Our Privacy Commitment
StackBar is built to be as light on data as it is on your storefront. It requests zero access scopes and collects no customer or order data. Your bar settings are stored inside your own Shopify store, and the storefront makes no external requests.
1. Introduction
This Privacy Policy explains how StackBar ("the App", "we", "us", or "our"), developed and operated by Tappect, handles information when a Shopify merchant installs and uses the App. StackBar adds a free shipping progress bar and an announcement bar to a Shopify online store.
The short version: StackBar installs with no access scopes, so it cannot read your products, orders, customers, or any buyer information. It stores no customer personal data. The only data we retain is the technical session record required to keep your app admin securely signed in.
This policy applies to the merchant who installs the App and to the storefront visitors who see the bars.
2. Data We Do NOT Collect
StackBar does not request access scopes and does not collect any of the following:
- Customer or buyer personal information (name, email, address, phone)
- Order, cart, checkout, or payment data tied to an identifiable person
- Product, inventory, or catalog data
- Marketing profiles, behavioral tracking, or advertising identifiers
- Any storefront visitor analytics or telemetry
Zero access scopes. Because the App is granted no Shopify API permissions to protected data, it is technically unable to access this information at all.
3. Data We Do Process
To operate the App, we process a limited amount of technical, non-customer data:
- Session records: Your store's .myshopify.com domain and the OAuth session token that keeps your embedded app admin securely signed in. This is stored in our database and is required for the App to function.
- Bar settings: The messages, thresholds, colors, placement, and schedule you configure. These are stored as app-data metafields inside your own Shopify store — not in our database.
- Cross-promotion state: A small flag recording whether you dismissed an in-app promotional card or clicked the review link, stored as a metafield in your store.
None of this data identifies a storefront shopper. It relates only to you, the merchant, and your store configuration.
4. The Storefront Bars
The bars shown to your shoppers are rendered by a Shopify theme app embed. On the shopper's device, the App:
- Reads your bar settings from your store's metafields (already delivered with the page)
- Reads the shopper's current cart total from Shopify's own /cart.js endpoint on your domain
- Makes no requests to our servers and loads no third-party scripts
The cart total is read only to display how far a shopper is from free shipping. It is used on-device, in the moment, and is never transmitted to us or stored.
5. Subprocessors & Hosting
The App relies on the following service providers:
- Shopify: Hosts your store, delivers the app embed, and stores your bar settings as metafields.
View Shopify Privacy Policy - Vercel: Hosts the App's embedded admin.
View Vercel Privacy Policy - Supabase: Provides the database that stores the OAuth session records described in Section 3.
View Supabase Privacy Policy
We do not use analytics SDKs, crash-reporting services, advertising networks, or any other third-party data collection tools.
6. Data Retention & Deletion
Session records are retained only while the App is installed. When you uninstall StackBar, Shopify sends us an app/uninstalled webhook and we delete the associated session records. Your bar settings are metafields inside your store and are removed with the App.
We honor Shopify's mandatory data-protection webhooks:
- customers/data_request and customers/redact: We store no customer data, so there is nothing to return or redact; we acknowledge and log the request.
- shop/redact: We delete your store's session records.
7. Data Security
- Minimization: We hold only what is needed to run the App — session records.
- Encryption in transit: All connections use HTTPS/TLS.
- Managed infrastructure: Hosting and the database run on reputable managed providers with encryption at rest.
- Least privilege: Zero Shopify access scopes means the smallest possible attack surface.
8. International Users & Your Rights
Because we do not collect personal data about your customers, most data-subject requests (access, deletion, portability) have nothing to act on. As the merchant, you may request deletion of your store's session records at any time by uninstalling the App or contacting us.
The App is available to merchants worldwide and its admin is localized in 11 languages. Data processing follows the practices described above regardless of region.
9. Children's Privacy
StackBar is a business tool for Shopify merchants and is not directed to children. It collects no personal information from anyone, including children.
10. Changes to This Policy
We may update this Privacy Policy if the App's data practices change. Any changes will be reflected on this page with an updated date. Continued use of the App after an update constitutes acceptance of the revised policy.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: support@usestackable.com
Subject Line: StackBar Privacy Inquiry
Developer: Tappect
App: StackBar — Free Shipping Bar & Announcement Bar for Shopify