Digitdeck

Developer Privacy Policy

Last updated: July 27, 2026

Scope and roles

DIGIT DECK AGENCY S.A.S. (“Digitdeck”) operates a modular Shopify app. For shopper data processed to provide merchant-selected features, the merchant is generally the controller and Digitdeck acts as processor/service provider. Digitdeck is an independent controller for merchant contacts, support, security, legal compliance, and business administration.

Information processed

Depending on enabled modules, data can include store identity and configuration; catalog and inventory; order/customer identifiers and email where required; back-in-stock subscriptions; review content; referral attribution and rewards; pseudonymous experiment events; merchant prompts and AI drafts; billing state; and security/audit records. Digitdeck does not intentionally collect payment-card numbers.

Purposes

Data is used to authenticate installations, provide enabled modules, send requested transactional communications, create discounts and rewards, moderate reviews, measure usage, enforce limits, secure and debug the Service, provide support, and meet Shopify or legal obligations. Digitdeck does not sell personal information.

AI and tracking

Optional AI features send only merchant-selected context needed for generation and require human review. Storefront modules may use pseudonymous identifiers for referrals or experiments. Merchants must provide required privacy and cookie notices and use Shopify consent mechanisms where applicable.

Providers and international transfers

Digitdeck uses Shopify and providers for hosting, databases, queues, transactional email, optional AI, and support. Access is limited and contractually protected. See the Subprocessor List. Processing may occur in Colombia, the United States, or a configured cloud region using legally required transfer safeguards.

Retention and Shopify privacy webhooks

Data is retained only while needed. Digitdeck verifies and processes Shopify's mandatory data-request and redaction webhooks. Customer-linked records are deleted for valid redaction events. After uninstall, operational access is disabled and Merchant Data is deleted within Shopify's required period, normally no later than thirty days unless law requires retention.

Security

Controls include tenant isolation, encrypted access tokens, TLS, webhook HMAC and signed App Proxy verification, least privilege, rate limiting, idempotent jobs, audit records, and incident response. No system is completely secure.

Rights and contact

Depending on law, individuals can request access, correction, deletion, restriction, portability, withdrawal, or objection. Shopify customers should normally contact the relevant merchant first. Requests may also be sent with the store domain to digitdeck.servicios@gmail.com.