NORTH JS TECH
Skip to content
North Js Tech

Privacy Policy

Rich Form Builder ("the app", "we") is a Shopify app operated by NorthJS Tech

("the developer") that lets merchants build forms, place them on their

storefront, and collect submissions from their shoppers. This policy explains

what data the app handles, why, where it goes, and how long it is kept.

The app handles data in two roles:

For merchants (the shop that installs the app), we act as a data

controller for the account and configuration data described below.

For shoppers (people who view or submit a merchant's form), we act as a

data processor on the merchant's behalf. The merchant decides which

questions a form asks and is the controller of the answers. Merchants are

responsible for ensuring their forms and this data collection comply with

the laws that apply to their store, and for disclosing their use of forms in

their own privacy policy.

1. Data we collect from merchants

When a shop installs the app we receive and store, via Shopify's OAuth flow:

The shop's `myshopify.com` domain, name, email, and plan details.

An API access token scoped to the permissions listed on the app's install

screen (discounts, customers, files, locales, cart transforms, product

listings; and optionally themes for the setup guide). The token is used only

to perform the app's documented functions.

The forms, settings, templates, and translations the merchant creates.

These are the merchant's content and are served back to their storefront.

If the merchant connects an optional integration, we also store the

credentials that integration needs, in our database, used only server-side:

Custom SMTP — host, port, username, and password for the merchant's own

mail server.

Google Sheets — OAuth tokens for the Google account the merchant

connects.

Mailchimp — the API key and audience mapping the merchant provides.

HTTP webhook — the destination URL the merchant configures.

Captcha (Cloudflare Turnstile, Google reCAPTCHA, or hCaptcha) — the

site key and secret key the merchant provides.

Credentials are never included in the form data served to storefronts.

2. Data we process about shoppers, on the merchant's behalf

Form submissions

When a shopper submits a form, we store on the merchant's behalf:

The answers to the questions the merchant chose to ask. Depending on

the form, these may include personal data such as name, email address,

phone number, or postal address.

Uploaded files, when the form includes a file field. Files are stored

in the merchant's own Shopify Files library (marked public or private

according to the form's setting); we store the file's name, type, size, and

its Shopify location.

Technical details: the page URL the form was on, the shopper's

language, browser user-agent string, and IP address. The IP address is

stored both in raw form (shown to the merchant on the submission's detail

page) and as a salted hash used for rate limiting and abuse prevention.

A visitor identifier — a random ID created in the shopper's browser.

Marketing attribution parameters (such as utm_source).

The shopper's Shopify customer ID, when logged in.

Logged-in customers may view and (where enabled) edit their submissions.

Form views (impressions)

To provide merchants with conversion statistics, the app records limited

impression data such as visitor ID, page URL, language, browser time zone,

and approximate country code.

Drafts

If draft saving is enabled, draft responses remain in the shopper's browser

(local storage) until submitted.

3. Cookies and Local Storage

The app uses browser cookies and local storage only for functionality such as:

Visitor identification

Popup display preferences

Country lookup cache

Draft form storage

These are not used for advertising.

4. Emails

Submission notifications and auto-responses can be delivered through:

Resend (default)

Merchant SMTP

5. Optional Analytics

Merchants may enable:

Google Analytics

Meta Pixel

Shopify Analytics Identify

The app itself does not load advertising trackers.

6. Sub-processors

Data may be processed by:

Shopify

Linode (Akamai)

Resend

Merchant SMTP

Google

Cloudflare / hCaptcha

Mailchimp

Merchant Webhooks

api.country.is

We never sell personal data.

7. Retention and Deletion

Data remains until deleted by the merchant. Merchants may export or remove

their data at any time. App uninstall revokes Shopify access. Immediate

deletion can be requested.

8. Security

Shopify signed App Proxy requests

Verified customer identity

Server-side validation

Salted and hashed IPs

TLS encryption

9. Children

The app is not directed toward children.

10. Changes

This policy will be updated whenever data handling changes.

11. Contact

NorthJS Tech

https://northjstech.com

Email: support@northjstech.com

Last updated:

Let's talk
Privacy Policy | North Js Tech