ScarsityPro — Privacy Policy
1. Scope
This policy covers ScarsityPro (“the app”), a Shopify application that displays scarcity and urgency messages on merchants’ product pages. It describes what the app stores, why, and for how long.
The app is installed by a merchant on their Shopify store. Visitors to that store encounter the app only as the messages it renders on product pages.
2. What we store
2.1 Merchant and store data
| Data | Purpose |
|---|---|
Store domain (example.myshopify.com) | Identifies which configuration belongs to which store |
| Shopify access token | Authenticates the app’s own API calls to that store |
| Store currency, timezone, money format | Formats amounts and evaluates time-based rules correctly |
| Subscription plan and status | Determines which features are available |
| Widget configuration | The merchant’s own messages, rules, styles and targeting |
2.2 Aggregate performance data
For each widget, each A/B variant and each calendar day, the app stores three counters: how many times the widget was seen, how many times it was clicked, and how many times a visitor clicked the store’s add-to-cart control while it was on screen.
These are counts only. No visitor, session, page or order is identifiable from them.
2.3 Product sales counts
When an order is placed, the app reads only the product identifiers and quantities from it, and increments a per-product, per-day total. This powers the “Recent Sales” and “Sold Counter” widgets.
Nothing else from the order is read or stored: no customer name, email, address, phone number, payment information, order identifier or line-item price.
2.4 What we do not store
- Names, emails, addresses, phone numbers or any other personal detail of any customer or store visitor.
- IP addresses.
- Payment or financial information.
- Order or cart contents.
- Browsing history, or any cross-site tracking of any kind.
3. Data held on the visitor’s own device
To keep an A/B test consistent, the app stores a random identifier in the visitor’s browser localStorage, together with a flag recording whether they have visited before and, for evergreen countdown widgets, the moment their timer started.
This identifier is generated in the browser, is not linked to any person, and is never stored on our servers in a retrievable form — it is used within a single request to compute which variant to show, and is then discarded. Clearing the browser’s site data removes it entirely. The app sets no cookies of its own.
4. Access to Shopify data
The app requests these Shopify permissions:
read_products,read_inventory— product details and stock levels, so the widgets can show real numbers and targeting rules can be evaluated.read_orders— to receive theorders/createwebhook, from which only product identifiers and quantities are read, as described in section 2.3.
Product data retrieved from Shopify is held in server memory for at most five minutes to avoid repeated API calls, and is not written to disk.
5. Where data is stored
All data is stored on servers we operate at IONOS in London, United Kingdom, in a PostgreSQL database that is not reachable from the public internet. Traffic between merchants, store visitors and the app is encrypted in transit over HTTPS.
6. Sharing
We do not sell, rent or share this data. There are no advertising networks, no analytics third parties and no data brokers involved. Data is disclosed only where the law requires it, or to the hosting provider named above, strictly to operate the service.
7. Retention and deletion
- While installed: data is retained for as long as the app is installed.
- On uninstall: the store’s access token and sessions are deleted immediately. Widget configuration is kept for 48 hours so that a reinstall restores the merchant’s setup.
- 48 hours after uninstall: Shopify sends a
shop/redactrequest and the app erases everything belonging to that store — settings, widgets, rules, targeting, statistics and sales counts.
The app also implements Shopify’s customers/data_request and customers/redact endpoints. Because the app holds no customer data, there is nothing to return or erase in response to either; the endpoints exist and are authenticated as Shopify requires.
8. Rights
Merchants may request access to, correction of, or deletion of their data at any time by contacting domenicocaliendo95@gmail.com. Uninstalling the app triggers deletion automatically, as described above.
Because the app stores no personal data about store visitors, requests from individual shoppers should be directed to the merchant whose store they visited. Where GDPR applies, the merchant is the data controller for their store’s data and Domenico Caliendo acts as a processor on their instructions.
9. Changes
Material changes to this policy are announced to installed merchants before taking effect. The date at the top always reflects the current version.
Our contractual terms with merchants, including the data processing agreement, are set out in our merchant terms.