Privacy Policy - Stackable
Effective Date: 10th September 2026
Last Updated: 10th September 2026
1. Introduction
Optizio Ltd (“we,” “us,” or “our”) operates the Stackable: Combined Discounts Shopify application (“App”). This Privacy Policy explains how we collect, use, disclose, and protect information when you use our App.
Company Information:
- Company Name: Optizio Ltd
- Address: 124 City Road, London, EC1V 2NX, United Kingdom
- Data Protection Officer: David Spanton
- Contact: support@optiz.io
When you install and use our App, we collect:
- Store Information: Store name, store ID, myshopify domain, primary contact email, Shopify plan, currency, timezone, locale, and country
- User Information: Names and email addresses of store staff who interact with the App’s admin interface
- Configuration Data: Your discount configuration, including tier thresholds and reward values, and Shopify GIDs for the products, collections, discounts and locations you reference. Configuration for linked discount codes, code blocking rules and checkout upsell offers is stored as metafields and metaobjects inside your own Shopify store
- Contact Preferences: Any additional transactional or newsletter email addresses you choose to enter in the App’s settings, and your newsletter subscription preference
- Technical Information: System information, app usage data, and performance metrics
- Upsell Order Attribution: Where an order contains an item added through the App’s checkout upsell, we receive the product and variant identifiers, quantity, price and currency for that item so we can record an aggregate conversion event with Shopify. This information is processed in transit and is not retained on our systems. No customer details from the order are received or stored
- Support Information: Information provided during support interactions
- We do not collect personal data from your customers (end-users). We receive no customer names, email addresses, postal addresses, telephone numbers, account details or order history
- We do not request the Shopify
read_customers access scope, and the App has no ability to read your customer records
- We do not store or process credit card or payment information
- We do not set tracking cookies, web beacons, tags or pixels, and we do not track or profile individual shoppers
- We do not use customer tags, customer segments or any other customer attribute to determine discount eligibility. Discounts are calculated from cart contents alone
- We do not collect unnecessary personal information beyond what is required for app functionality
2.4 Shopify Access Scopes
The App requests the following Shopify access scopes. Each is limited to what a specific feature requires:
| Scope |
Purpose |
write_discounts |
Create and update the App’s discounts and write the configuration that drives them |
read_discounts |
List your existing discounts in the App, validate combinations, and display usage figures |
read_products |
Populate the product and collection pickers in the discount builder and upsell configuration |
read_orders |
Receive notification of orders containing an upsell item, in order to record the conversion described in section 2.2. Shopify filters these notifications so we receive only orders containing such an item |
read_locations |
List your retail locations so you can choose where the point of sale discount tile applies |
write_locations |
Save your point of sale discount selection to the relevant location |
write_metaobject_definitions |
Create the App’s configuration structures inside your own store, so your configuration remains in your Shopify account |
We do not request any customer, order-writing, theme, or script tag scope beyond those listed above.
3.1 Primary Uses
We use the collected information for:
- App Functionality: Providing and maintaining the stackable discount, linked discount code, code blocking, checkout upsell and point of sale features
- Support Services: Responding to your inquiries and providing technical support
- Product Updates: Communicating important app updates and new features
- Analytics: Understanding app performance and usage patterns to improve our services
3.2 Legal Basis for Processing
We rely on different legal bases depending on jurisdiction:
- GDPR (EU/UK): Primarily legitimate interest for app functionality and business operations; contract performance where processing is necessary to fulfill our agreement with you
- Consent-based jurisdictions (Brazil LGPD, India DPDP, South Korea PIPA): Explicit consent obtained during app installation and configuration
- US State Laws: Legitimate interest for app functionality, with consent obtained where required by specific state requirements
- Other jurisdictions: Appropriate legal basis as required by local privacy laws
3.3 Consent Management
For jurisdictions requiring explicit consent, we:
- Obtain clear, informed consent during app installation and setup
- Provide easy mechanisms to withdraw consent through app settings or email
- Maintain records of consent and withdrawal for compliance purposes
- Re-obtain consent when required by law or when expanding data processing activities
- Honor consent withdrawal by ceasing relevant processing activities
Marketing and newsletter communications are separate from service and support communications. You can change your newsletter preference at any time in the App’s settings, and service communications necessary to operate the App will continue regardless of that setting.
