Privacy Policy
Last updated: 22 July 2026 — draft, pending legal review
This Privacy Policy explains how BTB App Studio (“we”, “us”, “our”), the provider of Nex Reorder Payment Method (the “App”), handles information in connection with the App and this website. It applies to Shopify merchants who install the App and to visitors of this website.
1. Information we process
Merchant and store information. When you install the App, Shopify provides us with:
- your myshopify.com store domain, store name, primary contact email, country, currency and Shopify plan;
- an access token that lets the App call the Shopify APIs you approved at install.
Rule configuration. The payment and shipping rules you create — the methods selected, the action (hide, rename or reorder), the conditions, and the rule status. This is stored primarily on your own store as Shopify metafields, with a copy cached in our database to run the App reliably.
Store data accessed via API. To let you build rules, the App reads limited catalogue and shipping data under the permissions you grant at install, which currently include: reading products, reading shipping profiles, and writing payment/delivery customizations and metaobjects. We access this data only to render choices in the rule editor and to save your rules.
Diagnostics and usage. Aggregated, non-identifying usage events and error diagnostics (for example, a rule failed to save) so we can keep the App working.
Support communications. If you email or chat with us, we keep the message and your contact details to answer and to maintain a support history.
Website visitors. This marketing website may collect standard server logs and, if enabled, privacy-friendly analytics. See “Cookies” below.
2. What we do not collect
The App enforces your rules through Shopify’s native Functions, which run inside Shopify’s own infrastructure at checkout. As a result:
- we do not receive or store your customers’ names, addresses, emails or order contents;
- we do not receive, store or process card numbers or any payment credentials;
- we do not sell personal information, and we do not use your data to train models.
3. How we use information
- To provide, operate and secure the App and its features.
- To save and apply the rules you configure.
- To provide support and respond to your requests.
- To bill your subscription and manage plan entitlements.
- To diagnose faults, prevent abuse, and improve reliability and usability.
- To meet our legal obligations and Shopify’s platform requirements.
4. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies we rely on: contract (to provide the App you installed), legitimate interests (to secure, support and improve the App), legal obligation (record keeping, responding to lawful requests), and consent where required (for example, non-essential analytics cookies). In most merchant-data scenarios you are the controller and we act as your processor.
5. Sharing and subprocessors
We do not sell your data. We share it only with providers needed to run the service:
- Shopify — the platform the App runs on, and the biller for your subscription.
- Cloudflare — hosting, edge delivery and data storage for the App and this website.
- PostHog (United States) — product analytics. We identify your store by its Shopify handle so we can understand how the App is used and diagnose problems.
- Our email and helpdesk provider — support conversations you start with us.
We may also disclose information where required by law, or to protect our rights, users or the service.
6. International transfers
Our providers may process data outside your country, including in the United States. Where required, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
7. Retention and deletion
- We retain your rule configuration and store record while the App is installed.
- When you uninstall, we delete or anonymise the associated data within 30 days, except where we must keep records for legal, tax or security reasons.
- We support Shopify’s mandatory privacy webhooks —
customers/data_request,customers/redactandshop/redact— and respond within the timeframes Shopify requires. - Rules stored as metafields on your store remain under your control and are removed by Shopify with the app installation.
8. Security
We use encryption in transit (HTTPS/TLS), access tokens scoped to only the permissions you approve, least-privilege access for our team, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and will notify you of a qualifying breach as required by law.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing, and to withdraw consent. Residents of California may request disclosure of the categories of information collected and may opt out of “sale” (we do not sell data). To exercise a right, email mail@btbappstudio.com. You may also complain to your local supervisory authority.
10. Cookies
The App uses only the cookies necessary to keep you signed in to the Shopify admin session. This website uses essential cookies and, where enabled, privacy-friendly analytics. You can control cookies in your browser settings.
11. Children
The App is a business tool and is not directed to anyone under 16.
12. Changes to this policy
We may update this policy. We will change the “last updated” date above and, for material changes, notify merchants in the App or by email.
13. Contact
BTB App Studio, Canada.
Email mail@btbappstudio.com.