In short. Smart BOGO stores information about the store that installs it and the gift campaign that store configures. It collects nothing about individual shoppers: no names, no email addresses, no order contents, no payment details, no IP addresses, no tracking across sites. Storefront activity is recorded only as daily counts per store, which cannot be traced to a person.
Smart BOGO is a Shopify app operated by Zaytech Corp, Mountain House, California, United States, which is responsible for the information described here. Questions and requests go to [email protected].
This page covers the Smart BOGO app. Zaytech Corp’s general privacy policy covers the company’s other services. It does not cover Shopify, or the store you install it on — you remain the controller of your own customers’ information.
The app requests three permissions only — to manage discounts, read your theme settings, and read your products. It has no access to your customers, orders or payments. Within those, at install and at each re-authorisation, we store:
myshopify.com name, store name, storefront URL, and the store contact details in your Shopify settings: store and contact email, owner name, phone and business address. Those last ones can identify a person, so the rights in section 7 apply to them.Only what you enter on the settings page: whether the campaign is active, the spend threshold and its currency, and which product is the gift. We also log your saves, installs and uninstalls, and the error if a save fails, so we can answer “it worked yesterday” without asking you to reconstruct it. We never ask you for payment details — billing is Shopify’s.
Nothing. The app does not use customer data at all. It holds no customer names, email addresses, phone numbers, addresses, order history or payment details, and it never receives any.
That is enforced by Shopify rather than merely promised by us: the app requests only the three permissions in section 1, none of which covers customers or orders, so Shopify would refuse it that data even if it asked. It has no checkout extension and does not use the Customer Account API. Under Shopify’s own classification it accesses no protected customer data.
When a shopper sees the bar or the gift is added, the app increases a counter. The record is a number per store, per day, per type of event — “gift added: 14”. No shopper identifier, no cart or checkout contents, no cart token, no IP address; none of that is ever sent to us.
The storefront code does keep three technical markers — two flags in the browser’s sessionStorage so a browsing session is not counted twice, a note on the shopper’s own cart if they remove the gift, and a marker on the gift line so the app can recognise it. None is sent to us, and none is used for advertising, profiling or tracking across sites.
To run the app, to support you when something goes wrong, and to decide what to build and fix — for example, which stores present more than one currency, because that changes how a spend threshold has to be compared. We do not sell or rent data, use it for advertising, or share it with anyone for their own purposes.
Installing gives the app an access token, used only to make those requests on your behalf. Uninstalling revokes it.
While the app is installed, for as long as it is needed to run the app and support you. When you uninstall, the token is revoked and the campaign marked inactive at once; Shopify sends us a shop erasure request 48 hours later and we delete your store’s information in response. The short gap is what lets the app tell you what was configured if you reinstall, which is common.
The erasure covers everything: your store record and its contact details, the saved campaign, the activity log, and the daily counts, which are keyed to your store even though they name no person. We also delete it all at any time if you ask.
If one of your customers makes a data or deletion request through Shopify, we receive it and confirm we hold nothing about that person, because we never collected any — see section 3. We keep nothing from those requests either, not even the identifiers they arrive with.
Zaytech Corp is established in the United States, not in Europe, and information is stored and processed there — so for merchants in the EEA or UK that is a transfer outside your region. Besides Shopify, which is the source of the information in section 1 and the platform the app runs inside, the only other party involved is a third-party cloud hosting provider in the United States, which stores the app and its database on our instructions and transmits it over encrypted connections.
Email [email protected] to ask what we hold about your store, to correct it, or to delete it. Depending on where you are you may also have the right to object to or restrict how we use it, to receive a copy, to withdraw consent, and to complain to your data protection authority. We respond within 30 days.
If one of your customers asks what this app holds about them, the answer is nothing — see section 3. Forward the request if you would like that in writing, or let it reach us through Shopify’s own privacy request flow, which we answer automatically.
Connections to the app and its database are encrypted in transit and database access is limited to the people who operate the service. No system is perfectly secure; if a breach affects your information we will notify you and, where required, the relevant authority. The app is a business tool and is not directed at children under 16. If what we store changes, this page changes with it and the date above is updated; where a change materially affects what we hold, we will tell merchants rather than rely on you rereading it.