This Privacy Policy explains what information the CreditGate app (“CreditGate”, “we”, “us”) processes when a merchant installs it on their Shopify store, why, and the choices and rights you have. By installing or using CreditGate you agree to this policy.
Who this policy is for
CreditGate is a Shopify app that enforces B2B credit limits and overdue-balance rules at checkout. This policy covers:
- Merchants who install and operate the app.
- Business buyers whose company an order is placed on behalf of, and whose company credit status CreditGate checks on the merchant’s behalf to enforce the rules the merchant configures.
For business buyers: the merchant whose store you are buying from is the controller of your data. CreditGate processes it only to enforce the credit rules that merchant sets.
What we process and why
CreditGate works at the level of the buyer’s B2B company, not the individual shopper. To enforce a credit rule it processes:
| Data | Why |
|---|---|
| The buyer’s B2B company and company location (read) | To identify which company an order is being placed for, so the right credit limit applies at checkout. |
| Company credit configuration (credit limit, outstanding balance, overdue flag, and currency), stored on a Shopify company metafield | So the checkout check can read it and decide whether to allow the order. |
| Orders placed on payment terms and their payment status (read) | To keep each company’s outstanding balance current from the store’s own Shopify orders. |
| Merchant account and session details provided by Shopify at install | To authenticate the app to your store and keep it connected. |
CreditGate does not perform credit scoring, identity verification, or fraud detection. It acts on the credit limit the merchant sets and the balance derived from the store’s own Shopify orders placed on terms.
Checkout decisions happen inside Shopify
This is worth stating plainly, because it is unusual and it is good for your data:
- The checkout check runs as a native Shopify validation function, and these functions cannot make network calls.
- So at the moment a buyer checks out, no data about that buyer or that order is sent to us to make the decision. The check reads a credit value already stored in Shopify and decides there, inside Shopify.
- We never see, and never receive, your buyers’ payment details or card data. That stays with Shopify’s checkout.
What we store, and where
- Each company’s credit configuration (limit, balance, overdue flag, currency) lives in Shopify on the company record (a metafield), where the checkout check reads it.
- CreditGate keeps a small application datastore to maintain those balances: for each company, the credit limit you set and the balance derived from the store’s Shopify orders on terms. This is the minimum needed to keep the limit current between orders.
- We keep the store domain and the access token Shopify issues at install, used to authenticate the app to your store.
What we do not do
- We do not sell, rent, or share company or customer data for advertising.
- We do not use the data for anything other than enforcing the credit rules the merchant configures.
- We do not build cross-merchant profiles or credit files; data is scoped per store.
Service providers
CreditGate runs on standard cloud hosting used to operate the app. Any such provider processes data only to host the service, under confidentiality and data-protection obligations. We do not use third-party analytics or advertising trackers in the app.
Data retention and deletion
- When a merchant uninstalls CreditGate, the app stops accessing the store and its stored credentials for that store are deleted.
- CreditGate honors Shopify’s privacy requests. On a data request we provide the data we hold for that company (its credit configuration and the balance we track). On a redaction request we delete that company’s records from our datastore. On a shop redaction request (sent by Shopify after uninstall) we delete the store’s data.
- The credit-configuration metafield lives in Shopify and follows the company’s lifecycle there.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). Because CreditGate processes company and buyer data on the merchant’s behalf, please direct requests to the merchant, who can act on them in Shopify. Merchants can contact us using the details below for help.
Security
Data is transmitted over encrypted connections (TLS), and access to the app’s systems is limited to what is needed to operate the service. No method of transmission or storage is perfectly secure, but we work to protect the limited data we handle.
Children
CreditGate is a tool for merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the app evolves or as legal requirements change. The “Last updated” date reflects the current version.
Contact
CreditGate is operated by Conatus Creative Inc., the company behind the Hurdle app brand. For privacy questions or requests, contact us using the email and postal address at the bottom of this page.