Roles
TreStack Timer keeps no shopper data on our servers, so the personal data in scope is small. Where the app processes personal data on your behalf, you are the controller and TreStack is the processor, and we process it only to run the app you installed, only on your instruction, and never for our own purposes. For our own account and billing records about your store, we are the controller, and the privacy policy covers those.
This agreement forms part of the terms and conditions. Installing the app accepts it. If your organisation needs it as a countersigned document, write to us and we will sign one.
Scope and duration of processing
Processing lasts for as long as the app is installed, and ends when Shopify's shop redaction, sent 48 hours after uninstall, deletes your store's data.
- Subject matter
- Running TreStack Timer on your Shopify store: showing your timers, drawing email timer images, counting views, clicks, closes, and completions, and billing your plan through Shopify.
- Categories of data
- Your store's contact email and name, the text you write into the chat and into timers, and the IP address that arrives with a shopper's count request or an email client's image request. The IP address is used only to rate limit count requests and is not stored with the counts.
- Data subjects
- You and your staff who use the app admin or the chat, shoppers whose browsers send count requests, and email recipients whose email clients request a timer image.
- Not processed
- Orders, customers, and payments. The app has no Shopify access to them. No cookies are set on your storefront and no shopper identifier is sent.
- Special categories
- None. Nothing in the app needs sensitive personal data, and none should be written into a timer.
Sub processors
You authorise the sub processors below. The privacy policy carries the same list and is the live copy. We remain responsible for their performance. If we add or replace one, we will date the change in the privacy policy and note it in the changelog before it goes live, which gives you the chance to object by uninstalling.
- Chaport
- Live chat inside the app admin only, never on your storefront. Receives your store name, myshopify domain, and plan, plus whatever you write in the chat.
- Contabo
- Hosts the one server the app runs on, operated by the studio. It holds the store data listed in the privacy policy.
- Cloudflare
- Sits in front of timer.trestack.app and passes requests to that server. It sees the IP address and request of each, and keeps none of our data.
Transfers
Data is hosted in the United States, on the server named in the privacy policy. Where personal data from the European Economic Area, the United Kingdom, or Switzerland reaches it, the transfer relies on the standard contractual clauses or another mechanism valid at the time. The mechanism is to be confirmed.
Security measures
The measures below are the ones we actually run. We hold no security certification and do not claim one.
- All traffic to timer.trestack.app is served over HTTPS
- The store access token Shopify issues is stored encrypted, and deleted when you uninstall
- Four Shopify access scopes, none of them for orders, customers, or payments
- Server logins by SSH key only, with root login and password login turned off, a firewall open only to web traffic and SSH, and automatic security updates
- Count requests are rate limited per IP address, and counts are written as totals, never per shopper
- Text you write into a timer is displayed as text, never run as code. The one exception, a few formatting tags allowed in the cart timer title, is filtered against a fixed list on the server and again in the browser. Links are checked before they are used
- The studio's internal admin tool uses its own password login, stored only as a hash, with a limit on failed attempts
- Nightly database backups, 14 kept
Assistance, audits, and breach notification
We handle Shopify's privacy webhooks: a customer data request and a customer redaction have nothing to return or delete because the app holds no customer data, and a shop redaction deletes all of your store's data. We will help by hand where your case falls outside those, and we will answer reasonable written security questionnaires. We do not offer on site audits.
If we become aware of a personal data breach affecting your store, we will tell you without undue delay, with what we know, what we are doing, and what you may need to tell your own customers. The notification window is a placeholder to be confirmed.
Deletion and return
Counts are kept for 400 days and a deleted timer is purged after 30 days while the app is installed. On uninstall the access token is deleted at once, and timers stop showing because nothing was written into your theme files. The shop redaction Shopify sends 48 hours later deletes the store record and everything tied to it. Backups roll off within 14 days of that. You can ask for an export of your timers before you uninstall, or for deletion sooner, by writing to us.
Questions about this document go to [email protected] and are answered by the people who wrote the app.