Skip to content
Every feature on every plan — plans differ only by order volume.See pricing
AmImA Cart Drawer

Legal

Privacy Policy

What the app collects, why, and how long it is kept.

Last updated 8 September 2026

AmImA DEV ("we", "us") operates the AmImA Cart Drawer app for Shopify. This policy explains what the app collects, why, and how long it is kept.

The short version: we store your store configuration and anonymous cart statistics. We do not use your customers' personal data at all. When a cart converts we read the order amount, so that usage charges are billed accurately, and nothing that identifies the shopper.

1. Who this applies to

This policy covers merchants who install the app on their Shopify store. It also explains what the app does and does not collect about visitors to those stores.

2. What we collect from merchants

When you install the app, we receive from Shopify and store:

  • Your store's myshopify domain
  • Your store name, contact email, phone number and country
  • The company name on your billing address
  • Your Shopify plan name
  • Install and uninstall dates, and how many times you have installed

3. The configuration you create

We also store everything you build in the app, so it is there when you come back:

  • All cart drawer design settings and saved cart designs
  • Reward tier definitions, upsell configuration and add-on configuration
  • Your translations
  • The IDs of the Shopify discounts the app created on your behalf
  • Your subscription plan and billing status
  • If you contact support through the app: the email address and message you submit, and which page you sent it from

4. Customer data — what we do not use

We do not use your customers' personal data. Not their names, email addresses, phone numbers, postal addresses or payment details, and not their IP addresses, geolocation, browser or operating system.

Shopify's app listing lists device and activity data — geolocation, IP address, browser and operating system — among the data this kind of app is able to access. AmImA does not read, record, store or transmit any of it.

What the app does record is anonymous cart activity, so you can measure performance: that a cart was viewed, that checkout was clicked, that an upsell was added, and Shopify's cart token. When a cart converts we read the order amount, so your usage charges are calculated accurately and the order can be attributed back to the cart that produced it. None of this is linked to a person.

The drawer stores a countdown deadline in the browser's own sessionStorage so a promotional timer does not restart when a shopper refreshes the page. That value never leaves the shopper's browser.

5. Shopify permissions and why we need them

The app requests only the scopes it uses:

PermissionWhy it is needed
read_productsProduct and variant lookups for upsells and pickers
write_productsCreates the hidden add-on product and its price ladder
write_discountsCreates and maintains reward tier discounts
read_discountsRequired by Shopify to set discount combination rules
write_filesLogo and trust badge uploads
read_publications / write_publicationsPublishes the add-on product to your Online Store
read_ordersMatches orders back to the cart, for conversion reporting
read_localesLists your store's published languages for translations

6. How long we keep it

Data is kept only as long as it is useful to you:

  • Configuration and settings: for as long as the app is installed
  • Anonymous cart events: automatically deleted after 90 days
  • Support messages: retained for support history
  • On uninstall: your session is deleted immediately, along with the app's discount tracking records
  • 48 hours after uninstall, when Shopify sends its shop redaction request, we permanently delete all remaining data for your store

7. GDPR and CCPA

We implement Shopify's mandatory compliance webhooks. Because the app holds no customer personal data, customers/data_request has nothing to report and customers/redact has nothing to delete; shop/redact permanently deletes all data for your store.

You may request access to, correction of, or deletion of your merchant data at any time by emailing info@amima.me.

Reinstalling within the 48-hour redaction window restores your settings. After it, the app starts fresh.

8. Subprocessors

We share data only with the vendors that run the service:

  • Shopify — the platform the app runs on
  • Vercel — application hosting
  • Resend — transactional email for support replies

9. Security

All traffic is served over HTTPS. Access to Shopify's API uses session tokens rather than third-party cookies. Webhook requests are verified by signature and rejected if they do not match.

10. International transfers

AmImA DEV is based in Pakistan, and the app runs on infrastructure provided by Vercel Inc., a United States company. Merchant data may therefore be processed in the United States and in the other countries where Vercel operates data centres.

Where personal data protected by the GDPR or the UK GDPR is transferred outside the EEA or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum, as incorporated in Vercel's data processing agreement.

Because the app processes no shopper personal data at all (see section 4), these transfers concern merchant account and configuration data only.

11. Changes to this policy

We will update this page when the app's data handling changes, and revise the date at the top.

Contact

AmImA DEV, Budhla Sant Multan, Allied Bank — Budhla Sant Multan, Budhla Sant, Multan 59021, Pakistan. Questions about this policy or a data request? We answer every message, usually within 4 to 8 hours.

info@amima.me