Docs, Billing, privacy, and data

Privacy and data, what the app stores

What the app stores about your store, what it stores about shoppers, which is nothing on our servers, and how Shopify privacy requests are handled.

Category
Account
Updated
26 September 2026
Applies to
TreStack Timer, every plan

About your store

The shop domain, name, contact email, and timezone. Plan and subscription records. The settings of your timers. Records of the images you upload, while the files themselves live in your own Shopify Files. Daily counts per timer of views, clicks, closes, and completions.

The daily counts are kept 400 days. A deleted timer is purged after 30 days.

About shoppers

Nothing on our servers, and no cookies. In the shopper own browser, local storage keeps when a per visitor countdown started and whether they closed a bar, and session storage stops one visit counting a timer's view or completion more than once.

The storefront sends a count event to timer.trestack.app with the timer ID and the event type, and no shopper identifier. The IP address is used only to limit how many requests one address can send, and is not stored with the counts. The visitor country comes from Shopify, not from an IP lookup of ours.

Email timers

When an email with a timer is opened, the email app requests the image from timer.trestack.app. The address holds only the timer ID. No cookies, no identifier per recipient, and the image is cached per minute, so it cannot tell who opened what.

Shopify privacy requests

Shopify forwards customer data requests and customer redaction requests to installed apps. The app has nothing to return or delete for them, because it holds no customer data. After you uninstall, Shopify sends a shop redaction request, and that deletes all of your store data from the app.

Getting your position straight, in four steps.

In order. Each step assumes the one before it is finished, so skipping one is how the last step fails for a reason that looks unrelated.

  1. Step one

    Read the lists above

    That is everything the app stores. If something is not on them, it is not held.

  2. Step two

    Read the privacy policy

    The full policy is at trestack.app/privacy.

  3. Step three

    Update your own policy

    Name the app and the browser storage it uses. It sets no cookies.

  4. Step four

    Ask about anything unclear

    [email protected]. The people who build the app answer.

Settings reference

The controls this page touches, with what each one does and the default the app ships where there is one.

Store data
Shop domain, name, contact email, timezone, plan and subscription records, timer settings, image records.
Counts
Daily per timer: views, clicks, closes, completions. Kept 400 days.
Deleted timers
Purged after 30 days.
Shopper data on our servers
None.
Cookies
None, on the storefront or in email images.
Browser storage
Local storage for per visitor countdowns and closed bars. Session storage so one visit counts a view and a completion once.
After uninstall
The shop redaction request Shopify sends deletes all of your store data.

If this does not work

The failures most likely on this procedure, with the check that resolves each one. If none of them fit, we would rather have the store URL than a guess.

Send us the store URL
A customer asks what the app holds about them

Nothing on our servers. Anything in their own browser, a countdown start time or a closed bar, they can clear by clearing site data for your store.

You need a written description for an audit

Write to [email protected] with what your auditor asked for. The privacy policy and the DPA are the starting documents.