Privacy Policy
Last updated 19 August 2026
This policy explains what information Toolbox Technology handles when you visit this website and when a merchant installs the AOVtools app on a Shopify store. It applies to toolboxtechnology.com and to the AOVtools app.
1. This website
We do not collect personal information from visitors to this website. There are no accounts, no contact forms, no advertising trackers and no analytics. We do not set cookies.
Our hosting provider processes standard server request data, such as IP address and browser type, for security and to deliver the page. We do not use that data to build a profile of you and we do not have access to it in a form that identifies you.
2. Information the app collects
When a merchant installs AOVtools, Shopify grants the app access to store data under the permissions shown during installation. The app stores:
- Store details, including the myshopify.com domain, store name, contact email, plan and currency.
- Staff account details for people who sign in to AOVtools, limited to the email address, name and Shopify user ID returned by Shopify at login.
- Catalogue data, including products, variants, prices, images, collections and inventory levels by location.
- Campaign configuration created by the merchant, such as offers, thresholds, gift selections, schedules and promotional artwork.
- Operational records, including webhook deliveries from Shopify, sync job status and login session records.
The app does not collect names, email addresses, payment details or contact information belonging to shoppers on a merchant's storefront. The storefront widget reads only the current cart contents in the shopper's browser so it can display offer progress. It does not identify the shopper and does not send shopper details to us.
3. How we use information
We use the information above to:
- Operate the app and apply the campaigns a merchant configures.
- Keep catalogue and inventory data current with the connected store.
- Authenticate staff users and maintain signed-in sessions.
- Diagnose faults, investigate abuse and keep the service secure.
- Meet our legal and tax obligations.
Where the UK GDPR or EU GDPR applies, our lawful basis is performance of a contract with the merchant, and our legitimate interest in securing and improving the service. We act as a processor for store data supplied by the merchant, and the merchant is the controller of that data.
4. What we do not do
- We do not sell personal information, and we never have.
- We do not share it with advertisers or data brokers.
- We do not use it to train machine learning models.
- We do not use merchant data to market to their customers.
- We do not combine data across merchants. Every record is scoped to a single store.
5. Service providers
We share data only with the providers needed to run the service, and only to the extent needed. Each is bound by contract to protect it.
| Provider | Purpose |
|---|---|
| Shopify | The platform the app runs on and the source of store data |
| Cloudflare | Application hosting, storage and content delivery |
| Supabase | Managed database hosting |
We may also disclose information if required by law, or to protect our rights, safety or property. If the business is sold or merges with another company, data may transfer as part of that transaction, and this policy will continue to apply until it is replaced.
6. Data retention
We keep store and campaign data for as long as the app is installed. Some records are deleted on a shorter schedule:
| Record | Retention |
|---|---|
| Login sessions | Expire after 7 days, then deleted |
| Webhook delivery records | 30 days |
| Installation tokens | Deleted when the app is uninstalled |
When a merchant uninstalls the app, our access to the store ends immediately and stored access credentials are destroyed. We retain catalogue and campaign records for 90 days so that a reinstall restores prior configuration, after which they are deleted. A merchant can ask us to delete everything sooner.
7. Security
Access credentials for a store are encrypted before they are written to the database, using AES-256-GCM with keys held outside it. All traffic runs over HTTPS. Requests from Shopify are cryptographically verified before they are accepted. Every database query is scoped to a single store, so one merchant's data cannot be returned to another.
No system is perfectly secure. If a breach affects personal information, we will notify affected merchants and the relevant regulator as required by law.
8. International transfers
We are based in the United States, and our providers operate globally. Information is processed in the United States and may be processed in other countries whose data protection laws differ from those where the merchant is located. For merchants in the European Economic Area, the United Kingdom or Switzerland, these transfers rely on Standard Contractual Clauses or an equivalent safeguard offered by the provider.
9. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a copy in a portable format, object to or restrict how we use it, and withdraw consent where we relied on it. You also have the right to complain to a data protection authority in your country.
California residents have the right to know what personal information is collected and to request deletion. We do not sell or share personal information as those terms are defined by the CCPA, so there is nothing to opt out of. We will not discriminate against anyone for exercising a right.
To make a request, contact us using the details below. We will respond within 30 days. If a request concerns data we hold on behalf of a merchant, we will refer it to that merchant, who is the controller.
10. Children
The service is intended for businesses. It is not directed at children under 16, and we do not knowingly collect their personal information. If we learn that we have, we will delete it.
11. Changes to this policy
We may update this policy as the service changes. The date at the top shows when it was last revised. If a change materially affects how we handle personal information, we will tell merchants inside the app or by email before it takes effect.
12. Contact
Questions about this policy, or requests about your data, can be sent to privacy@toolboxtechnology.com.