Developer Privacy Policy
Last updated: July 27, 2026
Scope and roles
DIGIT DECK AGENCY S.A.S. (“Digitdeck”) operates a modular Shopify app. For shopper data processed to provide merchant-selected features, the merchant is generally the controller and Digitdeck acts as processor/service provider. Digitdeck is an independent controller for merchant contacts, support, security, legal compliance, and business administration.
Information processed
Depending on enabled modules, data can include store identity and configuration; catalog and inventory; order/customer identifiers and email where required; back-in-stock subscriptions; review content; referral attribution and rewards; pseudonymous experiment events; merchant prompts and AI drafts; billing state; and security/audit records. Digitdeck does not intentionally collect payment-card numbers.
Purposes
Data is used to authenticate installations, provide enabled modules, send requested transactional communications, create discounts and rewards, moderate reviews, measure usage, enforce limits, secure and debug the Service, provide support, and meet Shopify or legal obligations. Digitdeck does not sell personal information.
AI and tracking
Optional AI features send only merchant-selected context needed for generation and require human review. Storefront modules may use pseudonymous identifiers for referrals or experiments. Merchants must provide required privacy and cookie notices and use Shopify consent mechanisms where applicable.
Providers and international transfers
Digitdeck uses Shopify and providers for hosting, databases, queues, transactional email, optional AI, and support. Access is limited and contractually protected. See the Subprocessor List. Processing may occur in Colombia, the United States, or a configured cloud region using legally required transfer safeguards.
Retention and Shopify privacy webhooks
Data is retained only while needed. Digitdeck verifies and processes Shopify's mandatory data-request and redaction webhooks. Customer-linked records are deleted for valid redaction events. After uninstall, operational access is disabled and Merchant Data is deleted within Shopify's required period, normally no later than thirty days unless law requires retention.
Security
Controls include tenant isolation, encrypted access tokens, TLS, webhook HMAC and signed App Proxy verification, least privilege, rate limiting, idempotent jobs, audit records, and incident response. No system is completely secure.
Rights and contact
Depending on law, individuals can request access, correction, deletion, restriction, portability, withdrawal, or objection. Shopify customers should normally contact the relevant merchant first. Requests may also be sent with the store domain to digitdeck.servicios@gmail.com.