Privacy Policy
This policy explains what personal data the Unspent app processes when it is installed on a Shopify store, how and why we process it, who we share it with, how long we keep it, and how it is deleted.
1. Who we are
Unspent is operated by DiLight Entertainment UG (haftungsbeschränkt) ("Unspent", "we", "us"). For questions about this policy or the data we process, contact us at privacy@dilight.website.
When Unspent is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and Unspent acts as a data processor on the merchant's behalf, processing store data only to provide the app's returns, exchange, store-credit and loyalty features. For our own account, billing, security and support records, we act as the controller.
2. Data we process
Unspent turns returns into exchanges and store credit and runs a multi-currency customer wallet (store credit, loyalty points and bonus credit) over an append-only ledger. It reads Shopify data using the merchant's authenticated session and via webhooks, and it persistently stores the returns, exchange and wallet records it creates. The data involved:
- Store & account data — your
.myshopify.comdomain, the OAuth access token issued at install (stored encrypted and never shown in plain text), granted scopes, locations, plan and billing status, and your app configuration (policies, incentives, loyalty earn rules and currency-conversion rules). - Product & inventory data — product and variant details (title, SKU, price, image) and per-location inventory levels, read to validate return eligibility and to recommend in-stock exchanges.
- Order, return & refund data — order and line-item details, quantities, fulfilment status, return requests, reasons, exchange orders and refund records, used to process the return-to-resolution loop and to reconcile issued value.
- Customer data (protected) — the customer's name, email address and shipping address are the protected customer fields we process. Name and email identify the customer in the merchant admin and authenticate them on the self-service returns portal (order number + email); the shipping address is used to create exchange orders and return shipping. We request only these fields and do not request phone numbers or billing addresses.
- Wallet & loyalty data — the append-only ledger of store-credit grants, adjustments, redemptions, expiry, loyalty-points earning and bonus credit, plus derived balances and tier. Cash-equivalent balances are mirrored into Shopify's native Store Credit for checkout redemption, and balances are synced to customer metafields so merchants can build their own storefront widgets.
- Technical & security data — logs, webhook and signed integration requests, rate-limit counters and error diagnostics needed to operate and protect the service.
We do not process or store payment-card details. Access to store data is limited to the Shopify scopes granted
at install: read_products, read_inventory, read_locations,
read_fulfillments, read_customer_merge, write_orders,
write_returns, write_draft_orders, write_customers and
write_store_credit_account_transactions (write scopes include the corresponding read access).
3. How we use data
- Accept and manage return requests, evaluate policy eligibility and route resolutions.
- Recommend and create inventory-validated exchanges.
- Issue, adjust, expire and redeem store credit, loyalty points and bonus credit through an append-only, idempotent ledger, and mirror cash-equivalent credit into Shopify Store Credit for checkout.
- Apply configurable incentives, loyalty earn rules and currency conversion.
- Sync wallet balances and history to customer metafields for merchant-built widgets.
- Operate billing, enforce plan limits, prevent abuse, and provide support.
4. Legal basis (GDPR)
Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing, securing and protecting the service. For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions as their processor.
5. Sharing & sub-processors
We do not sell personal data. We share data only with the providers needed to run the service:
- Shopify — the platform the app is installed on and the source of product, order, customer, inventory and store data, and the holder of native Store Credit balances.
- Our hosting / infrastructure provider — to host the application and its database.
Unspent supports a signed, tenant-pinned app-to-app boundary through which first-party DiLight apps (such as PartnerPilot) may request store credit on a merchant's store. This is authenticated by HMAC signature and is off by default; no customer data is shared outbound through it.
6. Data retention
We keep store data only for as long as needed to provide the service to the merchant. Returns, exchange, wallet
and ledger records are retained while the app is installed so the store's history and balances stay intact, subject
to the merchant-configurable retention period (default 365 days) for operational records. When the app is
uninstalled, or on a Shopify shop/redact request, we purge the store's data as described below.
Aggregated, non-identifying statistics may be kept longer.
7. GDPR / data-deletion requests
Unspent implements Shopify's mandatory compliance webhooks (verified by HMAC signature before any action):
customers/data_request— we record the subject-access request so the merchant (the controller) can fulfil it; the data cannot be returned inline in the webhook response.customers/redact— we anonymize the identified customer's personal data across the store's returns, exchange and wallet records, preserving only non-identifying financial aggregates required for accounting.shop/redact— sent by Shopify roughly 48 hours after uninstall, we purge all of the store's data (configuration, returns, exchanges, ledger, resolutions and cached data) and revoke the stored install.
Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.
8. Protected customer data
Unspent follows Shopify's Protected Customer Data requirements and requests the minimum needed: the customer's name, email and shipping address. We use these only to operate returns, exchanges and the customer wallet, we do not use protected customer data for advertising or profiling, we restrict access to it, and we apply the retention and deletion practices described above.
9. Security
The app uses Shopify's OAuth for install and stores access tokens encrypted at rest. Inbound webhooks are verified with HMAC signatures, App Proxy customer pages are verified with a signed-request check, and the app-to-app integration boundary is verified with its own HMAC, timestamp and tenant checks. Embedded admin requests use Shopify App Bridge session tokens, every record is scoped to the individual store, financial changes are recorded as append-only, idempotent ledger entries, requests are rate-limited, and all traffic is served over TLS.
10. Cookies
The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.
11. International transfers & your rights
Where data is transferred internationally, appropriate safeguards are applied. Subject to applicable law, data subjects have rights of access, correction, export, restriction, objection and deletion. Store customers should normally contact the merchant (the controller); merchants can contact us for assistance in fulfilling requests.
12. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.
13. Contact
DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website