Privacy policy
Appal: Discount & Free Gift. Last updated 25 July 2026.
What the app stores
The app stores the promotions you create and your app settings. Every record is keyed to your shop domain. Concretely that is: offer configuration (thresholds, selected products and collections, discount values, schedules), widget and storefront settings, bulk discount code job records, and the Shopify session token needed to call the Admin API on your behalf.
Customer personal data
The app does not collect or store personal data about your customers. It does not request customer scopes, and it does not read customer records, orders, or contact details. Discounts are evaluated inside Shopify by a Shopify Function at the moment a cart is priced, and the storefront script reads only the current cart contents in the shopper’s own browser to decide whether a gift qualifies. That cart data is not sent to us or retained.
Data we access from Shopify
With your permission the app reads products and collections so you can select them when building a promotion, and it creates and updates discounts on your store. The requested scopes are write_discounts, write_cart_transforms and read_products.
Sharing
We do not sell your data and we do not share it with third parties for advertising. Data is processed by our hosting and database provider (Railway) solely to run the service.
Retention and deletion
When you uninstall the app we remove the stored session for your shop. Shopify’s mandatory shop/redact request, which arrives 48 hours after uninstall, triggers deletion of everything else we hold for that shop: offers, settings and bulk code job records. You can also request deletion at any time by emailing us.
Your requests
The app answers Shopify’s customers/data_request, customers/redact and shop/redact webhooks. Because no customer personal data is stored, the first two have nothing to return or erase.
Contact
Email support@appal.io with any privacy question or deletion request.