AmImA DEV ("we", "us") operates the AmImA Cart Drawer app for Shopify. This policy explains what the app collects, why, and how long it is kept.
The short version: we store your store configuration and anonymous cart statistics. We do not use your customers' personal data at all. When a cart converts we read the order amount, so that usage charges are billed accurately, and nothing that identifies the shopper.
1. Who this applies to
This policy covers merchants who install the app on their Shopify store. It also explains what the app does and does not collect about visitors to those stores.
2. What we collect from merchants
When you install the app, we receive from Shopify and store:
- Your store's myshopify domain
- Your store name, contact email, phone number and country
- The company name on your billing address
- Your Shopify plan name
- Install and uninstall dates, and how many times you have installed
3. The configuration you create
We also store everything you build in the app, so it is there when you come back:
- All cart drawer design settings and saved cart designs
- Reward tier definitions, upsell configuration and add-on configuration
- Your translations
- The IDs of the Shopify discounts the app created on your behalf
- Your subscription plan and billing status
- If you contact support through the app: the email address and message you submit, and which page you sent it from
4. Customer data — what we do not use
We do not use your customers' personal data. Not their names, email addresses, phone numbers, postal addresses or payment details, and not their IP addresses, geolocation, browser or operating system.
Shopify's app listing lists device and activity data — geolocation, IP address, browser and operating system — among the data this kind of app is able to access. AmImA does not read, record, store or transmit any of it.
What the app does record is anonymous cart activity, so you can measure performance: that a cart was viewed, that checkout was clicked, that an upsell was added, and Shopify's cart token. When a cart converts we read the order amount, so your usage charges are calculated accurately and the order can be attributed back to the cart that produced it. None of this is linked to a person.
The drawer stores a countdown deadline in the browser's own sessionStorage so a promotional timer does not restart when a shopper refreshes the page. That value never leaves the shopper's browser.
5. Shopify permissions and why we need them
The app requests only the scopes it uses:
| Permission | Why it is needed |
|---|---|
| read_products | Product and variant lookups for upsells and pickers |
| write_products | Creates the hidden add-on product and its price ladder |
| write_discounts | Creates and maintains reward tier discounts |
| read_discounts | Required by Shopify to set discount combination rules |
| write_files | Logo and trust badge uploads |
| read_publications / write_publications | Publishes the add-on product to your Online Store |
| read_orders | Matches orders back to the cart, for conversion reporting |
| read_locales | Lists your store's published languages for translations |
6. How long we keep it
Data is kept only as long as it is useful to you:
- Configuration and settings: for as long as the app is installed
- Anonymous cart events: automatically deleted after 90 days
- Support messages: retained for support history
- On uninstall: your session is deleted immediately, along with the app's discount tracking records
- 48 hours after uninstall, when Shopify sends its shop redaction request, we permanently delete all remaining data for your store
7. GDPR and CCPA
We implement Shopify's mandatory compliance webhooks. Because the app holds no customer personal data, customers/data_request has nothing to report and customers/redact has nothing to delete; shop/redact permanently deletes all data for your store.
You may request access to, correction of, or deletion of your merchant data at any time by emailing info@amima.me.
Reinstalling within the 48-hour redaction window restores your settings. After it, the app starts fresh.
8. Subprocessors
We share data only with the vendors that run the service:
- Shopify — the platform the app runs on
- Vercel — application hosting
- Resend — transactional email for support replies
9. Security
All traffic is served over HTTPS. Access to Shopify's API uses session tokens rather than third-party cookies. Webhook requests are verified by signature and rejected if they do not match.
10. International transfers
AmImA DEV is based in Pakistan, and the app runs on infrastructure provided by Vercel Inc., a United States company. Merchant data may therefore be processed in the United States and in the other countries where Vercel operates data centres.
Where personal data protected by the GDPR or the UK GDPR is transferred outside the EEA or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum, as incorporated in Vercel's data processing agreement.
Because the app processes no shopper personal data at all (see section 4), these transfers concern merchant account and configuration data only.
11. Changes to this policy
We will update this page when the app's data handling changes, and revise the date at the top.
Contact
AmImA DEV, Budhla Sant Multan, Allied Bank — Budhla Sant Multan, Budhla Sant, Multan 59021, Pakistan. Questions about this policy or a data request? We answer every message, usually within 4 to 8 hours.
info@amima.me