4.1 Third-Party Service Providers
We share information with the following trusted third-party services:
Cloudflare
- Purpose: Application hosting, session storage, caching, and the database holding the store and staff records described in section 2.1
- Data Shared: Store information, staff names and email addresses, contact preferences, and the technical and configuration data necessary for app operation
- Data Location: EU and US data centre locations
- Compliance: GDPR compliant with appropriate data processing agreements
Sentry
- Purpose: Application error monitoring and diagnostics
- Data Shared: Technical error and performance data, which may include your store domain and staff identifiers
- Data Location: United States
- Compliance: GDPR compliant with appropriate data processing agreements
Intercom
- Purpose: Handling support enquiries and service correspondence
- Data Shared: The contents of your correspondence with us, including your name, email address and store URL. The App contains no support messenger, so information reaches Intercom only through correspondence you send us
- Data Location: Dublin, Ireland for EU customers
- Compliance: GDPR compliant with appropriate data processing agreements
4.2 Shopify Integration
We share data with Shopify only as required for app functionality and in accordance with Shopify’s Partner Program requirements.
Two aspects of the App’s design are relevant to your privacy assessment:
- Your configuration stays in your store. Discount configuration, linked code rules, code blocking rules and upsell settings are stored as metafields and metaobjects within your own Shopify account. You can read, export and delete this data yourself at any time through the Shopify admin or the Shopify API.
- Discount calculation happens inside Shopify. The discount logic runs as a Shopify Function within Shopify’s checkout. It reads only the configuration you authored and the contents of the cart, and it makes no call to Optizio systems. No cart or checkout data is transmitted to us.
4.3 What We Don’t Share
- We do not sell, rent, or trade your personal information
- We do not share your data with advertisers or marketing companies
- We do not provide your information to third parties except as described in this policy
5. Data Security
We implement comprehensive security measures to protect your information:
- Encryption: All sensitive data is encrypted both at rest and in transit using industry-standard encryption (AES-256)
- Access Controls: Access to data is granted based on job roles and the principle of least privilege
- Authentication: Multi-factor authentication (MFA) is required for all critical systems
- No Separate Credentials: The App has no user accounts and no passwords of its own. Access is authenticated by Shopify and governed by the staff permissions you set in your Shopify admin, so removing a staff member in Shopify immediately removes their access to the App
- Regular Updates: We maintain up-to-date software and security patches
- Monitoring: Continuous monitoring for security threats and incidents
- Compliance: We follow Shopify’s secure app development guidelines and maintain comprehensive security policies
For detailed information about our security practices, please refer to our Information Security Policy.
6. Data Retention
6.1 Retention Periods
- Configuration Data: Held in your own Shopify store rather than on our systems, as described in section 4.2. It remains under your control, and uninstalling the App does not remove it from your store. You can delete it at any time through the Shopify admin or API
- Session Data: Deleted automatically when you uninstall the App
- Store and Staff Records: Retained while the App is installed. Following uninstall, the record is marked as uninstalled and retained only for as long as necessary to support reinstallation, to meet our billing, accounting and legal obligations, and to resolve any dispute. You may request deletion at any time under section 7
- Billing and Subscription Records: Retained for 6 years, as required by UK statutory accounting and tax obligations
- Support Data: 3 years after last interaction
These retention periods comply with data minimization principles and are designed to meet the requirements of all applicable privacy laws.
6.2 Data Deletion
Upon request or at the end of retention periods, we will permanently delete your information from our systems and instruct our third-party service providers to do the same.
On request we will provide a copy of, or permanently delete, all store and staff records we hold for your shop domain. Contact us at support@optiz.io or use Shopify’s built-in data request mechanisms.
6.3 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify relevant supervisory authorities within 72 hours where required by law
- Notify affected individuals without undue delay
- Provide clear information about the nature of the breach and steps being taken
- Comply with jurisdiction-specific notification requirements (GDPR, US state laws, PIPEDA, etc.)
- Follow New York SHIELD Act requirements for data security and breach notification
7. Your Rights and Choices
7.1 General Rights
You have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to our processing of your personal information
7.2 GDPR Rights (EU/UK Users)
If you are located in the EU or UK, you have additional rights under GDPR:
- Right to restrict processing
- Right to data portability
- Right to object to processing based on legitimate interest
- Right to withdraw consent where processing is based on consent
7.3 US State Privacy Rights
California (CCPA/CPRA): If you are a California resident, you have rights under the California Consumer Privacy Act:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (note: we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
Virginia (VCDPA): If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to non-discrimination for exercising your privacy rights
Colorado (CPA): If you are a Colorado resident, you have rights under the Colorado Privacy Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to data portability
Connecticut (CTDPA): If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act:
- Right to access, correct, and delete personal information
- Right to opt-out of targeted advertising and profiling
- Right to data portability
Utah (UCPA): If you are a Utah resident, you have rights under the Utah Consumer Privacy Act:
- Right to access and delete personal information
- Right to opt-out of targeted advertising
- Right to non-discrimination for exercising your privacy rights
7.4 US Federal Privacy Laws
COPPA (Children’s Online Privacy Protection Act): See Section 9 for our children’s privacy practices and age-appropriate data handling.
