Skip to content

Checkout Commander Privacy Policy

Version 1 (v1) Published August 23, 2026

Checkout Commander (“the App”) provides checkout customization built on Shopify’s Checkout Functions (“the Service”) to merchants who use Shopify to power their stores. Shopify processes checkout data when the Service runs. The App sends the operation configuration you create to Shopify so the Service can evaluate it at checkout. The App’s application database stores the merchant, account, configuration, subscription, and email-preference information described in this policy; it does not store the checkout transaction records evaluated by Shopify. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with a Shopify-supported store.

In this policy, “you” and “your” refer to the individual who installs, accesses, or otherwise uses the App and who accepts this Privacy Policy — this may or may not be the same person as the store’s owner. Where this policy describes information about the store itself, its owner, or its customers, they are referred to as such rather than as “you.”

Catalyst Software (“we”, “us”, “our”) develops and operates the App. We are the data controller of the personal information described in this policy — we decide how and why it is processed — and, under Canadian law (PIPEDA), we are the organization accountable for it.

When you install the App, we are automatically able to access certain types of information from your Shopify account:

  • Your Shopify account profile: name, email address, locale, Shopify user ID, and whether you are the account owner;
  • The store’s information: store name and domain, store owner’s name, contact email address, currency, weight unit, locales, and Shopify plan details;
  • Shop and user access tokens issued by Shopify when the App is authorized, which we store in order to authenticate subsequent calls to Shopify’s APIs on your behalf and on behalf of the store;
  • App install and subscription information via the Shopify Partner API, including application charge information (subscription amount and billing dates) and shop events such as install and uninstall timestamps and subscription status changes. Subscriptions are billed entirely by Shopify; no payment card or financial account data ever reaches the App.

Additionally, we collect the following types of personal information from you once you have installed the App:

  • Email addresses used in the App’s configuration: the shop’s notification email, a user’s notification email, and a user’s marketing email. These addresses may be supplied by Shopify or entered in the App and can be different from one another;
  • Marketing consent decisions, including the email address to which consent applies, the selected topics, the submitter’s IP address, a timestamp, the submission source, the wording and locale shown at the time, and the version of the privacy policy linked then;
  • The operations and conditions you configure. These are merchant-authored settings and may contain values you choose to enter.

We do not collect any information about individuals who visit the store — no IP addresses, web browser details, time zone, or cookie information of the store’s visitors.

Shopify can send the App privacy requests about a customer or a shop. Shopify processes checkout records in Shopify systems; the App does not store checkout customer records in its application database, so it has no such records to return or delete. A shop privacy request starts the cleanup described in the Data retention section below.

We collect most personal information directly from the relevant individual, through your Shopify account. In some cases — for example, the store owner’s name and contact email — this information is provided to us by Shopify at install time and may relate to an individual other than the person completing the install, such as a staff member or partner acting on the store owner’s behalf. In these cases, we receive that information indirectly, through Shopify, rather than directly from the individual it concerns.

The App uses a single encrypted session cookie to keep you signed into the embedded App; this cookie does not track you across other sites. We do not use analytics cookies, web beacons, tags, or pixels, and we do not use any third-party advertising technology. Our error monitoring provider, Honeybadger, may receive browser error reports that include your IP address, browser and device details, and the page you were viewing when an error occurred; Honeybadger retains this data for 30 days.

We use the personal information we collect from you in order to provide the Service and to operate the App. Additionally, we use this personal information to: communicate with you; respond to support requests, for which our staff may need to view the store’s configuration; and optimize or improve the App, including through error monitoring and configuration audit logs. We do not sell your personal information, and we do not use it for behavioural advertising. We also do not use your personal information for automated decision-making that produces legal or similarly significant effects for you.

We share your personal information with third-party service providers only to the extent necessary to operate the App:

  • Shopify — the platform that powers the store: authentication, access to shop and user data, execution of your operations through Shopify Functions, subscription billing, and privacy requests;
  • Vultr — hosts the App and its database in Atlanta, Georgia, United States;
  • Zoho — delivers the emails the App sends;
  • Honeybadger — error monitoring, as described above;
  • Cloudflare — hosts our public website and documentation at checkoutcommander.com.

