Bogo

Spend X · Free gift offers for Shopify

Privacy Policy

Last updated: August 8, 2026 · Effective for the Bogo Shopify application hosted at bogo-mu.vercel.app

1. Introduction

This Privacy Policy explains how Bogo (“we”, “us”, or “the App”) collects, uses, stores, and protects information when a merchant installs and uses the App on their Shopify store. By installing or using Bogo, you agree to this policy.

Bogo helps merchants create “spend X, get a free gift” promotions, including offer configuration in the Shopify admin, automatic gift handling on the storefront, and related discount setup.

2. Who this policy applies to

  • Merchants — store owners and staff who install and configure Bogo in Shopify Admin.
  • Storefront shoppers — customers who interact with carts and gift offers on a merchant’s Online Store. We do not intentionally collect personal profiles of shoppers beyond what is needed to run the offer on the merchant’s storefront.

3. Information we collect

3.1 From Shopify (merchant / shop data)

When you install Bogo, Shopify provides access (based on the scopes you approve) that may include:

  • Shop domain and shop identifiers
  • Offline / online session and access tokens required to call the Shopify Admin API
  • Product and variant details for the selected free-gift product (title, image, price, availability)
  • Discount / price-rule related data created or updated for the offer
  • Theme-related information needed to detect whether the app embed is enabled
  • Metaobject and shop metafield values used to store offer configuration for the storefront

3.2 Offer and display configuration

We store the merchant’s offer settings, for example: minimum cart value, gift product, discount code references, widget title templates, placement flags, colors, progress-bar visibility, and related display preferences.

3.3 Technical / operational data

  • Authentication session records needed to keep the embedded admin app logged in
  • Standard server logs (e.g. request timestamps, error diagnostics) from our hosting provider
  • App uninstall signals from Shopify webhooks so we can clean up shop-related data

3.4 What we do not collect

  • We do not sell merchant or customer personal data
  • We do not use shopper browsing history outside the merchant’s storefront offer logic
  • We do not request payment card numbers; checkout remains on Shopify

4. How we use information

  • Authenticate and authorize the merchant inside the embedded Shopify admin app
  • Create, update, activate, or deactivate gift discounts for the configured offer
  • Persist offer settings for the admin UI and sync public storefront config via Shopify metafields / metaobjects
  • Render and update the cart / gift widget on the Online Store according to merchant settings
  • Detect app embed status and improve reliability of the free-gift experience
  • Respond to support requests and maintain the security and integrity of the App
  • Comply with legal obligations and Shopify Partner / App Store requirements

5. Where data is stored

  • Application database (Neon / PostgreSQL) — Shopify session records and per-shop offer configuration JSON used by the admin app.
  • Shopify platform — discounts, metaobjects, and the shop metafield used by the theme app extension so the storefront can read offer settings.
  • Hosting (Vercel) — application runtime and infrastructure logs as provided by the host.

Data may be processed in regions where our providers operate. We take reasonable measures to protect data in transit (HTTPS) and at rest through our providers’ controls.

6. Sharing of information

We share data only as needed to operate the App:

  • Shopify — to read/write shop resources you authorize via OAuth scopes
  • Infrastructure providers (e.g. Vercel, Neon) — solely to host and run the App
  • Legal requirements — if required by law, regulation, or valid legal process

We do not sell personal information and do not share data with advertisers for cross-context behavioral advertising.

7. Cookies and similar technologies

The embedded admin app relies on Shopify’s session and authentication mechanisms. On the merchant’s storefront, the theme extension may use the Shopify cart APIs and local browser storage only as needed to apply the free-gift offer. We do not use third-party advertising cookies in the App.

8. Data retention and deletion

  • Session and offer data are retained while the App remains installed and as needed to provide the service.
  • When you uninstall Bogo, Shopify sends an uninstall webhook. We use that signal to remove or invalidate shop session data associated with your store from our application database.
  • Offer-related discounts, metafields, or metaobjects that remain on your Shopify shop after uninstall can be removed by you in Shopify Admin, or may be cleaned up where our uninstall handling allows.
  • Aggregated / anonymized operational logs may be retained for a limited period for security and debugging.

To request deletion of remaining App-stored data for your shop, contact us using the details below and include your *.myshopify.com domain.

9. Security

We use industry-standard practices appropriate to an embedded Shopify app, including OAuth, encrypted transport (HTTPS), scoped API access, and restricted database credentials. No method of transmission or storage is 100% secure; we continuously work to improve protections.

10. Children’s privacy

Bogo is a business application for Shopify merchants and is not directed at children under 16. We do not knowingly collect personal information from children.

11. Your rights and choices

Depending on your location, you may have rights to access, correct, or delete personal information we hold about your merchant account, or to object to certain processing. You can:

  • Uninstall the App from Shopify Admin at any time
  • Update offer settings or unpublish offers inside the App
  • Contact us to request access or deletion of App-stored shop data

12. Third-party services

The App integrates with Shopify and relies on hosting/database providers. Their privacy practices are governed by their own policies. We encourage you to review Shopify’s and our providers’ documentation.

13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the App after an update constitutes acceptance of the revised policy where permitted by law.

14. Contact

For privacy questions, data requests, or support related to Bogo: