This Privacy Policy explains what information the Mainstay app (“Mainstay”, “we”, “us”) processes when a merchant installs it on their Shopify store, why, and the choices and rights you have. By installing or using Mainstay you agree to this policy.
Who this policy is for
Mainstay is a Shopify app that runs subscriptions on a merchant’s store and works to keep those subscribers with failed-payment recovery, cancellation save offers, and churn reporting. This policy covers:
- Merchants who install and operate the app.
- Subscribers (store customers) whose subscription and billing activity Mainstay processes on the merchant’s behalf to run and retain their subscription.
For subscribers: the merchant whose store you subscribe to is the controller of your personal data. Mainstay processes it only to provide subscription and retention features to that merchant.
What we process and why
Mainstay orchestrates subscriptions that Shopify itself owns and bills, so it processes some subscription, billing, and customer data:
| Data | Why we use it |
|---|---|
| Subscription contract details from Shopify (status, next billing date, billing cadence, product lines) | To run recurring billing, show your subscribers in the admin, and let a subscriber manage their own subscription in the portal. |
| Billing attempt outcomes (success, failure with a decline code, an authentication challenge) | To recover failed payments with the right action: retry, ask the subscriber to update their card, or alert you. |
| Customer identifier and display name (from Shopify) | To link a subscription to its owner, list subscribers in the admin, and confirm a portal visitor owns the subscription they are managing. |
| Cancellation reason and save-offer outcome | To offer the right alternative before a cancellation and to report save-offer performance. |
| Per-shop retention settings | To apply your dunning schedule and your save-offer policy. |
| Merchant account and session details provided by Shopify at install | To authenticate the app to your store and keep it connected. |
Mainstay does not vault or store card numbers and is not a payment processor. Payment methods and the money movement stay with Shopify Payments and Shopify’s subscription billing. Mainstay never handles raw card data, and it does not perform identity verification, KYC, or fraud scoring.
What we store, and where
- Subscription contracts and payment methods are owned by Shopify, on the customer and contract records, not in a separate copy held by us.
- Mainstay keeps a small application datastore for the orchestration and retention state it needs: per-contract dunning state (status, consecutive failed payments, the next retry time, the last decline code and action), a per-cycle billing journal used to guarantee a charge is never issued twice, save-offer events (the cancellation reason, the offer, and whether it was accepted or declined), and your per-shop settings.
- We keep the store domain and the access token Shopify issues at install, used to authenticate API calls.
- We do not maintain our own database of your store’s shoppers or a copy of your catalog.
Customer portal sessions: the portal identifies a shopper only through Shopify’s signed app-proxy request. Every request is verified, and Mainstay re-checks that a subscription belongs to the signed-in customer before making any change. Mainstay never trusts a subscription or customer identifier sent by the browser.
What we do not do
- We do not sell, rent, or share your data or your subscribers’ data for advertising.
- We do not build cross-merchant profiles; data is scoped per store.
- We do not vault cards, act as a payment processor, or run identity or fraud checks.
- We do not use third-party analytics or advertising trackers inside the app.
Service providers
Mainstay runs on standard cloud hosting used to operate the app. Any such provider processes data only to host the service, under confidentiality and data-protection obligations, and not for their own purposes. We do not use third-party analytics or advertising trackers in the app.
Data retention and deletion
- When a merchant uninstalls Mainstay, the app stops accessing the store and its stored credentials for that store are deleted.
- Mainstay honors Shopify’s privacy requests. On a customer data request we provide the data we hold for that subscriber (their contract state, billing-journal rows, and save-offer events). On a customer redaction request we delete that subscriber’s rows from our datastore. On a shop redaction request (sent by Shopify after uninstall) we delete the store’s data.
- Subscription contracts and payment methods live in Shopify and follow the customer’s data lifecycle there.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). Because Mainstay processes subscriber data on the merchant’s behalf, please direct subscriber requests to the merchant, who can act on them in Shopify. Merchants can contact us using the details below for help with any request.
Security
Data is transmitted over encrypted connections (TLS), and access to the app’s systems is limited to what is needed to operate the service. No method of transmission or storage is perfectly secure, but we work to protect the limited data we handle.
Children
Mainstay is a tool for merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the app evolves or as legal requirements change. The “Last updated” date reflects the current version. Material changes will be reflected here.
Contact
Mainstay is operated by Conatus Creative Inc., the company behind the Hurdle app brand. For privacy questions or requests, contact us using the email and postal address at the bottom of this page.