Privacy Policy
Last updated: May 2026
What data we collect
ConsentGuard collects and stores the following data when installed on a Shopify store:
- Store information: Your myshopify.com domain and plan preferences (which ConsentGuard tier you subscribe to).
- Consent block configuration: The consent blocks, display rules, and translations you create in the app.
- Consent audit records: When a customer completes checkout, we record which consent blocks were displayed, whether they were accepted, the order number and name, the locale, a snapshot of the exact consent text shown, and the timestamp.
- Buyer technical identifiers: We also record the buyer's IP address and browser user-agent at the moment consent was given. These are personal data under the GDPR. We collect them for one purpose only: so the consent record can be used as evidence in a chargeback or dispute, where an unattributable record is worthless. We do not use them for tracking, profiling, advertising, or analytics, and we never sell or share them.
- What we do not collect: We do not store customer names, email addresses, phone numbers, shipping or billing addresses, or payment details.
How we use your data
Data is used solely to provide the ConsentGuard service: displaying consent blocks during checkout and maintaining an audit log of consent events for your compliance records.
Data retention
Audit log records are retained according to your plan: 30 days on the Free plan, or 365 days on Pro. You can configure a shorter retention period in the app settings. Records are deleted automatically once the retention period elapses.
Data sharing and sub-processors
We do not sell or rent your data. Consent records are only accessible to you, through the Shopify admin.
We use the following sub-processors to operate the service:
- Railway — application hosting and the PostgreSQL database where consent records are stored.
- Resend — transactional email. Resend receives your shop domain and the alert email address you configure. It never receives buyer data.
Data deletion
When you uninstall ConsentGuard, all your data (consent blocks, settings, and audit records) is automatically deleted. You can also request data deletion by contacting us.
GDPR compliance
ConsentGuard handles all mandatory Shopify GDPR webhooks: customer data requests, customer data erasure, and shop data erasure. When Shopify sends a data deletion request, the relevant records are removed from our database.
Contact
For privacy questions or data requests, contact us at: giorgimazm@gmail.com