Checkout AI: B2B Checkout
Privacy Policy
Effective September 20, 2026 · Smith Crafts LLC
Checkout AI: B2B Checkout (the “App”) is a Shopify app provided by Smith Crafts LLC (“we”, “us”). This policy explains what data the App accesses, why, and how we handle it. The App is an admin tool for authoring B2B checkout rules that run inside Shopify’s Functions runtime. We do not inject scripts or trackers into your storefront, and we do not store your customers’ names, postal addresses, email addresses, phone numbers, or payment details.
What we store today
- Shop identity & access tokens. Your shop domain and the offline access token Shopify issues at install, used to authenticate the App to your store. Kept while the App is installed and deleted on uninstall / shop redaction.
- Merchant-staff session data. The App uses Shopify’s Prisma session-storage adapter. Its schema includes columns for the Shopify staff user who installed or authorized the App —
userId,firstName,lastName,email,locale,accountOwner,collaborator, andemailVerified. The App itself does not read these fields for any feature; they may be populated by Shopify during authentication. They are deleted together with the rest of the shop’s sessions on uninstall and on Shopify’sshop/redactwebhook. - Rule configuration. The checkout rules you build (conditions, actions, messages) and the compiled function configuration — merchant-authored, not personal data. Published configuration lives with your store as Shopify metaobjects and function-owner metafields; the App database also stores drafts and working copies so you can review, edit, and publish rules.
- B2B targeting metafields we read to run rules. Company, company location, customer tags, and the buyer-segment metafield
custom.b2bcc_segmentthat you set. These are read at rule-evaluation time. The App never requests or reads customer names, addresses, emails, or phone numbers. - Support submissions. If you send a message through the App’s help form, we store the message you typed, the shop domain, and any contact address you provided so we can reply. Optionally forwarded to a merchant-configured webhook if
B2BCC_SUPPORT_FORWARD_URLis set. - AI rule drafts (optional). If you use the draft-a-rule-with-AI feature, the rule description you type is sent to our AI sub-processor (Anthropic) to generate a draft. The text you typed and the drafted rule are stored per-store so you can review, edit, and publish them. No customer data is sent to the AI provider.
- AI usage counters and plan state. Per-shop AI call counts, the detected billing plan handle, subscription id, and the current billing-period start, used to enforce plan-based quotas.
- Review-prompt state. Whether we have already prompted you to review the App and whether you dismissed the prompt.
- Historical order telemetry. New order ingestion and backfills are disabled. Registered order webhooks are acknowledged without storing order content. Historical order records remain subject to the retention and deletion rules below.
Historical order-audit data
Order auditing and its associated alerts have been retired. New order ingestion, backfills, detection, verification and alert delivery are disabled. The descriptions below identify historical records that may remain until the existing retention or privacy-deletion process removes them. They are not an offer to activate these features.
- Order webhook subscriptions. Registered order deliveries are acknowledged and discarded without processing order content. No new backfill scans are performed.
- Order-audit snapshot (what we store). Previously processed orders may have a sanitized snapshot to a table called
OrderAuditSnapshot. The snapshot contains: the order’s Shopify GraphQL id (GID) and order number, timestamp, sales channel, currency, per-line product/variant ids, product tags used for rule targeting, quantities and prices, discount applications, purchasing company and company-location references, and the recorded configuration reference. The snapshot schema is constructed so that customer name, postal address, email address, and phone number cannot be written to it. This constraint is enforced by a test that will run in continuous integration. - What is not stored. Customer name, billing or shipping address, email address, phone number, payment method details, and IP address. None of the corresponding protected customer fields are requested, read, or stored.
- Purpose limitation. Order-audit snapshots are used only for the originating shop’s historical audit and privacy obligations. They are not used for analytics on other shops, not shared, and not sold.
- Rule-configuration versioning. To replay an order against the rules that were live when the order was placed, the App stores an append-only
RuleConfigVersionrecord for every publish — the compiled shards, the underlying intent JSON, and a content hash. This is merchant-authored configuration, not personal data. - Leak findings and alerts. Findings are stored per shop with their lifecycle state (open, fix proposed, fixed, verified, intended). Alert-delivery records track which channels a finding was sent to (in-app card and, once we launch a delivery-tested email path, email) and per-shop alert preferences. No customer identifiers are stored in findings or alerts.
