DropLink · Legal

DropLink Privacy Policy

Last updated: 15 May 2026

This policy describes how DropLink, a Shopify app published by Zerglo ("we", "us"), collects and handles data when installed on a Shopify store. DropLink generates shareable checkout links (including subscription / selling-plan links) and reports click and conversion analytics back to the merchant who installed it.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and Shopify's data protection requirements for App Store apps.

1. Data We Collect From Merchants

When a merchant installs DropLink, the following merchant-scoped data is stored:

  • Shop domain: The merchant's myshopify.com domain, used to identify the install.
  • OAuth access tokens: Encrypted tokens issued by Shopify for API calls on the merchant's behalf. Stored in encrypted form in Cloudflare D1.
  • Storefront access token: A token generated to read public product and selling-plan data needed to build checkout links.
  • Plan tier and billing status: The merchant's current subscription tier (Free, Starter, Pro, or Growth), synced from Shopify Billing.
  • Link configurations: Each checkout link the merchant creates — title, products, optional discount codes, UTM parameters, order notes, and A/B-test variants.

2. Data We Collect From Shoppers Who Click DropLinks

When a shopper clicks a short link generated by DropLink (e.g., go.zerglo.com/abc123), we record a click event containing:

  • SHA-256 hash of the visitor's IP address: Used to identify unique visitors in aggregate. The raw IP is never stored or logged; the one-way hash cannot be reversed.
  • User-agent string: The browser/device string sent by the visitor's browser, used to detect bot traffic and device-type breakdowns.
  • Truncated referrer: Where the visitor came from, truncated to origin + path. Query strings are stripped before storage to avoid logging any URL-embedded identifiers.
  • Conversion data: If a click leads to a paid order (matched via Shopify's orders/paid webhook), we record the Shopify order ID and order total. We do not store the customer's name, email, address, payment details, or any other order line-item PII.

We do not set tracking cookies on shopper devices. Click attribution is performed server-side via the short-link identifier embedded in the cart permalink.

3. Data Retention

  • Raw click events: Retained for 90 days, after which they are aggregated into daily summaries and the raw rows are deleted by a scheduled job.
  • Aggregated daily summaries: Retained for the lifetime of the install for the merchant's historical analytics.
  • Conversion records: Retained for the lifetime of the install. Deleted if the merchant uninstalls or if a shopper invokes the GDPR redact webhook (see section 5).
  • Merchant configuration: Deleted within 48 hours of uninstall, in line with Shopify's shop/redact webhook.

4. Subprocessors

DropLink is hosted entirely on Cloudflare infrastructure. The following subprocessors handle data on our behalf:

  • Cloudflare, Inc.: Hosts the application (Cloudflare Workers) and the database (Cloudflare D1, encrypted at rest). Data is processed in Cloudflare's global edge network.
  • Shopify Inc.: Provides OAuth, billing, and webhook delivery. We do not transmit merchant or shopper data to Shopify beyond what Shopify itself originates.

We do not share DropLink data with any other third party, advertising network, or analytics provider.

5. GDPR Compliance Webhooks

DropLink implements Shopify's three mandatory privacy webhooks:

  • customers/data_request: When a shopper requests their data, we acknowledge the request and confirm that DropLink stores no reversible personally identifiable information about them.
  • customers/redact: When Shopify instructs us to redact a specific customer, we delete any conversion records tied to the order IDs included in the redact payload.
  • shop/redact: When a merchant uninstalls DropLink, all merchant configuration, links, clicks, conversions, A/B tests, custom domains, API tokens, and webhook subscriptions are deleted within 48 hours.

6. Your Rights

Merchants and shoppers retain the rights granted under UK GDPR, including the right of access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent. To exercise any of these rights with respect to DropLink, contact [email protected].

If you are unhappy with how we handle your request, you may complain to the Information Commissioner's Office (ICO) at ico.org.uk.

7. Security

DropLink uses Shopify OAuth for merchant authentication, SHA-256 hashing for API tokens at rest, parameterised SQL queries (no concatenation) for every database operation, HMAC verification on every Shopify webhook, and HTTPS (Cloudflare Full mode) for all network traffic. Cloudflare D1 encrypts the database at rest.

8. Changes to This Policy

Material changes to this policy will be communicated in-app and dated above. Continued use of DropLink after changes are posted constitutes acceptance.

9. Contact

Questions about DropLink and data protection:
Zerglo · [email protected]