Skip to content
EarnKit

Legal · Version 1.0

Privacy policy

Effective date: September 12, 2026

EarnKit is a Shopify loyalty app. This policy describes how we handle personal information when a merchant installs and uses EarnKit, when their customers participate in the loyalty program, and when you visit our public website or contact support.

Operator: EarnKit is run by James Seymour-Lock, an individual (not a registered company), 442 Lorimer Street, Ste D, PMB #740, Brooklyn, NY 11206, United States.

For merchants, you are generally responsible for telling your customers how your store uses their information. EarnKit processes customer data on your instructions to run the loyalty program you configure. This policy explains what EarnKit itself collects and does.

Who we are and how to contact us

EarnKit is operated by the person named above. Questions about this policy or about how we handle data in the app can be sent to support@earnkit.app.

That address is also shown in the embedded app.

Our role: we process data on the merchant’s behalf

When a merchant installs EarnKit, the merchant decides to run a loyalty program and what it rewards. EarnKit runs that program for them. In data-protection terms the merchant is the controller of their customers’ data, and EarnKit is a processor acting on the merchant’s instructions. Shopify is a separate controller and processor under its own terms.

For the merchant’s own account details, and for visitors to this website, EarnKit is the controller.

What we collect and why

The tables below describe data the app actually stores or processes today, taken from the implementation rather than from product intentions. Shopify identifiers are always full GIDs, never bare numeric IDs or email addresses.

Customer and order data through Shopify

What Why
Shopify customer GID Tie one loyalty balance, birthday enrolment, and rewards to one person
Points balance and ledger entries Run the loyalty program and let merchants audit how points changed
Shopify order GID and the money that earned points Explain why an order earned the points it did, in the order’s currency
Refund facts needed to reverse points Reverse the correct number of points when money is returned
Loyalty metafields published to Shopify Show balance and program state in Shopify-native surfaces
Birthday (month and day only, if the customer enters it) Award birthday points on the right calendar day. No year is collected.
Referral codes and attributions Pay a referrer when a friend’s first qualifying order completes
Issued discount codes (stored, never logged) Let a shopper find a reward they already redeemed

What we do not store about shoppers: name, email address, phone number, or postal address. The app does not write those fields to our database.

Referral codes carry no part of anyone’s name. At the protected-data level this app requests and ships with, first name is not available to it at all: the operation that could read one is gated off, so codes are generated from a random suffix alone (for example, 4K7M). On erasure the code string is replaced with a hash tombstone. (An earlier draft of this policy described codes as carrying up to two letters of the referrer’s first name. That describes a capability behind a gate that is closed, and stating it here would have described data we do not process.)

Operational records of an active store (webhook receipts, audit events, completed and failed background jobs, and referral link opens) are kept to run, debug, and evidence the service. Job payloads for birthday awards carry a customer GID and an award date, which together identify a birthday; those payloads are scrubbed when Shopify sends a customer erasure request, except for queued customer-merge jobs that must retain the linkage until they run so an erasure reaches every ID for the same person.

Merchant and staff data

What Why
Shop identifier and install/session state Authenticate staff in the embedded app and scope every database row to one store
Staff name and email in the Shopify session Login state for the Shopify App Bridge session. This is merchant staff data, not shopper data
Loyalty program settings and their change history Remember how you configured earning, rewards, and referrals
Billing relationship through Shopify Charge for the app per the App Store listing

We do not use shopper birthdays for authentication or identity verification.

Public website

The marketing site at earnkit.app is static HTML on Cloudflare. It does not run the loyalty database. Visiting it may send your IP address and browser metadata to Cloudflare. The pages load their fonts from earnkit.app itself and request nothing from any other company, and we do not use analytics pixels on the public site today.

If you submit the early access form, a Cloudflare Worker emails the work email address, store address and monthly order band you entered to EarnKit so we can review and answer your request. What you type is sent only when you submit the form, and it is not written to the loyalty database. Visiting the page without submitting still involves Cloudflare, as described above.

  • For the merchant’s customers, EarnKit processes data on the merchant’s instructions, under the merchant’s terms and the merchant’s own legal basis.
  • For the merchant’s account and program settings, processing is necessary to provide the service the merchant installed.
  • For this website, processing is what is needed to serve the pages you request and to answer an early access request if you choose to send one.

EarnKit does not sell personal data, does not use it for advertising, and does not profile anyone or make automated decisions with legal effect. Points are awarded by the rules the merchant configured, applied the same way to every order.

Where we process and store data

Application data (loyalty balances, ledger entries, settings, and operational records) is stored in PostgreSQL on Railway and processed by the EarnKit app service on Railway.

Primary processing region: United States.

Shopify processes store and customer data on its own infrastructure worldwide under the merchant’s Shopify relationship. Subprocessors listed below may process data in other countries. Where law requires safeguards for international transfers, we rely on the merchant’s use of Shopify and on each provider’s standard contractual terms. Where a provider is certified under the EU-U.S. Data Privacy Framework (with its UK Extension) or the Swiss-U.S. Data Privacy Framework, we rely on that certification; otherwise we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which our Terms incorporate for merchants who need them.

Subprocessors

We use the following categories of service providers to run EarnKit. Each processes only what is needed for its role:

Provider Role Data involved
Shopify Commerce platform, APIs, webhooks, discount issuance, metafields Store, customer, and order identifiers and facts the app requests through authorised scopes
Railway Application hosting and PostgreSQL database All tenant data described in this policy
Sentry Error monitoring and runtime logs Structured operational logs, designed to exclude customer identifiers, tokens, discount codes and request bodies; 30-day log retention on the current plan
Cloudflare Static hosting for the public marketing website, and intake for the early access form Visitor connection metadata for pages on earnkit.app; for a submitted early access request, the work email address, store address and order band; no loyalty database
GitHub CI workflows and encrypted database backup artifacts Backup files derived from PostgreSQL; artifacts expire after 29 days

We do not sell personal information. We do not use customer data for advertising profiles.

How long we keep data

The table below lists the retention periods EarnKit enforces today. We state only periods that are actually running, not periods we intend to adopt.

Data class Retained until
Points ledger, balances, redemptions, and related financial history Life of the install; erased only when the store is deleted through shop/redact, completed within 30 days of Shopify’s signal
Shop settings and settings history Life of the install; shop/redact
Completed background jobs 14 days after completion, except permanent idempotency markers, which are kept for the life of the install by design
Webhook receipts for order-update events, once processed 90 days after processing
Other webhook receipts, failed and dead jobs, audit events, referral visit evidence Kept for the life of the install. We intend to shorten this to 90 days, but the deletion work is not running yet, and this policy does not promise a period we do not yet enforce
Referral funnel aggregate counters (per shop, no customer rows) Life of the install; shop/redact
Redaction tombstones (shop/redact and customers/redact completion records) Kept for the life of the install. We intend to shorten this to 90 days after completion, but nothing deletes tombstones yet. A tombstone names no customer and no shop domain by design. It carries identifiers, timestamps and a backup deadline only
Early access requests (work email address, store address, monthly order band) Held in EarnKit’s intake mailbox. No automated deletion period is enforced today
Database backup files (pg_dump in GitHub Actions) 29 days from creation
shop/redact erasure work Completed within 30 days of Shopify’s signal
customers/redact erasure work Completed within 30 days of Shopify’s signal
Data-request answer artifacts (customers/data_request) if never collected 45 days after the answer is ready
Data-request answer artifacts after collection 7 days after collection
Birthday enrolment Until customers/redact deletes it, or the install ends
Runtime logs in Sentry 30 days (provider plan setting)

This policy states what is enforced, not what is planned. We intend to shorten the period for operational records and tombstones to 90 days, but the deletion work that would apply it is not running yet. Until it is, the classes listed above as “life of the install” are kept for that longer period. We will update this policy in the same change that shortens them, not before.

Deletion, redaction, and data requests

EarnKit responds to Shopify’s mandatory compliance webhooks:

customers/data_request

When a customer requests their data, Shopify notifies us. We assemble an answer from what we hold about that customer before any erasure runs, so a request made before deletion is still answered. Answers expire on the schedule in the retention table above.

customers/redact

When a customer asks to be forgotten, Shopify sends customers/redact. We process it in a single database transaction. Depending on the row, we delete personal data, disassociate it from the customer while keeping merchant accounting intact, or retain financial-history rows the merchant’s liability depends on:

  • Deleted: birthday enrolment, referral links and attributions, paid-order evidence tied to the shopper, pending awards, and similar rows that exist only to describe the person.
  • Disassociated: order earning decisions keep the order and reason but lose the customer link.
  • Retained: points ledger entries and balances stay as financial history; the shopper receives no further awards because a stop marker is written in the same transaction.

A redaction reaches every Shopify customer ID we know for the same person, including IDs merged in Shopify.

shop/redact

When a merchant uninstalls, Shopify eventually sends shop/redact. We erase that shop’s tenant data (settings, balances, ledger, operational rows, and backups on the schedule above) within 30 days of the signal. A tombstone recording that erasure is retained so an older backup cannot restore deleted data without a record of the erasure; see the retention table above for how long tombstones are currently kept.

Your rights as a merchant

You can access and change your loyalty program settings in the embedded app while the app is installed. You may export customer loyalty data through features the app provides. If you uninstall EarnKit, Shopify’s shop/redact flow triggers deletion of your shop’s data on the timeline above.

Contact support@earnkit.app for questions about your store’s data in EarnKit or to raise a concern. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

Your customers’ rights

If you are a shopper, contact the merchant whose store you shopped to exercise privacy rights. The merchant decides program rules and is responsible for their customer-facing privacy notice.

The merchant can submit customer erasure and data-access requests through Shopify; EarnKit fulfils the technical steps described above. EarnKit does not decide whether to grant a request. That is the merchant’s obligation as controller.

Security

Data travels to and from the app over HTTPS. Every request from Shopify is verified with its signature before it is acted on, and requests from a storefront carry a tenant identity that the caller cannot choose. Customer identifiers, tokens and request bodies are kept out of logs and error reports by lint rules that fail the build and a scrubber that runs before anything is sent. Our database host, Railway, lists encryption at rest among the data-security controls in its Trust Center (trust.railway.com) and holds a SOC 2 Type 2 report.

If an incident affects a merchant’s data, EarnKit will tell the merchant by email from support@earnkit.app as soon as the facts are established.

Changes to this policy

We may update this policy when collection, retention, subprocessors, or legal requirements change. When we do, we will post the new version on this page with an updated effective date and version number. Material changes that affect how we process customer data will be communicated to installed merchants through the app or by email where appropriate.

If you continue using EarnKit after the effective date of an update, you accept the revised policy to the extent permitted by law.