Privacy Policy
Last updated: September 30, 2026
Introduction
Elite Post Purchase ("the App") is a Shopify app that shows buyers an offer on Shopify's post-purchase page, right after they pay and before the thank-you page. The App and this website are provided by GEFA Technology AB, a Swedish company ("we", "us"). This policy explains what data we process when a merchant uses the App, when buyers reach a merchant's post-purchase page, and when you visit this website.
For the data about merchants and their stores described below, we are the controller. For buyer and order data we process to run a merchant's post-purchase page, we act on behalf of that merchant.
Access the App asks Shopify for
When you install the App, you grant it these Shopify access scopes:
- Read and write orders (
read_orders,write_orders): to keep a minimal record of your orders (see below) and to tag orders with an accepted offerElitePostPurchase. - Read and write order edits (
read_order_edits,write_order_edits): to add an accepted offer to the buyer's order, and to read which order edits were made by the App. - Read products (
read_products): to let you choose products for your offers. - Read product listings (
unauthenticated_read_product_listings): to show offered products and check collection conditions on the post-purchase page. For this, the App stores a Storefront API token in a metafield on your store. - Read checkout branding (
read_checkout_branding_settings): to use your checkout colors in the offer preview in the App. - Read locales (
read_locales): to know which languages your store sells in, for the checkout text.
What we store about your store
- Store details: your myshopify domain, store name, Shopify plan, the date your store was created, its currency and languages, and when you installed and uninstalled the App.
- Billing: your subscription status, free-trial dates, billing cycle, and a record of every usage charge.
- Your offers: the flows, conditions, designs, products, discounts, shipping settings and checkout texts you create in the App.
- Access tokens: the Shopify access tokens that let the App work with your store, stored encrypted. When a staff member opens the App, Shopify also issues a token for that staff member together with basic account details (such as their name, email address and language), which is stored with it, encrypted.
Orders and buyers
We do not store buyers' names, email addresses, postal addresses, phone numbers or payment details. The App asks Shopify for a limited set of order fields, so this data is not sent to us in the first place. For each order placed while the App is installed, we store:
- the order's ID, name (such as #1001) and checkout token;
- when it was created, updated or cancelled, its currency, its sales channel and whether it is a test order;
- for orders with an accepted offer: the amount added by the App and when the order was tagged.
We use this to count your orders for billing and to show you what your offers sold. The App may also check this record against your orders in Shopify to fill any gaps.
On the post-purchase page, Shopify gives the App signed details of the purchase, such as the products, quantities, order total and language (and, where the buyer has a customer account, their Shopify customer ID). The App uses these to pick which offer to show and to check an accepted offer before Shopify adds it to the order. We do not store them. When a buyer accepts an offer, we store the checkout's reference ID, which of your flows it belongs to, the product variant accepted and the signed change sent to Shopify.
Our servers keep request logs for security and debugging. We deliberately keep buyer data, access tokens and request bodies out of these logs.
Notifications to our team
When a store installs, reinstalls or uninstalls the App, we send a message to our team's Slack workspace with the store's name, myshopify domain, Shopify plan and age. For uninstalls it also includes the subscription status (for example on trial or paying) and the total the store has been charged.
Shopify's privacy webhooks
- Customer data request (
customers/data_request): the App stores no customer names, contact details or customer IDs, so there is no customer data to return. The request is acknowledged. - Customer erasure (
customers/redact): the App holds no customer record to erase. The request is acknowledged. The order records described above are deleted with the rest of your store's order data (next item). - Shop erasure (
shop/redact, sent by Shopify 48 hours after you uninstall, unless you reinstall first): we delete your store's order records, the records of accepted offers, and any remaining access tokens.
Retention
When you uninstall the App, we delete its access tokens for your store straight away. Order records and the records of accepted offers are deleted when Shopify sends the shop erasure request described above.
We keep your store details, your offer settings and your billing history after you uninstall. This lets a reinstall pick up where you left off and keeps the free trial to once per store, and billing records are part of our accounting. To have them deleted, email us at contact@elitecart.app; we will delete what we are not required to keep.
Service providers
We use these providers to run the App and this website:
- Shopify: the platform the App runs on, including checkout, order data and billing.
- Cloudflare: hosts the App's servers and their request logs.
- PlanetScale: hosts the App's database.
- Slack: receives the install and uninstall notifications described above.
- Vercel: hosts this website.
Some of these providers are based in, or process data in, countries outside the EU/EEA, such as the United States and Canada.
This website
When you visit this website, our hosting provider processes technical data such as your IP address and browser details to deliver the pages. The site may store your language and light/dark theme choice in your browser.
If enabled, we use Google Analytics to understand how the website is used, which sets cookies in your browser, and Gleap for the contact chat, which processes the messages you send us through it. If you book a call, Calendly handles the booking. If you email us, we keep the correspondence to answer you.
Why we process data
We process the data above to provide the App you installed (performance of our contract with you), to keep the App secure, fix problems and follow installs and uninstalls (our legitimate interests), and to keep billing records (legal obligations).
Your rights
You can ask us for access to, correction of or deletion of your personal data, ask us to restrict or stop processing it, and ask for a copy of it. Email us at contact@elitecart.app. You can also complain to the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.
Buyers who want to exercise their rights regarding an order should contact the store they bought from; Shopify passes their requests on to us as described above.
Changes to this policy
We may update this policy to reflect changes to the App, our practices or the law. The date at the top shows when it last changed.
Contact
GEFA Technology AB, Sweden. For questions or complaints about our privacy practices, email us at contact@elitecart.app.