PayShield

Privacy policy

Last updated September 9, 2026

PayShield is a Shopify app that lets merchants control which payment and delivery methods appear at checkout. This policy explains what data the app touches, why, and what happens to it.

Data we store

Store identity and API access
Your store's domain and an access token issued by Shopify so the app can read and write its own settings. Stored in a session database hosted by Vercel (application) and Neon (session database).
Your rules
The rules you create (conditions, method names, new names) are saved as metafields inside your own Shopify store. They never leave Shopify's infrastructure.

Data we do not store

The app does not collect, store or transmit customer personal data. Rules are evaluated by a Shopify Function that runs inside Shopify checkout. During a checkout the Function receives cart totals, the shipping country, whether the customer is logged in, order count, amount spent, and whether the customer or products carry the tags you configured. That data is processed in memory by Shopify for the duration of the checkout and is not sent to our servers or retained.

The app requests only the permissions needed to manage payment and delivery customizations. It does not request access to orders, customers, or products.

Third parties

The admin interface is hosted on Vercel and the session database on Neon. Both act as data processors for the store identity data described above. We do not sell or share data with anyone else.

Retention and deletion

When you uninstall the app, Shopify notifies us and the store's session data is deleted. Your rules, stored as metafields in your store, are removed by Shopify together with the app. We respond to Shopify's mandatory privacy webhooks (customer data requests, customer data erasure, and shop data erasure) within the required period; since the app holds no customer data, those requests require no export.

Security

All traffic uses HTTPS. Requests from Shopify are verified with signed session tokens or HMAC signatures. Access tokens are stored server-side only.

Changes

We will update this page when the app's data handling changes and record the date above.

Contact

Questions about privacy: support@dczt.dev