7.5 How to Exercise Your Rights
To exercise any of these rights:
- Through Shopify: Use Shopify’s built-in data request mechanisms
- Email Us: Contact support@optiz.io
- Response Time: We typically respond within 2 business days
8. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
- Transfers to Optizio: Optizio Ltd is established in the United Kingdom. Transfers of personal data from the European Economic Area to us are made on the basis of the European Commission’s adequacy decision in respect of the United Kingdom, renewed on 19 December 2025
- Third-Party Services: Cloudflare, Sentry and Intercom are each certified under the EU-U.S. Data Privacy Framework, including the UK Extension, and are engaged under data processing agreements incorporating Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable
- Processing Locations: The processing location for each service provider is stated in section 4.1
- Safeguards: We ensure adequate protection through contractual obligations and compliance certifications. If a certification we rely upon lapses or is invalidated, we will transfer under an alternative recognised safeguard or cease the transfer
9. Children’s Privacy
Our App is not intended for use by individuals under the applicable age of digital consent. We do not knowingly collect personal information from children under the relevant age threshold:
- GDPR (EU/UK): 16 years (or lower age set by member state law)
- COPPA (USA): 13 years
- PIPEDA (Canada): 13 years
- South Korea: 14 years
- Other jurisdictions: As required by local law
If you believe we have inadvertently collected information from a child under the applicable age, please contact us immediately and we will take steps to remove such information.
10. Artificial Intelligence and Automated Processing
10.1 The Discounting Engine Is Not AI
Stackable’s discount logic is deterministic, rule-based software. It evaluates the conditions you configure in our admin interface — quantity thresholds, spend thresholds, and the collections you target — using fixed arithmetic and boolean logic. The same rule applied to the same cart always produces the same result.
We do not operate, host, train, fine-tune or distribute any artificial intelligence model or machine learning system as part of the App. There is no inference, scoring, ranking, prediction, profiling or probabilistic output anywhere in the discounting engine.
For merchants assessing obligations under Regulation (EU) 2024/1689 (the “EU AI Act”): our assessment is that the App is not an AI system within the meaning of Article 3(1), because it is a system based on rules defined solely by natural persons to automatically execute operations (Recital 12). Optizio Ltd is not a provider of an AI system or a general-purpose AI model in respect of the App.
10.2 No Model Training on Your Data
We do not use your data, your configuration, your content or your customers’ data to train, fine-tune or evaluate any artificial intelligence model, and we do not supply it to any third party for that purpose.
10.3 No Automated Decision-Making About Individuals
We do not carry out automated decision-making, including profiling, that produces legal effects concerning any individual or similarly significantly affects them, within the meaning of Article 22 of the GDPR. Applying a promotional discount to a cart according to rules you authored is not such a decision.
Discount eligibility is determined from the contents of the cart alone. The App does not read, receive or evaluate any customer attribute, tag or segment, and it does not receive your customer’s identity. See sections 2.3 and 4.2.
10.4 No AI-Generated Content
The App does not generate or alter text, images, audio or video. All merchant-facing and storefront-facing content is either entered by you or drawn from our static, human-written translation files. We therefore supply no synthetic or AI-generated content requiring disclosure or machine-readable marking.
10.5 AI-Assisted Software Development
Our engineers use AI-assisted coding tools when developing the App, as is now standard in software development. These tools operate on our own source code. Merchant data, store configuration and customer data are not provided to them. All AI-assisted code passes through the same review, automated testing and release process as any other change.
10.6 Changes to This Position
If we introduce a feature that changes any of the above, we will update this section before that feature becomes available to you, and material changes are notified as set out in section 11.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the “Last Updated” date at the top of this policy
- For significant changes, we will notify you via email (if provided) or through in-app notifications
- We will provide at least 30 days advance notice of material changes
- Continued use of the App after changes constitutes acceptance of the updated policy
12. Compliance with Local Laws
12.1 Primary Jurisdictions
This Privacy Policy is designed to comply with privacy laws in multiple jurisdictions, including:
- GDPR (European Union and United Kingdom)
- US State Privacy Laws (California CCPA/CPRA, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA)
- US Federal Laws (COPPA, New York SHIELD Act)
- PIPEDA (Canada)
12.2 Additional Jurisdictions
If you have questions about how local privacy laws apply to your use of our App, please contact us.
For questions about this Privacy Policy or to exercise your privacy rights:
Data Protection Officer: David Spanton
Email: support@optiz.io
Address: Optizio Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
For GDPR-related inquiries in the EU/UK:
You also have the right to lodge a complaint with your local data protection authority.
For CCPA-related inquiries in California:
You may contact the California Attorney General’s office regarding privacy concerns.
This Privacy Policy is effective as of the 10th September 2026 and governs your use of the Stackable: Combined Discounts Shopify application.