CampaignCart QA privacy policy

Operator and contact

Effective 14 September 2026. CampaignCart QA is operated by Mark Barron, Drogheda, Ireland. Contact dev@emmaenterprisesgroup.com for privacy requests or support.

What the app does

CampaignCart QA compares a merchant’s discount promise with Shopify configuration and a guest storefront journey on desktop and mobile. Checks stop before payment and never place orders. This release supports US markets, USD currency, en-US storefronts and the supported percentage promotions described in the app. Findings describe what was observed, not every possible customer experience.

Information processed

Installation and authentication: shop domain and identifiers, installation status, granted permissions, subscription status, timezone, and encrypted Shopify access and refresh credentials with expiry information.

Campaigns: the merchant’s campaign name, discount code, launch time, nominated product and variant identifiers, storefront URL, market, currency, locale and expected promotion.

Check results: observed amounts, journey findings, verdicts, device and stage information, timestamps, diagnostic categories and storefront screenshots. Capture safeguards are applied, but public merchant content or a theme can display personal information. Please do not put private customer information into campaign names or support requests.

Support: information voluntarily supplied in in-app cases or emails, and diagnostic attachments permitted by the app. Limited compliance records contain webhook identifiers, topic, processing outcome, time and a keyed shop reference. Keyed references are pseudonymous, not guaranteed anonymous.

The app requests read_discounts, read_products, read_markets. It requests no customer, order or payment-data access through Shopify’s Admin API. Shopify handles subscription approval and payments; the app does not collect card details.

Optional development-store tests

Only after Shopify verifies a development installation, its authorised owner may enter the storefront password for one explicitly requested test. The password is encrypted while queued and expires after 15 minutes. It is removed from active database credential fields when the live-lease worker takes it, or on completion, uninstall or the expiry sweep. It is not saved in campaigns, reports, operational logs or browser storage. Historical encrypted backups expire on the database provider’s schedule. This mode does not test anonymous public access and is not offered for live merchant stores.

Purposes and legal grounds

Information is used to authenticate installations, deliver checks and reports, administer subscriptions, provide support, secure the service and handle compliance requests. Where personal information is necessary to deliver a contract with you, processing is based on performance of that contract. Necessary operational security and troubleshooting rely on legitimate interests in maintaining a secure, functioning service. Required compliance handling relies on applicable legal obligations. Where consent is requested for optional attachments, you can withdraw it for future processing.

For personal information within merchant-supplied campaign content or storefront evidence, the merchant determines the purpose of the check and is responsible for its lawful use; we process that content to deliver the requested service. We are responsible for our own account, support and operational processing.

Providers, sharing and international transfers

Render hosts the web service, worker and PostgreSQL database in Frankfurt. Cloudflare R2 stores screenshots in a private European Union-jurisdiction bucket with public access and custom domains disabled. Shopify provides installation authentication, subscription management and platform APIs. Support emails are also processed by the email services used to deliver and host the correspondence.

EU storage selection does not mean every provider operation or support access occurs only in the EU. Render and Cloudflare’s published data-processing terms provide for international processing and applicable transfer safeguards, including EU Standard Contractual Clauses where required and the EU–US Data Privacy Framework where applicable. You can request more information about the relevant safeguards at the privacy contact.

Screenshots are retrieved through authenticated app routes, not public bucket URLs. A deliberately shared report is accessible to anyone holding its valid link until expiry or revocation; that restricted shared view excludes screenshots. We do not sell information, use it for advertising profiling, or use merchant data to train AI models.

Retention and deletion

Screenshot evidence is retained for 30 days from capture, with application deletion processing and a bucket lifecycle backstop. Share links expire after 30 days and can be revoked. In-app support cases are retained for 180 days unless erased sooner with the ended installation. Compliance audit records are retained for 90 days. Campaigns, settings and report history are retained for the installation, then erased by the shop-redaction process.

Uninstall closes the installation and invalidates its use. Its stored Shopify credentials and remaining installation records are erased when Shopify’s shop-redaction event is processed; uninstall does not mean every stored record or screenshot disappears immediately. Pending object deletions are retried if storage is unavailable. You may also send an erasure request to the privacy contact without relying solely on uninstall.

Render runtime logs expire according to the workspace plan, currently within 7 to 30 days. Paid database point-in-time backups have a provider recovery window of up to 7 days; provider-held logical exports expire after 7 days. Backups are not selectively rewritten when active records are erased. Support correspondence is kept as needed to resolve the request and, where necessary, meet legal obligations or establish, exercise or defend legal claims; unnecessary correspondence is deleted. Longer retention is limited to information that must be kept for an applicable legal obligation or claim.

Your rights

Where applicable, you may request access, correction, deletion, restriction or portability of personal information, and object to processing based on legitimate interests. Rights have legal limitations and identity verification may be necessary. Write to dev@emmaenterprisesgroup.com. Where we process content on a merchant’s instructions, we will assist or direct the request to that merchant. You may complain to the Irish Data Protection Commission or another competent supervisory authority.

Security and automated findings

Authentication credentials are encrypted in storage. Tenant authentication, private screenshot storage, fenced worker ownership and bounded diagnostic categories protect the service. No system can guarantee absolute security. Verdicts assist merchants in reviewing promotions and do not make decisions with legal or similarly significant effects about individuals.

Material policy changes will be reflected in the effective date and communicated as appropriate. Provider documentation is linked below.