ConsentDock

Privacy policy

This policy explains what ConsentDock processes when a merchant installs and uses the app, why the data is needed, and how it is retained or deleted.

Effective July 16, 2026

Scope

ConsentDock is a Shopify app for configuring buyer acknowledgement rules, enforcing required responses, and retaining order-level evidence. This policy applies to data processed through the app and its Shopify extensions.

Data we process

  • Merchant and installation data, including shop domain, Shopify session information, granted scopes, locale, and subscription status.
  • Configuration data, including consent rules, messages, product references, app settings, and synchronization preferences.
  • Order evidence, including Shopify order identifiers, timestamps, customer or company identifiers when present, rule snapshots, acknowledgement status, and buyer-provided responses.
  • The minimum order context needed to evaluate a rule, such as product references, order subtotal, and delivery country code.
  • Operational data, including webhook receipts, synchronization status, audit records, and application errors.

How data is used

  • Authenticate merchants and operate the embedded app.
  • Match and publish merchant-configured consent rules.
  • Validate that required acknowledgements are present.
  • Create, display, export, and synchronize order evidence.
  • Provide billing entitlements, security, and troubleshooting.
  • Respond to Shopify privacy and deletion requests.

ConsentDock does not sell personal data or use buyer responses for advertising.

Service providers and disclosures

ConsentDock uses Shopify to provide installation, authentication, billing, storefront, checkout, order, and webhook services. The app is hosted on Google Cloud infrastructure. Data is disclosed only as needed to operate those services, comply with law, protect the app, or follow a merchant-configured export destination.

If a merchant enables Pro webhook export, evidence is sent to the endpoint selected by that merchant. The merchant is responsible for the destination and its handling of exported data.

Retention and deletion

Evidence retention is set when a record is created: 30 days on Essential, 180 days on Growth, and 730 days on Pro. A later plan change does not shorten an existing record's stored deadline. Expired evidence can be removed through the app's retention cleanup process.

ConsentDock processes Shopify's mandatory customer data request, customer redaction, and shop redaction webhooks. Customer-linked evidence is deleted when a valid customer redaction request is received. Shop data is deleted following Shopify's shop redaction process.

Security

ConsentDock uses access controls, encrypted transport, managed secrets, tenant-scoped database access, webhook signature verification, and audit records to protect app data. No method of storage or transmission is completely risk free.

Your choices and requests

Merchants control rule content, synchronization settings, exports, API credentials, and retention cleanup. Buyers can submit privacy requests through the merchant that collected their information. Shopify then forwards applicable requests to ConsentDock through its privacy webhooks.

Contact and changes

For support or privacy questions, use the ConsentDock support contact shown on its Shopify App Store listing. This policy may be updated when the app or its legal obligations change. The effective date above identifies the current version.