YOUR DATA, EXPLAINED
Privacy policy
Effective September 19, 2026. This policy explains how ConsentLedger processes information when merchants use the app and buyers respond to a merchant’s acknowledgement requests.
Provider: ConsentLedger, 290 Myrtle Street, Manchester, NH 03104, United States. Merchant processing responsibilities are set out in our Data Processing Agreement and merchant terms.
Information we process
We process the store domain, app authorization and session information, subscription status, merchant-created rules and settings. For order evidence, we process order identifiers, an order reference, a customer identifier when available, buyer responses, the published rule text and version, and confirmation and retention timestamps. Responses may contain personal information entered by a buyer. Product and checkout information is used to determine which rules apply. Technical logs and audit events support operation, security and troubleshooting. Agreement confirmations include the merchant and representative names, designated notice email, store, accepted text and version, and acceptance time.
How we use it
We use this information to display relevant acknowledgement questions, validate required answers, associate responses with orders, retrieve and export evidence, administer subscriptions, handle privacy requests and maintain the service. Merchants determine what they ask buyers and how they use the resulting records. An acknowledgement record does not independently verify identity, age or legally valid consent.
Who receives it
Authorized users of the merchant’s Shopify store can access records through the app. Shopify provides the commerce platform and billing. DigitalOcean hosts the application and database in New York, United States. If a merchant enables exports or webhooks, records are sent to the destination they configure. We do not sell buyer records or use them for advertising. Information may also be disclosed where necessary to comply with a valid legal obligation.
Retention and deletion
Evidence receives a retention deadline when recorded: 90 days on Starter, 365 days on Growth and 730 days on Pro. Changing plans does not extend existing records’ deadlines. Scheduled maintenance removes expired evidence. Shopify customer erasure requests remove associated retained records; limited opaque suppression markers prevent delayed events from recreating erased records. Shopify’s shop erasure notification removes the store’s app data and sessions. Copies already exported by a merchant remain under that merchant’s control.
Access and choices
Buyers should contact the store where they placed an order to request access, correction or deletion. The merchant controls the transaction and can use the app’s privacy request workflow. Merchants can also contact us for help with app data or privacy requests. We may need sufficient information to verify and locate a request. Please do not send passwords or payment card information.
Security and service providers
The app uses encrypted connections, authenticated store access and store-scoped records. Access and exports are audited. No online service can guarantee uninterrupted availability or absolute security. Cross-border processing may occur where our hosting and platform providers operate.
Contact and updates
For privacy and support requests, email [email protected]. We update this page when our practices change and show the effective date above.