This Privacy Policy explains what information the RegGate app (“RegGate”, “we”, “us”) accesses when a merchant installs it on their Shopify store, why we use it, and the choices and rights you have. By installing or using RegGate you agree to this policy.
Who this policy is for
RegGate is a Shopify app used by merchants to enforce regulated-product compliance rules at checkout: state and province restrictions, per-state quantity caps, and an age confirmation. This policy covers:
- Merchants who install and operate the app.
- Store customers whose checkout RegGate evaluates on the merchant’s behalf so the merchant’s rules are applied.
For store customers: the merchant whose store you are shopping is the controller of your personal data. RegGate processes it only to provide compliance enforcement to that merchant.
Checkout decisions stay inside Shopify
This is the most important thing to know about how RegGate handles data. The rule check runs inside Shopify’s checkout, in a sandboxed function that cannot make network calls. So at the moment a decision is made, the shopper’s shipping destination, cart contents, and age confirmation are read and evaluated inside Shopify and are never transmitted to our servers. RegGate decides what to block without collecting that checkout data on our side.
What we access and why
RegGate requests only the access it needs to do its job:
| Data | Why we use it |
|---|---|
| Your rule configuration (the products, the restricted states or provinces, the per-state quantity caps, and the attestation settings) | To know what to enforce. It is stored in the app’s own database, and a copy is written to the app’s checkout validation record in Shopify, where the checkout function reads it. |
| The shipping destination state or province, cart contents, and age-confirmation value at checkout | Evaluated inside Shopify checkout to apply your rules. Because the function cannot make network calls, this checkout data is never sent to our servers to make the decision. |
| Merchant account and session details provided by Shopify during install | To authenticate the app to your store and keep it connected. |
RegGate does not verify identity, check IDs, read birthdates, or score buyers for fraud. It confirms that a visible age attestation is present, and applies the state and quantity rules you set. It does not read or edit your orders to make its checkout decision.
What we store, and where
- Your rule configuration (your rules and their settings) is stored in the app’s own database, and a serialized copy is written to the app’s checkout validation record in Shopify, where the checkout function reads it. Your rules describe your products and restrictions and carry no shopper personal data.
- We also keep a minimal application record needed to run the app: the store domain and the access token Shopify issues at install, used to authenticate API calls.
- We do not maintain our own database of your store’s shoppers, their addresses, their ages, or their orders.
What we do not do
- We do not sell, rent, or share your data or your customers’ data for advertising.
- We do not use your data for anything other than enforcing the rules you configure.
- We do not collect storefront-shopper personal information beyond what Shopify already holds and exposes to the checkout function so it can apply your rules.
Service providers
RegGate runs on standard cloud hosting used to operate the app. Any such provider processes data only to host the service, under confidentiality and data-protection obligations, and not for their own purposes. We do not use third-party analytics or advertising trackers inside the app.
Data retention and deletion
- When a merchant uninstalls RegGate, the app’s stored credentials for that store are deleted, and the app stops accessing the store.
- RegGate supports Shopify’s privacy webhooks. On a customer data-request, we confirm what app-side data exists, which for storefront customers is none beyond what Shopify already holds. On a customer redaction request, there are no separate app-side customer records to erase. On a shop redaction request (sent by Shopify after uninstall), we delete the store’s remaining app records.
- Your rule configuration lives in the app’s database and in the app’s Shopify validation record. Remove the app’s rules to clear them, or uninstall, after which the shop redaction described above deletes the store’s remaining app records, including your rules and settings.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). Because RegGate processes store-customer data on the merchant’s behalf, please direct customer requests to the merchant, who can act on them in Shopify. Merchants can contact us using the details below for help with any request.
Security
Data is transmitted over encrypted connections (TLS), and access to the app’s systems is limited to what is needed to operate the service. No method of transmission or storage is perfectly secure, but we work to protect the limited data we handle.
Children
RegGate is a tool for merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the app evolves or as legal requirements change. The “Last updated” date reflects the current version. Material changes will be reflected here.
Contact
RegGate is operated by Conatus Creative Inc., the company behind the Hurdle app brand. For privacy questions or requests, contact us using the email and postal address at the bottom of this page.