Privacy Policy for CreditKit

Last updated: July 3, 2026

This Privacy Policy explains how CreditKit ("the App", "we", "us") collects, uses, stores, and shares information in connection with a Shopify store’s use of the App. It applies to every store that installs CreditKit and to the store’s customers whose data the App processes on the store’s behalf.

Our role: processor, not controller

The merchant who installs CreditKit ("the Merchant") is the data controller for their store and customer data. CreditKit acts as a data processor / service provider, handling that data only to provide the App’s functionality and only under the Merchant’s instructions (as configured within the App). We do not decide why customer data is collected in the first place — that determination, and the legal basis for it, belongs to the Merchant. Questions about a specific credit, refund, or return a Merchant issued should go to that Merchant directly; questions about how the App itself handles data can be sent to us at the contact below.

Information we access

When a Merchant installs the App, Shopify grants us access to the following categories of data, strictly limited to what each part of the App needs to function:

We only ever request the specific Shopify API access scopes needed for the features above, and Shopify requires the Merchant’s explicit consent before granting any of them.

What we don’t do

How we use this information

Access to the data above is used exclusively to operate the features a Merchant enables: issuing and managing store credit, automating refund-to-credit, running scheduled credit campaigns, processing B2B wholesale returns, and generating the audit log and financial reports the App displays back to the Merchant.

Where data is stored and processed

The App’s infrastructure (application hosting and database) is provided by third-party infrastructure providers and may be located in a country other than the Merchant’s or their customers’. By using the App, the Merchant acknowledges that data may be transferred to, stored in, and processed in such countries. We select infrastructure providers that maintain industry-standard security and confidentiality obligations, and we do not share the underlying data with those providers for any purpose beyond hosting it on our behalf.

Security

Data in transit between the App, Shopify, and our infrastructure is encrypted (HTTPS/TLS). Access to production systems is limited to what’s needed to operate and support the App. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard steps to protect the data we process.

Data retention

While a Merchant’s store is actively installed, we retain the records needed to operate the App and preserve an accurate, append-only audit trail of every credit and debit for the Merchant’s own accounting purposes.

We honor Shopify’s mandatory privacy webhooks: on a customers/redact request, we anonymize the corresponding customer-identifying fields in our records (dollar amounts and dates are kept for the Merchant’s accounting integrity, since removing them would corrupt their own financial history). On a shop/redact request — which Shopify sends roughly 48 hours after an app is uninstalled — we delete all of that store’s data from our systems.

Your rights

Depending on where a customer is located, applicable law (such as the EU/UK GDPR or U.S. state privacy laws) may give them rights to access, correct, delete, or restrict the use of their personal data. Because we act as a processor on the Merchant’s behalf, these requests should generally be directed to the Merchant (the store the customer purchased from) in the first instance, since they control the underlying customer relationship. We assist Merchants in fulfilling such requests and will honor any request Shopify routes to us directly through its mandatory privacy webhooks.

Children’s privacy

The App is a business tool for merchants and is not directed at children. We do not knowingly collect personal data from children.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to the App or applicable law. The "Last updated" date above reflects the most recent revision. Material changes will be reflected here; continued use of the App after a change constitutes acceptance of the updated policy.

Contact us

Questions or concerns about this Privacy Policy or how the App handles data can be sent to admin@peerware.site.