Privacy Policy
1) Overview
This policy explains how Segment Pricing collects, uses, and stores information when a merchant installs or uses the app in connection with their Shopify store. The app lets merchant staff define segment tiers and per-product values, then applies the correct tier automatically at checkout for customers assigned to a segment.
Shopify processes many categories of data under Shopify policies. This policy covers only the data handled by VAZA s.r.o. through the app.
2) Information accessed from Shopify
The app accesses the following data via Shopify APIs only to provide the app functionality:
- Shop identifiers (shop domain, shop ID) and installation status.
- Shop metafield custom.b2b_segments (array of segment names).
- Product and variant identifiers and base catalog values.
- Product/variant metafield custom.segment_prices (JSON mapping of segment name to value).
- Customer identifiers and customer metafield custom.b2b (single segment name).
- Shopify Customer Segments managed by the app via Segment APIs (create/update/delete).
3) Information collected directly from merchants
- Segment (tier) names configured in the app.
- Per-product tier values entered in the admin grid.
- Bulk adjustment inputs (percent or fixed amount) when used.
4) Technical data
- Log data (timestamp, request path, error logs, user agent).
- Authentication and authorization events.
- Operational metrics (response times, error rates).
We do not sell personal information or use it for advertising.
5) How we use information
- Provide and operate the app.
- Write app configuration to Shopify metafields.
- Apply automatic discounts at checkout for eligible customers.
- Sync app-managed Shopify Customer Segments.
- Provide support, troubleshoot, and maintain security.
- Comply with legal obligations.
6) Where data is stored
Primary configuration data is stored in Shopify using metafields described above. The app may also store limited operational data outside Shopify, such as store identifiers, installation state, API tokens, and segment mapping IDs.
Hosting/subprocessors: Vercel for hosting and MongoDB for persistent storage, used only to provide infrastructure services.
7) Sharing and disclosure
- With Shopify via Shopify APIs to deliver app functionality.
- With service providers (hosting, database, logging) under contract.
- For legal reasons if required by law or lawful request.
- During business transfers, subject to appropriate safeguards.
8) Data retention
Shopify metafields remain until the merchant edits them or uninstalls the app. External operational data is retained only as long as needed to provide the app and comply with legal obligations.
9) Security
We use reasonable administrative, technical, and physical safeguards, including access controls and encryption where appropriate. No method of transmission or storage is 100% secure.
10) International transfers
Data may be processed in countries outside the merchant's jurisdiction where our providers operate. We rely on appropriate safeguards for cross-border transfers.
11) Privacy requests
Merchants can request access, correction, or deletion related to app-processed data by contacting info@vaza.digital. Customers should contact the merchant first.
12) Shopify mandatory privacy webhooks
We respond to Shopify's compliance webhooks as required:
- customers/data_request
- customers/redact
- shop/redact
13) Changes to this policy
We may update this policy from time to time. Material changes will update the effective date above.
14) Contact
VAZA s.r.o.
Email: info@vaza.digital
Address: Jenisejská 2441/45A, Košice - mestská časť Nad jazerom 040 12