Privacy Policy - Discount Kit
Effective Date: 21st July 2025
Last Updated: 31st July 2026
1. Introduction
Optizio Ltd (“we,” “us,” or “our”) operates the Discount Kit Shopify application (“App”). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our App.
Company Information:
- Company Name: Optizio Ltd
- Address: 124 City Road, London, EC1V 2NX, United Kingdom
- Data Protection Officer: David Spanton
- Contact: support@optiz.io
When you install and use our App, we collect:
- Store Information: Store name, description, primary email, store ID, URL, Shopify plan, industry vertical, and country
- User Information: Names and email addresses of store staff who interact with the App’s admin interface
- Configuration Data: Shopify GIDs for products, collections, and discounts, as well as customer tag names required for discount functionality
- Technical Information: System information, app usage data, and performance metrics
- Support Information: Information provided during support interactions
- We do not collect personal data from your customers (end-users)
- We do not store or process credit card information
- We do not collect unnecessary personal information beyond what is required for app functionality
3.1 Primary Uses
We use the collected information for:
- App Functionality: Providing and maintaining the discount features and services
- Support Services: Responding to your inquiries and providing technical support
- Product Updates: Communicating important app updates and new features
- Analytics: Understanding app performance and usage patterns to improve our services
3.2 Legal Basis for Processing
We rely on different legal bases depending on jurisdiction:
- GDPR (EU/UK): Primarily legitimate interest for app functionality and business operations; contract performance where processing is necessary to fulfill our agreement with you
- Consent-based jurisdictions (Brazil LGPD, India DPDP, South Korea PIPA): Explicit consent obtained during app installation and configuration
- US State Laws: Legitimate interest for app functionality, with consent obtained where required by specific state requirements
- Other jurisdictions: Appropriate legal basis as required by local privacy laws
3.3 Consent Management
For jurisdictions requiring explicit consent, we:
- Obtain clear, informed consent during app installation and setup
- Provide easy mechanisms to withdraw consent through app settings or email
- Maintain records of consent and withdrawal for compliance purposes
- Re-obtain consent when required by law or when expanding data processing activities
- Honor consent withdrawal by ceasing relevant processing activities
4.1 Third-Party Service Providers
We share information with the following trusted third-party services:
Cloudflare
- Purpose: Session storage and caching for app functionality
- Data Shared: Technical and configuration data necessary for app operation
- Compliance: GDPR compliant with appropriate data processing agreements
Mantle
- Purpose: Business operations platform for support, analysis, and product updates
- Data Shared: Store information and usage data
- Status: This service is being retired on 14 August 2026. From that date these functions are performed in-house by Optizio Ltd in the United Kingdom, reducing the number of third parties involved in processing.
Intercom
- Purpose: Customer support services
- Data Shared: Name, email, country, store URL, user system information, and Shopify plan
- Data Location: Dublin, Ireland for EU customers
- Compliance: GDPR compliant
Sentry
- Purpose: Application error monitoring and diagnostics
- Data Shared: Technical error and performance data, which may include merchant and staff identifiers
- Compliance: GDPR compliant with appropriate data processing agreements
4.2 Shopify Integration
We share data with Shopify only as required for app functionality and in accordance with Shopify’s Partner Program requirements.
4.3 What We Don’t Share
- We do not sell, rent, or trade your personal information
- We do not share your data with advertisers or marketing companies
- We do not provide your information to third parties except as described in this policy
5. Data Security
We implement comprehensive security measures to protect your information:
- Encryption: All sensitive data is encrypted both at rest and in transit using industry-standard encryption (AES-256)
- Access Controls: Access to data is granted based on job roles and the principle of least privilege
- Authentication: Multi-factor authentication (MFA) is required for all critical systems
- Regular Updates: We maintain up-to-date software and security patches
- Monitoring: Continuous monitoring for security threats and incidents
- Compliance: We follow Shopify’s secure app development guidelines and maintain comprehensive security policies
For detailed information about our security practices, please refer to our Information Security Policy.
6. Data Retention
6.1 Retention Periods
We automatically delete data according to these schedules:
- App Configuration/Session Data: On app uninstall (automatic deletion)
- Support Data: 3 years after last interaction.
These retention periods comply with data minimization principles and are designed to meet the requirements of all applicable privacy laws.
6.2 Data Deletion
Upon request or at the end of retention periods, we will permanently delete your information from our systems and instruct our third-party service providers to do the same.
6.3 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify relevant supervisory authorities within 72 hours where required by law
- Notify affected individuals without undue delay
- Provide clear information about the nature of the breach and steps being taken
- Comply with jurisdiction-specific notification requirements (GDPR, US state laws, PIPEDA, etc.)
- Follow New York SHIELD Act requirements for data security and breach notification
7. Your Rights and Choices
7.1 General Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to our processing of your personal information
7.2 GDPR Rights (EU/UK Users)
If you are located in the EU or UK, you have additional rights under GDPR:
- Right to restrict processing
- Right to data portability
- Right to object to processing based on legitimate interest
- Right to withdraw consent where processing is based on consent
7.3 US State Privacy Rights
California (CCPA/CPRA): If you are a California resident, you have rights under the California Consumer Privacy Act:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (note: we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
Virginia (VCDPA): If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to non-discrimination for exercising your privacy rights
Colorado (CPA): If you are a Colorado resident, you have rights under the Colorado Privacy Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to data portability
Connecticut (CTDPA): If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to data portability
Utah (UCPA): If you are a Utah resident, you have rights under the Utah Consumer Privacy Act:
- Right to access and delete personal information
- Right to opt-out of targeted advertising
- Right to non-discrimination for exercising your privacy rights
7.4 US Federal Privacy Laws
COPPA (Children’s Online Privacy Protection Act): See Section 9 for our children’s privacy practices and age-appropriate data handling.
