Privacy Policy
Complete Skateboard Builder. Effective 27 September 2026.
Complete Skateboard Builder is a Shopify app that lets a shopper assemble a complete skateboard from the parts a merchant sells, then adds those parts to the cart as grouped line items. This policy explains what the app stores, why it stores it, and how long it keeps it.
It covers the app, and the launch-notice email signup on the app’s pre-launch marketing website. It does not cover the Shopify platform itself, or the merchant store the app is installed on. Those have their own policies.
The short version
- The app stores no personal data about shoppers. It holds no names, addresses, email addresses, phone numbers, payment details, orders, or line items.
- What it does store is the configuration a merchant sets up, plus three daily counters per store.
- The storefront builder sets no cookies, writes nothing to browser storage, and runs no analytics or tracking of any kind.
- Everything the app holds for a store is deleted 48 hours after it is uninstalled.
- The only other thing collected anywhere is an email address, if you choose to leave one on the pre-launch marketing website for a launch notice.
Who this policy is for
There are three audiences: merchants who install the app, shoppers who use the builder on a merchant’s storefront, and website visitors who leave an email address for a launch notice before the app is available. Nearly everything below concerns merchants, for the simple reason that shoppers leave no data with the app.
The pre-launch marketing website
Before the app is listed on the Shopify App Store, its marketing website invites visitors to leave an email address for a single notice when the app goes live. That address, and which part of the page it was entered from, is what gets stored — nothing else. No name, no IP address, and no cookie or tracking of any kind accompanies it.
That address is used for exactly one thing: sending the launch notice. When that email is sent, it will go out through Resend, an email delivery service; Resend never receives any other data this policy describes. The address is kept until that notice has been sent, or removed sooner on request to help@fordailyuse.com.
What the app stores
For each store that installs it, the app stores four things.
Store identity and authentication
The store’s .myshopify.com domain and the access token Shopify issues at install, so the app can read the merchant’s catalog on their behalf. Where Shopify supplies them, this record can also hold the name and email address of the staff member whose session it is. That is a member of the merchant’s own team, never a shopper.
Builder configuration
Everything the merchant sets up in the app admin: the build steps and their order, the rules that decide which products qualify for each step, the button label and builder title, and the assembly upsell settings.
Usage counters
Three numbers per store per day. How many times the builder was opened, how many builds reached the cart, and how many paid orders contained a build. These are counts and nothing else. No order, no line item, no product and no shopper is recorded alongside them.
Webhook delivery identifiers
The identifier Shopify assigns to each webhook delivery, kept for seven days so that a delivery Shopify retries is not counted twice. It identifies the delivery, not the order and not the shopper.
What the app does not store
The app does not read, receive, or store any of the following:
- names, addresses, email addresses, or phone numbers
- payment or card details
- order records, line items, or purchase history
- shopper accounts, IP addresses, or device identifiers
- any identifier that could be traced back to an individual shopper
The order webhook is the single point at which the app sees an order at all. It counts how many distinct builds that order contains, and discards everything else. Nothing from the order reaches the database.
What the app does on a storefront
The builder runs in the shopper’s browser on the merchant’s storefront. It:
- sets no cookies
- writes nothing to local storage or session storage
- loads no analytics, no tracking pixels, and no third-party scripts
- sends no data to any service other than the merchant’s own Shopify store
When a shopper adds a complete to the cart, each part is stamped with a randomly generated build identifier so that the parts stay grouped together through checkout and fulfilment. That identifier is a random value with no meaning outside the cart. It is generated in the shopper’s own browser and stored by Shopify on the merchant’s cart and order. It is never sent to the app and never stored by it.
The builder does report two anonymous events back to the app: that a builder was opened, and that a build reached a cart. Each report carries the name of the event and nothing else. There is no identifier, no session, and no way to link an event to a person.
Data the app writes into a merchant’s store
To power size filtering, the app can create metafield definitions in the merchant’s Shopify admin under the csb namespace, and fill in values such as deck width and wheel diameter by reading the merchant’s own product titles, SKUs, and variant options.
Those definitions and their values belong to the merchant. They live in the merchant’s Shopify admin, they can be used by the merchant’s theme and their own admin filters, and they are deliberately left in place when the app is uninstalled so that the work of filling them in is not lost.
How the data is used
Configuration is used to run the builder. Usage counters are used to show the merchant how the app is performing on their own store. That is the whole of it. No data is sold, rented, or used for advertising, and none of it is used to train any model.
Who the data is shared with
The app uses two service providers and no others:
- Shopify, which hosts the store, processes checkout, and delivers the webhooks the app listens to.
- Railway, which hosts the app and its PostgreSQL database.
Nothing is shared with anyone else, and nothing is transferred to a third party for any commercial purpose.
Security
- Traffic between a browser and the app is encrypted with TLS. Plain HTTP requests are redirected to HTTPS.
- Traffic between the app and its database travels over the hosting provider’s encrypted private network.
- Data at rest is encrypted by the hosting provider.
- Every webhook is verified against Shopify’s signature before it is processed. Unsigned requests, and requests whose contents have been altered, are rejected.
- Requests from a storefront arrive through Shopify’s signed app proxy, so the store they come from is verified rather than asserted.
Retention and deletion
Configuration and counters are kept for as long as the app is installed.
When a merchant uninstalls, Shopify sends a shop redaction request 48 hours later. On receiving it, the app deletes everything it holds for that store: the store record, every build step and rule, the usage counters, and the stored session. The 48-hour gap is why a merchant who reinstalls the same day still finds their setup intact.
The metafield definitions and values in the merchant’s own Shopify admin are left alone, because they are the merchant’s data rather than the app’s.
Requests about shopper data
Shopify requires every app to answer two kinds of shopper data request. Because this app stores no shopper data, the answer is the same in every case:
- A request for a shopper’s data returns nothing, because there is nothing held.
- A request to erase a shopper’s data requires no action, because there is nothing to erase.
Both are received, verified, logged, and acknowledged.
Merchant rights
A merchant can ask what the app holds for their store, ask for it to be corrected, or ask for it to be deleted at any time, without waiting for an uninstall. Merchants in the European Union, the United Kingdom, California, and other places with comparable laws hold these rights under those laws. The app extends the same rights to every merchant regardless of where they are.
Children
The app is a tool for merchants and is not directed at children. It collects no personal data from anyone, of any age.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and any material change is communicated to merchants who have the app installed.
Contact
For Daily Use
help@fordailyuse.com