Aptum Checkout Protection

Privacy policy

Effective October 1, 2026. This policy explains what Aptum Checkout Protection (the “app”), provided by Aptum, LLC, collects when a Shopify merchant installs it, why, how long it is kept, and how to reach us.

What the app does

The app adds one checkout rule to the merchant's Shopify store. On a quote checkout, the rule compares the delivery address the buyer enters with the address the quote was prepared for and stops payment if they differ, or if the quote has expired or its signature cannot be verified. That comparison runs inside Shopify's checkout (as a Shopify Function). It does not run on our servers.

Information we collect through Shopify's APIs

The app requests no access to customers, orders, products or other protected customer data, and it does not receive buyer names, email addresses, phone numbers, delivery addresses, order contents or payment details. The address comparison happens inside Shopify, and Shopify returns only “allow” or “block” to the buyer's checkout.

Information the merchant gives us

Information from buyers

None. The app adds no storefront scripts, cookies, pixels or tracking to the merchant's store or checkout.

Logs and cookies

Our hosting provider keeps standard request logs (time, IP address, requested URL and browser user agent) for security and troubleshooting. Requests from the Shopify admin include short-lived Shopify session tokens in the URL. These logs are kept for up to 30 days. The settings page works through Shopify's session tokens and does not use advertising or analytics cookies.

How we use information

Only to install, operate, secure and support the app for the merchant. We do not sell information, use it for advertising, or combine it with other data.

Service providers and location

We host the app on Google Cloud (Cloud Run for the web service, Firestore for shop credentials, Secret Manager for the app's own credentials, and Cloud Logging for request logs). Data is stored in the United States (Google Cloud us-central1). Shopify runs the checkout rule as part of the merchant's store. We share information with no one else, except where the law requires it.

Retention and deletion

See Data retention for each category. In short: shop credentials are deleted when the merchant uninstalls the app, and again on Shopify's shop/redact request 48 hours later. Logs expire after 30 days.

Your rights and requests

Merchants can uninstall the app at any time, which deletes their stored credentials. Buyers and merchants can ask about, correct or delete information by writing to support@aptum.ai. We answer within 30 days. Shopify's customer data and redaction requests reach the app automatically. Because the app holds no buyer records, we confirm them as having no matching data. Privacy questions are handled by Nicholas Graham, Principal.

Security

All traffic uses HTTPS. Shopify webhooks are accepted only with a valid Shopify signature. Shop credentials are stored in Google Cloud, which encrypts them at rest, and only Aptum's service accounts and administrators can read them.

Changes and contact

We will post changes on this page and update the effective date. Contact: support@aptum.ai, Aptum, LLC, 12604 Hallstatt Dr, Manor, TX 78653.


Aptum, LLC · 12604 Hallstatt Dr, Manor, TX 78653