Finally, we may also share your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.

Your personal information is transferred to, stored in, and processed in Canada, where we are based, and the United States, where our hosting provider and some of our other service providers operate. If you are in the European Economic Area or the United Kingdom, these transfers are safeguarded as follows:

  • Canada benefits from an adequacy decision in which the European Commission recognized Canadian privacy law as providing essentially equivalent protection, and from equivalent recognition under UK law;
  • Our hosting provider, Vultr, participates in the EU-U.S. Data Privacy Framework (including the UK Extension) and the Swiss-U.S. Data Privacy Framework;
  • For other transfers, we take reasonable steps to ensure the recipient protects your personal information.

You may request details of the safeguards applied to a transfer through the contact information below.

We take reasonable technical and organizational measures to protect the personal information we hold against loss, misuse, and unauthorized access:

  • Connections to the App and to our systems are encrypted in transit with TLS;
  • Data stored on our hosting provider’s infrastructure is encrypted at rest with AES-256;
  • Staff access to personal information is limited to authorized Catalyst Software personnel and is controlled by role;
  • We minimize what we hold: Shopify processes checkout data for the Service, while the App stores the merchant, account, configuration, subscription, and email-preference information described above.

If a security incident affecting your personal information occurs, we will notify the affected store’s owner and take the steps required by applicable law.

To exercise any of the rights described in this section, contact us through the contact information below.

If you are in the European Economic Area or the United Kingdom

Section titled “If you are in the European Economic Area or the United Kingdom”

Under the GDPR and the UK GDPR, you have the right to:

  • access the personal information we hold about you;
  • ask us to correct or update inaccurate personal information;
  • ask us to delete your personal information;
  • ask us to restrict how we process your personal information;
  • object to our processing of your personal information;
  • receive the personal information you provided to us in a structured, commonly used, machine-readable format;
  • withdraw your consent at any time where processing is based on consent — in particular, you can stop marketing emails at any time using the one-click unsubscribe link in any marketing email or the email preferences page. Email preference links expire after 90 days, and withdrawing consent does not affect the lawfulness of earlier processing;
  • lodge a complaint with the data protection supervisory authority where you live.

We process your personal information to perform the contract we have with you (for example, to provide the Service) and, where we rely on legitimate interests, for the business purposes described in the How we use your personal information section above.

Under PIPEDA, you have the right to:

  • access the personal information we hold about you and challenge its accuracy;
  • have inaccurate information amended;
  • withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions.

If you are unhappy with how we handle your personal information, you may complain to us through the contact information below. If the matter is not resolved, you may complain to the Privacy Commissioner of Canada.

The App stores your operations and other merchant configuration indefinitely so that uninstalling does not lose your work. This configuration may contain values you choose to enter. Uninstall cleanup is asynchronous: after Shopify’s uninstall notification, Checkout Commander cancels the Shopify subscription, removes sessions and active checkout customizations, and retains the operations and remaining configuration. Shopify can then send a separate shop privacy request. When that request is processed, we clear shop and user names and email addresses, remove stored notification and marketing email settings, and clear access-token data. Consent records are retained as audit records rather than deleted; their stored consent email address and IP address are cleared, while the remaining consent details and an irreversible email digest remain. Configuration audit versions are retained for 90 days.

This is version 1 (“v1”) of this Privacy Policy. Rather than editing this policy in place, we release new numbered versions when we need to reflect changes to our practices or for other operational, legal, or regulatory reasons; each version is dated and retained. By continuing to use the App after a new version is released, you accept the then-current version automatically — we don’t require you to reconfirm your acceptance each time a new version is published.

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at privacy@catalystsoftware.dev or by mail using the details provided below:

Catalyst Software [INSERT PHYSICAL ADDRESS — PO box pending]


This page reflects Checkout Commander Privacy Policy v1. If a later version is released, it will be published as a new numbered version rather than an edit to this one, so the version that was in force when you gave consent (for example, to receive marketing emails) remains available for reference.