7.5 How to Exercise Your Rights
To exercise any of these rights:
- Through Shopify: Use Shopify’s built-in data request mechanisms
- Email Us: Contact support@optiz.io
- Response Time: We typically respond within 2 business days
8. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
- EU/UK: We comply with GDPR requirements for international transfers
- Third-Party Services: Cloudflare, Intercom, and Sentry are each certified under the EU-U.S. Data Privacy Framework, including the UK Extension, and are engaged under data processing agreements incorporating Standard Contractual Clauses where applicable. The transfer safeguard relied upon for each is identified in Annex I of our Data Processing Agreement.
- Safeguards: We ensure adequate protection through contractual obligations and compliance certifications
9. Children’s Privacy
Our App is not intended for use by individuals under the applicable age of digital consent. We do not knowingly collect personal information from children under the relevant age threshold:
- GDPR (EU/UK): 16 years (or lower age set by member state law)
- COPPA (USA): 13 years
- PIPEDA (Canada): 13 years
- South Korea: 14 years
- Other jurisdictions: As required by local law
If you believe we have inadvertently collected information from a child under the applicable age, please contact us immediately and we will take steps to remove such information.
10. Artificial Intelligence and Automated Processing
10.1 The Discounting Engine Is Not AI
Discount Kit’s discount logic is deterministic, rule-based software. It evaluates the conditions you configure in our admin interface — quantity thresholds, spend goals, product and collection targets, market, location, B2B status, and customer tags — using fixed arithmetic and boolean logic. The same rule applied to the same cart always produces the same result.
We do not operate, host, train, fine-tune or distribute any artificial intelligence model or machine learning system as part of the App. There is no inference, scoring, ranking, prediction, profiling or probabilistic output anywhere in the discounting engine.
For merchants assessing obligations under Regulation (EU) 2024/1689 (the “EU AI Act”): our assessment is that the App is not an AI system within the meaning of Article 3(1), because it is a system based on rules defined solely by natural persons to automatically execute operations (Recital 12). Optizio Ltd is not a provider of an AI system or a general-purpose AI model in respect of the App.
10.2 Shopify Sidekick Integration
Discount Kit integrates with Shopify Sidekick, the AI assistant built into the Shopify admin. Shopify is the provider and operator of Sidekick; we are not. Our role is limited to exposing a set of deterministic tools that Sidekick can call at your staff member’s request — searching your existing discounts, explaining how one is configured, validating a configuration, and setting fields in our discount builder.
- Merchant-facing only. The integration operates inside the Shopify admin. It is not embedded in your storefront and does not interact with your customers.
- A human decides. Sidekick can populate our discount builder, but it cannot save or activate a discount. Saving requires a person to review the form and click Save.
- What we contribute. Discount configuration only: titles, status, schedules, discount types, thresholds and rewards, product and collection references, discount codes, your store domain, and the eligibility values you configured, including customer tag names you selected. No individual customer record is involved.
- Your Shopify relationship governs the conversation itself. How Shopify processes what your staff type into Sidekick is governed by your agreement with Shopify, not by this policy.
10.3 No Model Training on Your Data
We do not use your data, your configuration, your content or your customers’ data to train, fine-tune or evaluate any artificial intelligence model, and we do not supply it to any third party for that purpose.
10.4 No Automated Decision-Making About Individuals
We do not carry out automated decision-making, including profiling, that produces legal effects concerning any individual or similarly significantly affects them, within the meaning of Article 22 of the GDPR. Applying a promotional discount to a cart according to rules you authored is not such a decision.
Discount eligibility is evaluated without us receiving your customer’s identity. Where a rule depends on customer tags, Shopify returns only a true or false result for the specific tags named in your rule; we do not receive customer names, email addresses, contact details, order history or full tag lists. See section 2.3.
10.5 No AI-Generated Content
The App does not generate or alter text, images, audio or video. All merchant-facing and storefront-facing content is either entered by you or drawn from our static, human-written translation files. We therefore supply no synthetic or AI-generated content requiring disclosure or machine-readable marking.
10.6 AI-Assisted Software Development
Our engineers use AI-assisted coding tools when developing the App, as is now standard in software development. These tools operate on our own source code. Merchant data, store configuration and customer data are not provided to them. All AI-assisted code passes through the same review, automated testing and release process as any other change.
10.7 Changes to This Position
If we introduce a feature that changes any of the above, we will update this section before that feature becomes available to you, and material changes are notified as set out in section 11.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the “Last Updated” date at the top of this policy
- For significant changes, we will notify you via email (if provided) or through in-app notifications
- We will provide at least 30 days advance notice of material changes
- Continued use of the App after changes constitutes acceptance of the updated policy
12. Compliance with Local Laws
12.1 Primary Jurisdictions
This Privacy Policy is designed to comply with privacy laws in multiple jurisdictions, including:
- GDPR (European Union and United Kingdom)
- US State Privacy Laws (California CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA)
- US Federal Laws (COPPA, New York SHIELD Act)
- PIPEDA (Canada)
12.2 Additional Jurisdictions
If you have questions about how local privacy laws apply to your use of our App, please contact us.
For questions about this Privacy Policy or to exercise your privacy rights:
Data Protection Officer: David Spanton
Email: support@optiz.io
Address: Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
For GDPR-related inquiries in the EU/UK:
You also have the right to lodge a complaint with your local data protection authority.
For CCPA-related inquiries in California:
You may contact the California Attorney General’s office regarding privacy concerns.
This Privacy Policy is effective as of the 21st July 2025 and governs your use of the Discount Kit Shopify application.