- Retention. Order-audit snapshots are retained for up to 90 days after the order is placed and are then deleted by an automated sweep. Leak findings are retained for the lifetime of the App installation so you can see the history of what was fixed and verified; individual findings can be deleted on request. All of this data is deleted for your shop within the Shopify-required window when we receive a
shop/redactwebhook, and any snapshot linked to a customer redaction request is deleted immediately on thecustomers/redactwebhook. - PCD level requested. Level 1 (order and B2B company data) only. We are not requesting Level 2 protected customer fields (name, address, email, phone).
What we do not do
- We do not store your customers’ names, postal or shipping addresses, email addresses, phone numbers, IP addresses, or payment details.
- We do not sell, rent, or share your data with third parties for their marketing.
- We do not use your shop’s data to train AI models.
- We do not inject scripts or tracking pixels into your storefront. Rules run inside Shopify’s own Functions runtime.
Sub-processors
- Shopify (Shopify Inc.) — hosts the platform, issues the OAuth tokens the App uses, sends the webhooks we subscribe to, and processes billing for our paid plans.
- DigitalOcean, LLC — hosts the App’s compute (App Platform) and provides the managed PostgreSQL database where the tables described above are stored. Both run in DigitalOcean’s U.S. East / New York region. Traffic to the App and to the database is served over TLS, and data is encrypted at rest.
- Anthropic, PBC — provides the large-language-model API used by the optional draft-a-rule-with-AI feature. Only the merchant-typed rule description is sent; no customer data.
- Merchant-configured support-forwarding endpoint (optional). If the merchant sets
B2BCC_SUPPORT_FORWARD_URL, support submissions are also POSTed to that URL. The merchant chooses and controls this endpoint. - Transactional email. Welcome messages use Resend. Order-audit alerts and digests are disabled. Historical delivery records remain subject to the retention and deletion rules below.
How data is protected
- Encryption in transit. All traffic to the App and to our sub-processors is served over HTTPS/TLS.
- Encryption at rest. The managed PostgreSQL database and the underlying App Platform storage — both DigitalOcean — encrypt data at rest.
- Access control. Production database and hosting credentials are held only by Smith Crafts LLC operators, are stored as hosting-provider secrets rather than in source control, and are rotated on personnel change.
- Minimum-necessary scope. The App’s installed OAuth scopes are listed in our public app configuration. Legacy order-related scopes remain configured while the retired processing paths are disabled; scope removal requires a separately reviewed Shopify configuration release.
Data retention & deletion
We retain installation, session, and rule data while the App is installed. When you uninstall, Shopify sends the App’s app/uninstalled webhook and we delete the shop’s Session rows immediately (including the merchant-staff fields listed above). About 48 hours later Shopify sends the mandatory shop/redact webhook, at which point we delete all remaining app-database records for the shop: AI rule drafts, support submissions, order-telemetry rows, AI usage counters, review-prompt state, and any historical order-audit snapshots, rule configuration versions, leak findings, and alert-delivery records.
When Shopify sends a customers/redact webhook, we delete any order-telemetry or order-audit-snapshot rows for the redacted customer’s orders identified in the payload.
When Shopify sends a customers/data_request webhook, the App responds with an inventory of the categories of data it may hold that reference a customer’s orders. Because the App never stores customer names, addresses, emails, or phone numbers, that inventory contains order-referenced records only. You may also email us at the address below to request deletion or a copy of the data we hold for your shop.
Your rights
Depending on your jurisdiction (including the EU/UK GDPR and the California CCPA/CPRA), you may have rights to access, correct, port, or delete data we hold that relates to you. Merchants can exercise these rights via the Shopify privacy webhooks described above or by emailing [email protected]. We respond within the timeframes required by applicable law. End customers of a merchant’s store should direct requests to the merchant, who is the data controller for their store’s customer data; we act as a processor on the merchant’s behalf.
International transfers
The App is operated from the United States. If you access it from elsewhere, your data may be transferred to and processed in the U.S. under the safeguards required by applicable law.
Changes
We may update this policy; material changes will be reflected by the effective date above and, where features that change data handling are added, in a same-release update. Continued use of the App after an update constitutes acceptance of the revised policy.
Contact
Smith Crafts LLC · Data-protection contact: [email protected].