Privacy Policy

Checkout Order Booster — Last updated: March 21, 2026

Overview

Checkout Order Booster ("the App") is a Shopify app that displays product upsell recommendations in a store's checkout flow. This policy explains what data we collect, how we use it, and your rights regarding that data.

Data We Collect

When a merchant installs the App, we collect and store:

How We Use Your Data

We do not sell, rent, or share your data with third parties for marketing purposes.

Customer Data

The App does not collect, store, or process personal data belonging to your customers (such as names, email addresses, phone numbers, or payment details). Upsell logic is evaluated using cart contents and cart value only, which are processed in real time and not persisted.

Data Retention

Your data is retained for as long as the App is installed on your store. If you uninstall the App, your offer configurations, settings, and aggregated metrics are deleted from our systems within 48 hours in accordance with Shopify's shop/redact compliance webhook requirements.

Third-Party Services

The App is hosted on Railway and uses a PostgreSQL database to store the data described above. Railway's privacy policy is available at railway.app/legal/privacy.

GDPR & Privacy Rights

We comply with Shopify's mandatory privacy compliance webhooks:

Security

All data is transmitted over HTTPS. Webhook requests are verified using Shopify's HMAC signature before any action is taken. Access tokens are stored securely and scoped to the minimum permissions required by the App.

Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the App after changes are posted constitutes your acceptance of the updated policy.

Contact

If you have questions about this privacy policy or how your data is handled, please contact us at skyappssupport@gmail.com.