VaultGate
Privacy Policy
How VaultGate processes merchant and customer-related data when you use the app.
VaultGate (“we”, “our”) is a Shopify app by AVOITS that provides Online Store access control (locks and keys) for merchants.
Data we process
- Shop data: shop domain, app settings, lock and key configuration, and subscription or trial status.
- Customer-related data: customer id, tags, and email only as needed to evaluate merchant-configured access rules; unlock event logs (timestamps, lock id, condition type, success or failure).
- Session data: Shopify offline session tokens required for the embedded admin app.
How we use data
Data is used only to operate VaultGate: authenticate merchants, enforce access rules on the Online Store channel, show unlock analytics, bill through Shopify, and provide support. We do not sell merchant or customer data.
Where data is stored
App data is stored on our hosting infrastructure used to run VaultGate for your shop. Access is limited to operating and supporting the service.
Shopify compliance requests
VaultGate implements Shopify’s mandatory webhooks: customers/data_request, customers/redact, and shop/redact.
- Data request: when Shopify sends a customer data request, we collect any unlock events tied to that customer id for the shop and store a structured export for fulfillment. Contact info@avoits.com if you need a copy within Shopify’s required timeline.
- Customer redact: unlock events for that customer id are deleted.
- Shop redact / uninstall: shop settings, locks, keys, unlock logs, and sessions for that shop are deleted.
Data retention and deletion
- On app uninstall we remove shop settings, locks, keys, and unlock logs associated with that shop.
- Merchants may also email info@avoits.com for privacy questions or deletion requests.
Third parties
VaultGate runs as an embedded Shopify app and uses Shopify APIs and Shopify App Pricing / Billing. We do not share your data with unrelated marketing platforms.
Contact
Privacy questions: info@avoits.com