CounterFields - Privacy Policy

CounterFields ("the app") lets Shopify merchants add structured, validated questions to the Shopify POS counter - serial numbers, membership IDs, engraving text, fitting notes, delivery instructions - and writes the answers onto the Shopify order. This policy explains what data the app processes and why.

Capture only

Answers entered at the counter are written directly onto the Shopify order as line item properties and order note attributes, using Shopify's POS Cart API on the device. They are never transmitted to, or stored by, CounterFields. There is no database table for captured values, and the app has no ability to read orders back. Merchants view and export their entries in Shopify admin.

Data we process

The app reads the store's products, collections and product tags (scope read_products) solely to work out which products a merchant's field set applies to, and stores the resulting product-ID-to-field-set lookup. It reads the store's locations and their names (scope read_locations) so a merchant can restrict a field set to chosen shops. It stores the merchant's own field definitions - labels, help text, field types, validation rules, targeting and location choices - along with the store domain, the Shopify access token issued to this app, a configuration version number, and the ID and timestamp of POS locations that have downloaded those definitions.

Data we do NOT collect

CounterFields stores no customer personal data: no names, emails, addresses, phone numbers, payment details, order records or customer identifiers. It does not request the read_orders, read_all_orders, read_customers or write_orders scopes and holds no protected customer data. It stores no staff names or staff IDs. No cookies, no advertising, no tracking.

Fields a merchant designs

A merchant can define a field that collects personal information, for example a delivery address or a phone number. Any such value is written onto the Shopify order and is governed by the merchant's own privacy policy and Shopify's data handling. It is still never transmitted to or stored by CounterFields.

Data retention and deletion

Field definitions are kept for as long as the app is installed. Uninstalling the app removes its access to the store immediately, and every stored record for the shop is permanently deleted in response to Shopify's shop redaction webhook. The customer data request and customer redaction webhooks are answered with a confirmation that no customer data is held. Data already written onto a Shopify order is the merchant's, held by Shopify, and is not affected.

Third parties

No data is sold, shared or sent to any third party. The only network calls the app makes are to Shopify's own APIs.

Contact

Fleeta Limited - sales@fleeta.co.uk