token, token expiry, granted scope | Firestore (Google Cloud) | While the app is installed. Deleted when Shopify reports the uninstall (app/uninstalled), and again on Shopify's shop/redact request about 48 hours later. |
| Checkout rule (title, enabled, fail-closed) and the merchant's signing key | The merchant's Shopify store, not our servers | Controlled by the merchant in Shopify admin (Settings → Checkout → Checkout rules), where the rule can be turned off or deleted at any time. |
| Web request logs (time, IP address, URL, user agent) | Cloud Logging (Google Cloud) | 30 days, then deleted automatically. |
| Support emails | Our business email | Until the request is resolved, then up to 24 months for follow-up, unless you ask us to delete them sooner. |
| Buyer names, emails, phone numbers, addresses, orders, payments | Never collected | Not applicable. |
Deletion on request
A merchant can delete everything we hold for their store by uninstalling the app. To ask for deletion without uninstalling, or for a copy of what we hold, write to support@aptum.ai. We act within 30 days. Shopify customer data and redaction requests are confirmed automatically because the app holds no buyer records.
Aptum, LLC · 12604 Hallstatt Dr, Manor, TX 78653