Privacy policy — Lilya: Terms & Checkbox
What the app accesses, what it stores, and when it is deleted.
This policy describes how Lilya: Terms & Checkbox (“the app”) handles data when a Shopify merchant installs and uses it. The app is made by Lilya Work. Contact: support@lilya.work.
Who this applies to
The app is used by merchants in their Shopify admin and shows a terms checkbox to their customers in the online store cart. It does not store personal data about the merchant’s customers: no names, e-mail addresses, IP addresses, browser details, customer IDs, cart tokens or order data.
Data the app accesses
When you install the app you grant it the Shopify permissions read_themes, read_validations, write_validations and write_app_proxy. With them the app:
- Reads your published theme to show whether the app embed or cart block is turned on. It never changes theme files.
- Creates and updates the checkout rule that stops checkouts without consent.
- Receives the requests the checkbox makes through your store’s app proxy.
The app does not ask for access to your orders, customers or products.
Data the app stores
- Your store’s myshopify.com domain and the access token Shopify gives the app.
- Your checkbox settings: text, links, languages, colors, behavior and record keeping mode.
- Each published version of those settings, its consent version and a SHA-256 fingerprint of the text and links, so a consent can be matched to the exact text.
- Your plan and trial status.
- Only if you turn on enhanced record keeping: a consent record each time a customer ticks the box, with a random record ID, the server time, the consent version, the text fingerprint, where it was ticked (cart page or drawer) and the storefront language.
When a customer ticks the box, the consent (accepted, version, time, where, record ID) is saved on their cart and copied by Shopify to the order. It stays with the order in your Shopify store.
How the data is used
Only to provide the app’s features: showing the checkbox, enforcing it at checkout, and letting you look up and export consent records. We do not sell data, use it for advertising, or share it with third parties other than the service providers below.
Service providers
- Cloudflare, Inc. runs the app and stores its data (Workers and D1 database, EU region). Rate limiting uses IP addresses briefly in memory; they are not stored.
- Shopify processes billing through Shopify App Pricing.
Retention and deletion
- Consent records are deleted automatically after the period you choose (30 to 3650 days, 365 by default).
- When you uninstall the app, its access token is deleted and the checkbox and checkout rule stop working.
- 48 hours after you uninstall, Shopify asks us to erase your store’s data (shop/redact) and the app deletes everything it stored for your store. If you reinstall within those 48 hours, your settings are kept.
- Shopify’s customer data requests (customers/data_request and customers/redact) are answered, but there is nothing to return or delete because the app stores no customer data.
Security
Admin requests are authenticated with Shopify session tokens. Storefront requests reach the app only through Shopify’s signed app proxy and are rate limited. Your text is stored and shown as plain text, and links are limited to web addresses and store pages.
Your rights
You can ask for a copy of the data the app holds about your store, or ask us to delete it before you uninstall, by writing to support@lilya.work. You can also complain to the data protection authority where you live.
Changes
If we change this policy we update the date at the top of this page.
