WasNow

Privacy policy

Effective September 12, 2026

In short

What the app can access

The app requests exactly these Shopify access scopes. Shopify lets it manage its own app-installation metafields without an additional write scope:

What is stored, and where

On WasNow's application hosting, database, cache and job queue: Shopify shop and installation identifiers and domains; store contact email and owner name; timezone, currency, published languages, theme and plan status; app settings; OAuth access and refresh credentials; cached discounts, collection membership and product identifiers; compiled display rules; and sync and error metadata. Background jobs carry the shop domain and task-specific Shopify object identifiers or status. Application logs and optional Rollbar error reports may contain the shop domain and technical diagnostics; Rollbar's dedicated user-IP collection is disabled and common forwarded-IP headers are scrubbed. Request parameters containing secrets or Shopify privacy-webhook customer details are filtered. A compliance receipt stores only the webhook topic, shop domain and receipt time. Necessary merchant-admin app sessions may store the selected language and a CSRF security token and use an app-session cookie. A daily cleanup deletes session records older than 30 days. The storefront extension does not use that cookie. WasNow suppresses its application access log for the sampled storefront counter, while the hosting and content-delivery edge may still process IP address, user agent, storefront origin and other ordinary HTTPS metadata.

What is written to Shopify

WasNow writes compiled display rules and settings only to app-owned metafields on its Shopify app installation. It does not write products, variants, prices, compare-at prices, discounts or theme files.

What is never stored

WasNow's application database and job queue store no customer records, order data, shopper email addresses, shopper browsing profiles, storefront shopper cookies or advertising identifiers. The sampled counter stores only aggregate shop-level totals and no page URL or persistent shopper identifier. Shopify sends mandatory privacy webhooks, but WasNow discards their customer details instead of saving them to its database, job queue or compliance receipt.

The storefront script

WasNow's storefront script sends the store domain, the sampling rate and counts of page views and prices displayed. The request payload contains no customer, cart or order data, page URL, cookie or persistent shopper identifier. It explicitly omits credentials and the referrer. Like every HTTPS request, it still exposes ordinary network metadata such as IP address, user agent and storefront origin to the hosting and content-delivery edge. WasNow suppresses its own application access log for this endpoint. This request is sent for a sample of page views; the resulting counts are aggregated by shop and day and are used only for the "prices displayed" numbers on the app's home page.

Sub-processors

Shopify (the platform, content delivery and app-owned metafields), the hosting, database, cache and job-queue providers configured for the deployed service, Rollbar when error reporting is enabled, and the configured email provider for account emails. Ask the support address below for the current provider list.

Retention and deletion

Shopify removes the app embed and app-owned metafields on uninstall. Receipt of the uninstall webhook stops scheduled access and queues deletion of the operational shop record and its database caches; Shopify's shop-redact webhook is a cleanup backstop. Sampled storefront counters expire after 8 days, and a daily cleanup deletes session records older than 30 days. Pending or retrying jobs, application logs, hosting/content-delivery access or security logs and optional error reports follow the retention configured for the deployed queue and providers; ask the support address below for the current periods. Those infrastructure logs can temporarily contain IP address, user agent, storefront origin and other network diagnostics even though the sampled payload omits them. A minimal compliance log containing the topic, shop domain and receipt time is retained for auditing until the merchant asks for its deletion. Customer details from data-request and redact webhooks are not retained.

Your rights

Email the address below at any time to ask for a copy of what is held about your store, or to ask for the operational data and compliance log to be deleted.

Questions about this policy: elias@youorder.it. YouOrderit, Barranquilla, Colombia.