Privacy Policy

Last updated: March 5, 2026

Social Plug ("we", "our", or "the App") is a Shopify app that lets merchants display social media icons and embedded content on their online stores. This policy explains what data the App collects, why, and how it is handled.

1. Data We Collect

From Merchants (store owners who install the App):

From Storefront Visitors (your customers):

What we do NOT collect:

2. How We Use Data

3. IP Address Handling

When a storefront visitor clicks a social icon, we briefly read their IP address to determine approximate country and city. The IP is then anonymized (last octet zeroed for IPv4) before anything is stored. The full IP address is never written to our database.

4. Data Sharing

We do not sell, rent, or share any collected data with third parties. Click analytics are visible only to the merchant who owns the store. The only external service we use is Resend for sending optional weekly report emails.

5. Data Retention

6. GDPR & Data Rights

Since we do not store personal customer data (no names, emails, or identifiable information), there is generally no customer personal data to access, correct, or delete. However, we fully support Shopify's mandatory GDPR webhooks:

Merchants can contact us at any time to request a full export or deletion of their data.

7. Security

All data is transmitted over HTTPS. Admin endpoints require Shopify session authentication. Public endpoints are rate-limited and validated against known installed stores. We follow Shopify's security best practices for app development.

8. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of the App after changes constitutes acceptance of the updated policy.

9. Contact

If you have questions about this privacy policy or your data, please contact us at: support@codeformarley.com