Privacy Policy
This Privacy Policy describes how North JS Tech ("we", "us", "our") collects, uses, and shares information when you install or use the Rich Upsell and Cross Sell app (the "App") for Shopify, available at https://www.northjstech.com/apps/rich-upsell-and-cross-sell.
By installing the App, you agree to the collection and handling of information as described in this policy.
Scope
This policy covers:
The App's admin interface embedded in the Shopify admin, used by merchants and their staff.
The storefront offer widget displayed on merchants' online stores.
The App's checkout, thank-you, order-status, and post-purchase extensions.
The App's backend services that power campaigns, discounts, and analytics.
It applies to two groups of people: merchants (store owners and staff who install and configure the App) and store visitors (shoppers who browse a store where the App is installed).
Information we collect from merchants
Account and session information
When you install the App or sign in through Shopify, we receive and store standard Shopify session information, which may include the name, email address, and locale of the staff member using the App, along with authentication tokens issued by Shopify. This is the standard session data Shopify provides to embedded apps and is used solely to authenticate your access.
Store information
We store basic information about your store: your .myshopify.com domain, store timezone, currency, installation and onboarding status, and the identifiers of the Shopify discount and cart-transform functions the App manages for your store.
Configuration you create
We store the campaigns, offers, discounts, display rules, translations, styling, and any custom CSS or JavaScript you author inside the App. This is content you create and control.
Information we collect about store visitors
We do not collect or store personal information about your store's visitors. Specifically, the App does not collect visitor names, email addresses, physical addresses, phone numbers, IP addresses, browser user-agents, customer account identifiers, or payment details.
Anonymous analytics events
To show you how your campaigns perform, the storefront widget sends anonymous analytics events (impression, click, and add-to-cart) to our servers. Each event contains only: the campaign identifier, the event type, the product and variant identifiers involved, quantity, monetary amount, and currency. These events contain no visitor identifiers and cannot be linked to an individual shopper.
Display rules run in the browser
Some campaign display rules can target customer context (for example, whether a visitor is logged in, has certain customer tags, or is a B2B customer). These rules are evaluated entirely within the visitor's browser. Customer identity and tags are never transmitted to or stored on our servers.
Cookies and browser storage
The App sets no cookies and does not use any tracking or fingerprinting technology. The widget uses two small pieces of functional browser storage on the storefront:
A short-lived (60-second) cache of campaign configuration, so offers load quickly without repeated network requests.
A temporary preview token, present only when a merchant is previewing their own campaigns; it expires after one hour.
Neither contains visitor data.
Order data (protected customer data)
The App requests Shopify's read_orders access scope so it can attribute completed purchases to the campaigns that generated them. When Shopify notifies us that an order was paid, we read only the order identifier, order totals, currency, and the line items (product, variant, quantity, price, and the App's own line-item properties).
We never read or store the customer section of the order — no names, emails, shipping or billing addresses, or payment information. What we persist is limited to the order identifier and monetary amounts, used to compute aggregate statistics such as campaign revenue and average order value for your analytics dashboard.
How we use information
- We use the information described above to:
- Provide and operate the App.
- Show analytics.
- Provide support.
Maintain and secure the service.
We do not use collected information for advertising, profiling, or unrelated purposes. We do not sell personal information.
Sharing and subprocessors
We share information only with:
- Shopify
- Akamai (Linode)
- GitHub
Our first-party support tooling may access your store identity and aggregate configuration only for support purposes.
Data retention and deletion
- Data is retained while the App is installed.
- Authentication sessions are deleted immediately after uninstall.
- Campaign configuration and aggregate analytics are retained temporarily after uninstall and then deleted.
- Data can be deleted upon request.
- Shopify privacy webhooks are honored.
Security
- TLS encryption in transit.
- Minimum required Shopify access scopes.
- HMAC-verified server communication.
- Secure storage of tokens and secrets.
International data transfers and GDPR
Merchant is the data controller. North JS Tech acts as the data processor for store data and an independent controller for limited merchant account information.
Changes to this policy
We may update this policy periodically. Material changes will be reflected by a new effective date and, where appropriate, merchants will be notified.
Contact
North JS Tech
Email: support@northjstech.com
Website: https://northjstech.com
If you have questions about this policy or wish to make a privacy request, please contact us.
Last updated: