This Privacy Policy explains what information the DropGate app (“DropGate”, “we”, “us”) processes when a merchant installs it on their Shopify store, why, and the choices and rights you have. By installing or using DropGate you agree to this policy.
Who this policy is for
DropGate is a Shopify app that enforces per-customer purchase limits on limited drops. This policy covers:
- Merchants who install and operate the app.
- Store customers whose purchase activity DropGate evaluates on the merchant’s behalf to enforce the limits the merchant configures.
For store customers: the merchant whose store you are shopping is the controller of your personal data. DropGate processes it only to provide limit enforcement to that merchant.
What we process and why
DropGate’s entire job is to count how many units of a drop one person has bought, so it necessarily processes some customer identity and order data:
| Data | Why |
|---|---|
| Customer email and phone number (stored in normalized form) | To recognize when several accounts belong to the same person (for example email aliases), so a per-identity limit cannot be bypassed with a second account. |
| Order line items for the drop products | To count how many units of a drop a customer has purchased. |
| Customer and order identifiers | To link purchases to the right identity and reconcile duplicates. |
| Shipping address (stored in normalized form) | Used only to flag a possible duplicate after an order, for the shipping-address action you choose per campaign (held for your review by default); never used on its own to link people. |
| Drop product information | To know which products a campaign’s limit applies to. |
| A per-identity purchase count, written to a Shopify customer metafield | So the checkout-time limit check can read it. |
DropGate does not perform identity verification, KYC, bot detection, or fraud scoring. It acts on the identity a customer declares through their Shopify account and order, and is honest that a determined buyer with multiple real identities is outside what it can stop.
What we store, and where
- The per-identity purchase count lives in Shopify on the customer record (a metafield), where the checkout limit check reads it.
- DropGate keeps a small application datastore to do its work: for each customer record it has seen, the normalized email and phone used to cluster identities, and a row per drop unit purchased (campaign, quantity, order reference). This is the minimum needed to count purchases per identity across orders.
- We keep the store domain and the access token Shopify issues at install, used to authenticate the app to your store.
What we do not do
- We do not sell, rent, or share customer data for advertising.
- We do not use the data for anything other than enforcing the limits the merchant configures.
- We do not build cross-merchant profiles; data is scoped per store.
Service providers
DropGate runs on standard cloud hosting used to operate the app. Any such provider processes data only to host the service, under confidentiality and data-protection obligations. We do not use third-party analytics or advertising trackers in the app.
Data retention and deletion
- When a merchant uninstalls DropGate, the app stops accessing the store and its stored credentials for that store are deleted.
- DropGate honors Shopify’s privacy requests. On a customer data request we provide the data we hold for that customer (their normalized identity keys and drop purchase counts). On a customer redaction request we delete that customer’s rows from our datastore. On a shop redaction request (sent by Shopify after uninstall) we delete the store’s data.
- The purchase-count metafield lives in Shopify and follows the customer’s lifecycle there.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). Because DropGate processes store-customer data on the merchant’s behalf, please direct customer requests to the merchant, who can act on them in Shopify. Merchants can contact us using the details below for help.
Security
Data is transmitted over encrypted connections (TLS), and access to the app’s systems is limited to what is needed to operate the service. No method of transmission or storage is perfectly secure, but we work to protect the limited data we handle.
Children
DropGate is a tool for merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the app evolves or as legal requirements change. The “Last updated” date reflects the current version.
Contact
DropGate is operated by Conatus Creative Inc., the company behind the Hurdle app brand. For privacy questions or requests, contact us using the email and postal address at the bottom of this page.