Privacy policy
Effective October 1, 2026. This policy explains what Aptum Checkout Protection (the “app”), provided by Aptum, LLC, collects when a Shopify merchant installs it, why, how long it is kept, and how to reach us.
What the app does
The app adds one checkout rule to the merchant's Shopify store. On a quote checkout, the rule compares the delivery address the buyer enters with the address the quote was prepared for and stops payment if they differ, or if the quote has expired or its signature cannot be verified. That comparison runs inside Shopify's checkout (as a Shopify Function). It does not run on our servers.
Information we collect through Shopify's APIs
- Shop identity and access credentials. When a merchant installs the app, Shopify gives us the store's myshopify domain, an offline access token with its refresh token and expiry, and the granted permission (
write_validations). We store these so the app's settings page can create and check the checkout rule. - Checkout-rule status. Each time the settings page opens, it reads the rule's title, enabled state and fail-closed setting from Shopify, and whether a signing key is set. We display these values and do not store them.
The app requests no access to customers, orders, products or other protected customer data, and it does not receive buyer names, email addresses, phone numbers, delivery addresses, order contents or payment details. The address comparison happens inside Shopify, and Shopify returns only “allow” or “block” to the buyer's checkout.
Information the merchant gives us
- Signing key. If the merchant enters one on the settings page, the app passes it straight to Shopify, where it is saved on the merchant's checkout rule. We do not keep a copy, and the settings page never reads it back.
- Test checkout links. The settings page can build a test checkout link from a sample address. The link is built in the merchant's browser, and the sample address is not sent to our servers.
- Support messages. If you email us, we keep the message and your contact details to answer it.
Information from buyers
None. The app adds no storefront scripts, cookies, pixels or tracking to the merchant's store or checkout.
Logs and cookies
Our hosting provider keeps standard request logs (time, IP address, requested URL and browser user agent) for security and troubleshooting. Requests from the Shopify admin include short-lived Shopify session tokens in the URL. These logs are kept for up to 30 days. The settings page works through Shopify's session tokens and does not use advertising or analytics cookies.
How we use information
Only to install, operate, secure and support the app for the merchant. We do not sell information, use it for advertising, or combine it with other data.
Service providers and location
We host the app on Google Cloud (Cloud Run for the web service, Firestore for shop credentials, Secret Manager for the app's own credentials, and Cloud Logging for request logs). Data is stored in the United States (Google Cloud us-central1). Shopify runs the checkout rule as part of the merchant's store. We share information with no one else, except where the law requires it.
Retention and deletion
See Data retention for each category. In short: shop credentials are deleted when the merchant uninstalls the app, and again on Shopify's shop/redact request 48 hours later. Logs expire after 30 days.
Your rights and requests
Merchants can uninstall the app at any time, which deletes their stored credentials. Buyers and merchants can ask about, correct or delete information by writing to support@aptum.ai. We answer within 30 days. Shopify's customer data and redaction requests reach the app automatically. Because the app holds no buyer records, we confirm them as having no matching data. Privacy questions are handled by Nicholas Graham, Principal.
Security
All traffic uses HTTPS. Shopify webhooks are accepted only with a valid Shopify signature. Shop credentials are stored in Google Cloud, which encrypts them at rest, and only Aptum's service accounts and administrators can read them.
Changes and contact
We will post changes on this page and update the effective date. Contact: support@aptum.ai, Aptum, LLC, 12604 Hallstatt Dr, Manor, TX 78653.
Aptum, LLC · 12604 Hallstatt Dr, Manor, TX 78653