Privacy, explained

Only what the app needs.

This policy explains the data processed by Discount Guard, its public website and its email support. It describes this app's current practices, rather than the data practices of a merchant's storefront.

Effective and last updated: Freshine / Discount Guard
01 /

Who operates the app

Freshine operates Discount Guard and is responsible for the data described in this policy. Merchants manage their own Shopify stores and their customers' data. Contact us by email for questions about this app.

Business contact address
43 Corporate Park #208, Irvine, CA 92606, United States

This address does not accept mail, packages or deliveries. Please contact us by email.

zhaomengfan6666@gmail.com

02 /

Data we process

We obtain the following information through Shopify authorization and APIs, required Shopify notifications, requests to our website, or messages you send to support.

InformationHow it is handled
Shop and rule identifiersThe shop domain, session identifier, the app's automatic discount ID, and short-lived coordination fields for saving settings are stored in Cloudflare D1. Shop and session identifiers are not encrypted by the application.
Shopify authorization sessionAccess tokens, refresh tokens and session properties are encrypted as a session payload in D1. If Shopify includes staff identity details in that session, such as a staff ID, name, email or locale, they are included in the encrypted payload.
Discount information and settingsThe app reads discount identifiers, titles, status, types and codes to display the picker and manage its rule. Selected promotion codes, the checkout message and rule status are stored on the app's discount in Shopify. The app database stores the rule reference rather than a separate coupon database.
Privacy notificationsRequired Shopify privacy webhooks can include customer identifiers and request details. The app authenticates and processes these notifications without persisting their customer payload. It does not maintain a customer database or retrieve customer or order records through the Admin API.
Website and service request metadataCloudflare and Shopify may process IP addresses, request times, browser or device information, and security or diagnostic metadata to deliver and protect their services. Our public pages do not add advertising pixels or third-party analytics.
Support correspondenceIf you email us, we receive your email address, message and any attachments you choose to send. Send only the information needed to explain the problem; hide customer information and other sensitive details in screenshots.
03 /

Why we use it

  • Authenticate the installed app and maintain its authorized Shopify connection.
  • Display the store's discount codes, save the app's rule and prevent conflicting settings updates.
  • Run the configured code-count rule inside Shopify. The Function uses entered codes and the rule configuration; it does not call our server during discount evaluation.
  • Respond to support and privacy requests, maintain service security and comply with applicable obligations.
04 /

Permissions & browser storage

The app requests read_discounts and write_discounts to read codes and create, update or deactivate its own automatic discount rule. It does not request permissions to read orders, customers or payment details. Original coupon settings remain under the merchant's control in Shopify.

The embedded console stores the language preference in this browser under discount-guard.locale. This preference is not an authorization credential. Public pages select the language through the URL. Shopify's authentication flow and the hosting providers may use storage or request information needed for their own services. We do not add advertising cookies or tracking for marketing.

05 /

Providers & locations

Shopify provides installation, authorization, discount storage and Function execution. Cloudflare Workers hosts the application, and Cloudflare D1 stores its shop and encrypted session records. Google Gmail processes messages sent to our support address. These providers may process information in the United States and other countries where they operate, under their own service terms and privacy practices. We do not guarantee storage in a particular country.

We do not sell the app's personal information or use it for targeted advertising. We disclose information as needed to the service providers above, to respond to a valid legal obligation, or to protect the service and users. We do not share app data with advertising networks or use a merchant's customer data to market our other services.

06 /

Retention & deletion

While the app is installed

We retain the shop's authorization session and rule reference for operating the installed app. Settings stored in Shopify remain subject to Shopify's handling and the merchant's controls.

After uninstall or a shop deletion request

When an authenticated APP_UNINSTALLED or SHOP_REDACT notification is processed, we delete that shop's active session and rule-reference records from D1. Deletion is tied to processing the notification; it is not a claim that every provider copy disappears immediately.

Database backups

Cloudflare D1 maintains rolling recovery history. Deleted records may remain in that history for up to 30 days, depending on the applicable plan, before it expires automatically. We do not create a separate permanent archive of these records.

Customer privacy requests

Because the app does not keep customer records, customer data request and customer deletion notifications are acknowledged without creating or retaining a customer record. Store-wide deletion notifications trigger deletion of the shop's active records.

Support messages and service records

We keep support correspondence for as long as needed to resolve the request and meet applicable legal or security obligations. You can ask us to delete it. Hosting and email providers' backup, security and operational records follow their own retention practices.

Cloudflare D1 recovery history ↗

07 /

Security

Browser connections use HTTPS. Authorization session payloads in D1 use AES-GCM encryption with an application-managed key. Access scopes are limited to discount management, and Shopify webhooks are authenticated before processing. Shop metadata and rule identifiers remain readable in the database. No service can guarantee absolute security; do not email passwords, access tokens or payment information.

08 /

Your privacy requests

Depending on the laws that apply to you, you may request access, correction, deletion or a copy of your personal information, or raise a concern about its processing. Send a request to the contact below and identify the shop or support conversation it concerns. We may verify your identity or authority to act for the shop before disclosing or deleting information. We respond within the periods required by applicable law, explain any applicable retention exception and do not penalize you for making a request. You may also contact your local data protection authority.

zhaomengfan6666@gmail.com

If you are a shopper asking about an order, a coupon's customer eligibility or your account with a merchant, contact that merchant. Shopify controls its own platform records. This policy covers Discount Guard's handling of data, and does not replace Shopify's or a merchant's privacy notice.

09 /

Policy changes

We may update this policy when the app, its providers or its data practices change. We will publish the revised policy here and update the effective date. For a material change, we will provide notice through the app or another appropriate channel.

Visit the support guide ↗