Grounded Order Edits
Privacy Policy
How we handle merchant and buyer information when stores use Grounded Order Edits.
1. Scope and our role
This policy applies to Grounded Order Edits, provided by Grounded Carts. It covers the app, its public website, merchant administration screens, Shopify extensions, and related support.
For buyer order information, the Shopify merchant generally decides why the information is processed and we process it to provide the service on that merchant's instructions. We independently determine how we use merchant contact, account, security, billing, and service-operation data needed to run Grounded Order Edits.
2. Information we process
- Shopify shop identity, installation, session, permission, plan, and app-configuration information.
- Order and customer identifiers, order contents, contact and delivery details, fulfillment state, discounts, payment and refund status, and the minimum related data needed to evaluate or apply a requested edit.
- Customer-submitted changes, delivery requests, cancellation choices, support categories and messages, and the operational outcome of those requests.
- Merchant user actions, approvals, audit events, integration settings, support correspondence, and security or reliability diagnostics.
- Pseudonymous measurements used for aggregate analytics, abuse prevention, idempotency, recovery, and controlled experiments.
Shopify remains the payment-data system of record. We do not receive or store card numbers, bank details, or reusable payment credentials. Checkout and invoice tokens used for authorization are not stored in raw form.
3. Sources
We receive information from Shopify APIs and webhooks, from merchants configuring the app, from customers using Shopify-hosted account and post-purchase surfaces, from integrations a merchant enables, and from the infrastructure that operates and secures the service.
4. Why we use information
- authenticate users and keep each shop's data separated;
- check eligibility and safely apply, approve, reverse, or reconcile order changes;
- protect fulfillment while edits or payments are unresolved;
- process refunds, added balances, cancellations, and Shopify-managed billing state;
- deliver merchant-selected integrations and customer support;
- prevent abuse, investigate incidents, maintain audit evidence, and improve reliability;
- produce tenant-level operational and product analytics; and
- meet privacy, security, accounting, legal, and Shopify platform obligations.
We do not sell personal information or use merchant customer data for third-party behavioural advertising. The public product site does not use advertising trackers. Essential authentication and security technologies may still be used where needed to provide the service.
5. Sharing and integrations
We disclose information only as needed to Shopify, infrastructure and security providers, professional advisers, or integrations deliberately enabled by a merchant. Optional integrations can include Gorgias, Slack, Klaviyo, Recharge, address-validation providers, Shopify Flow, and a merchant-controlled signed webhook. Each channel receives only the data intended for that function.
Information may be processed in Australia, Canada, Singapore, and the United States. Before production launch, the approved policy and subprocessor register will identify the actual service providers, locations, and applicable transfer safeguards.
6. Retention and deletion
We keep personal information only while it is needed for the service, security, dispute resolution, required records, or a lawful instruction from the merchant. Specific short-lived controls include five-minute invoice capabilities, seven-day encrypted webhook recovery envelopes, 180-day pseudonymous address-validation events, and 365-day pseudonymous cancellation-rescue sessions.
Shopify's mandatory customer and shop privacy webhooks trigger access and deletion workflows. Customer redaction removes or pseudonymizes the linked operational records. Shop redaction removes Shopify sessions and the tenant data graph, subject to narrowly required security, legal, or backup retention. Backup and log deletion follows the production retention schedule.
7. Security
Controls include least-privilege Shopify permissions, tenant scoping, encrypted secrets, encryption in transit and at rest, log redaction, pseudonymous identifiers, no-store customer responses, bounded inputs, signed webhooks, monitored background work, and response-loss recovery. No internet service can guarantee absolute security.
8. Access, correction, deletion, and complaints
Buyers should normally contact the Shopify store where they placed the order because that merchant controls the customer relationship. Merchants can use Shopify's privacy-request process or contact us. We may need to verify identity and authority before acting on a request.
To ask about access, correction, deletion, objection, restriction, or a privacy complaint, email richard@groundedcarts.com. We aim to acknowledge a complaint promptly and respond within 30 days where practicable. Applicable law may also permit a complaint to the relevant privacy regulator after you contact us.
9. Children
Grounded Order Edits is a business service for Shopify merchants and is not directed to children. We do not knowingly collect children's information for our own marketing. A merchant may nevertheless process an order placed for or involving a child; the merchant is responsible for ensuring that its collection and instructions are lawful.
10. Changes and contact
We will update the effective date when this policy materially changes and provide additional notice where required. Contact Grounded Carts at richard@groundedcarts.com or by post at 10/157 Airds Road, Minto NSW 2566, Australia.