Privacy Policy

Last updated: March 1, 2026

1. Introduction

This Privacy Policy explains how Gifton ("we," "us," or "our") collects, uses, stores, and protects information when you install and use the Gifton app on your Shopify store. Gifton is a Shopify app that enables gift wrapping, personalized gift messages, and voice gift notes for online stores.

By installing or using Gifton, you agree to the practices described in this policy. If you do not agree, please uninstall the app.

2. Information We Collect

2.1 Information Collected via Shopify APIs

When you install Gifton, we access certain information through Shopify's APIs to provide the app's functionality:

Data Purpose
Store domain & name Identify your store and configure the app
Access token Authenticate API requests to your Shopify store
API scopes Determine what data the app can access
Product data Create and manage gift wrap products in your catalog
Order line item properties Attach gift messages and voice note references to orders

2.2 Information Collected Directly from Merchants

We collect information that you provide when configuring the app:

  • Gift wrap product details (title, description, price, images)
  • Gift message settings (default templates, character limits, font preferences)
  • Voice message settings (enable/disable, max duration, retention period)
  • Storefront display preferences (which surfaces to show gift wrap on)
  • Subscription and billing preferences (plan selection)

2.3 Information Collected from Customers

When your customers interact with gift wrap features on your store, the following data may be collected:

  • Gift message text — Written by the customer when adding gift wrap. Stored as a Shopify line item property on the order.
  • Voice message audio — Recorded by the customer in their browser (up to 30 seconds). Stored securely on our servers.
  • Voice message metadata — Recording duration, creation timestamp, and expiration date.

We do not collect customer names, email addresses, payment information, or any other personal data beyond what is described above.

2.4 Automatically Collected Information

We generate standard server logs when requests are made to our app endpoints. These logs may include IP addresses, request timestamps, and user agent strings. Logs are used solely for debugging and security purposes and are retained for a limited period.

3. How We Use Your Information

We use the information we collect solely to provide, maintain, and improve the Gifton app:

Data How We Use It
Store credentials Authenticate your store, manage API requests, and sync product data
Gift wrap settings Configure and display gift wrapping options on your storefront
Gift messages (text) Attach to orders as line item properties for fulfillment and receipts
Voice messages (audio) Store securely and provide playback access via unique links and QR codes
Subscription data Manage your plan, feature access, and billing through Shopify
Server logs Monitor app performance, debug issues, and detect security threats

We do not sell, rent, or trade any personal information to third parties. We do not use your data for advertising, profiling, or marketing purposes unrelated to the app.

4. Data Sharing & Disclosure

We share information only in the following limited circumstances:

  • Shopify — Gift message text and voice note references are stored as line item properties within your Shopify orders. This data is visible in your Shopify admin and is subject to Shopify's privacy policy.
  • Cloud storage providers — Voice message audio files may be stored on third-party cloud infrastructure (such as Amazon Web Services S3). These providers act as data processors under our instruction and are contractually obligated to protect your data.
  • Legal requirements — We may disclose information if required by law, regulation, legal process, or government request.

We do not share data with any other third parties.

5. Data Storage & Security

5.1 Where Data Is Stored

  • App configuration and settings — Stored in our application database.
  • Gift message text — Stored as Shopify line item properties (within Shopify's infrastructure).
  • Voice message audio — Stored on secure cloud infrastructure (Amazon S3 or equivalent).
  • Subscription data — Managed through Shopify's billing system.

5.2 Security Measures

We implement the following measures to protect your data:

  • All data in transit is encrypted via HTTPS/TLS.
  • Voice messages are accessible only via unique, cryptographically secure tokens (128-bit entropy).
  • Shopify API tokens are stored securely and never exposed to the frontend.
  • App proxy endpoints verify request signatures to prevent unauthorized access.
  • Access to production systems is restricted to authorized personnel.

6. Data Retention

We retain data only as long as necessary to provide the app's functionality:

Data Retention Period
App settings & configuration Retained while the app is installed. Deleted upon uninstallation.
Subscription records Retained while the app is installed. Deleted upon uninstallation.
Voice message audio Retained for the duration set by the merchant (maximum 30 days, default 30). Automatically deleted after expiration.
Voice message metadata Deleted when the audio is deleted or upon app uninstallation.
Gift message text Stored as Shopify order properties. Retained by Shopify as part of order data.
Server logs Retained for up to 30 days, then automatically purged.

What Happens When You Uninstall

When you uninstall Gifton, the following data is deleted:

  • All app settings and configuration
  • All voice message audio files (purged from cloud storage)
  • All voice message metadata and playback tokens
  • Subscription and session data

Gift wrap products remain in your Shopify catalog (you can delete them manually). Past orders with gift wrap line items and messages are retained by Shopify as part of your order history.

7. Your Rights

7.1 Merchant Rights

As a merchant using Gifton, you have the right to:

  • Access — View all data stored by the app through your Gifton dashboard.
  • Correction — Update your settings and configuration at any time.
  • Deletion — Uninstall the app to delete all stored data. You can also contact us to request deletion.
  • Data portability — Request a copy of your stored data by contacting us.

8. Cookies & Tracking

Gifton does not use cookies, tracking pixels, or any client-side tracking technology. We do not track your customers' browsing behavior, and we do not use analytics services that collect personal data from your storefront.

The app uses Shopify's built-in app proxy for storefront requests, which operates within Shopify's existing cookie and session framework.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or app features. When we make changes:

  • We will update the "Last updated" date at the top of this policy.
  • For material changes, we will notify you via email or an in-app notification.

We encourage you to review this policy periodically. Your continued use of Gifton after changes are posted constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions about this Privacy Policy, your data, or how Gifton handles information, please contact us:

Email: admin@thedoubledots.com

Developer: Doubledots

We aim to respond to all privacy-related inquiries within 5 business days.