1. Who we are
This policy explains how Dragon Apps (“Dragon Apps”, “we”, “us”, “our”), a business registered in Australia at PO Box 2210, Sunnybank Hills QLD 4109, handles personal data in connection with the Shopify app Request a Quote, Hide Price (the “App”).
Contact us about anything in this policy at [email protected].
2. Our two different roles
This distinction matters, because it determines who you should contact about your data.
We are a processor for shopper data. When a shopper submits a quote request on a merchant's storefront, the merchant is the controller of that data — they decide what to ask for and what to do with it. We only process it on their instructions, to run the App. If you are a shopper and you want your data accessed, corrected or deleted, contact the merchant whose store you used. We will help them respond, and Section 10 explains how.
We are a controller for merchant data. When a merchant installs the App, we control the limited data we hold about them and their staff — their store domain, their settings, and the names and email addresses of the staff they add to receive lead alerts.
3. What personal data we process
Shopper data (we act as processor)
| Data | Where it comes from | Why we have it |
|---|---|---|
| Email address (required) | Typed into the merchant's quote form | Identifies the request and lets the merchant reply; copied to the Shopify draft order |
| Name, phone number, company name (optional) | Typed into the merchant's quote form | Lets the merchant contact the requester |
| Shopify customer ID | Provided by Shopify when the shopper is logged in | Links the request to the shopper's existing customer record |
| Answers to the merchant's own form questions | Typed into the merchant's quote form | The merchant's qualifying questions; content is defined entirely by the merchant |
| Note to the merchant | Typed into the merchant's quote form | Included on the quote PDF |
| Products and quantities requested | Selected on the storefront | The subject of the quote |
We do not read the merchant's customer list, order history, or any other customer records from Shopify. The App holds no customer-read permission on the Shopify Admin API. Apart from the Shopify customer ID above, everything we hold about a shopper is what that shopper typed into the merchant's form themselves.
Merchant data (we act as controller)
| Data | Why we have it |
|---|---|
| Store domain and Shopify access tokens | To authenticate the App to the merchant's store |
| Staff names and email addresses | To send lead alerts to the people the merchant nominates |
| A delivery log of alerts sent (recipient, status, errors) | So merchants can prove no lead was silently dropped |
| Store settings, branding, and quote form definitions | To run the App as configured |
4. Why we process it, and our legal basis
We process shopper data solely to provide the App to the merchant: recording the quote request, alerting the merchant's staff, producing the quote PDF, and creating a Shopify draft order. The legal basis is the merchant's — typically their legitimate interest in responding to a sales enquiry, or steps taken at the shopper's request prior to entering a contract.
We process merchant data on the basis of our contract with the merchant, and our legitimate interest in operating, securing and supporting the App.
5. What we do not do
We want to be specific here, because these are the things apps commonly do that we do not.
- We never sell or rent personal data, and we never share it with anyone for advertising or any other consideration.
- We never email shoppers. The App only ever emails the merchant's own nominated staff. Merchants download the quote PDF and send it themselves.
- We do not track shoppers. The storefront quote form sets no cookies, writes nothing to
localStorageorsessionStorage, and loads no analytics, advertising or fingerprinting scripts of any kind. - We do not use personal data to train machine learning models.
- We do not use personal data for automated decision-making that produces legal or similarly significant effects. The App decides whether to show or hide a price based on the merchant's rules and the shopper's customer tags or login state; this affects what is displayed on a page and nothing more.
- We do not enrich, profile or combine the data with data from other sources.
6. Sub-processors
We use these third parties to run the App. Each is bound by contract to appropriate confidentiality and security obligations.
| Sub-processor | What it does | Data it may see | Location |
|---|---|---|---|
| Shopify Inc. | Hosts the merchant's store; the App runs inside Shopify Admin | All data described above | Canada and United States |
| Railway | Hosts the application and its PostgreSQL database | All data described above | United States |
| Amazon Web Services (SES) | Sends lead alerts and verification emails to merchant staff | Staff email addresses; quote reference and requester name in the alert body | United States |
| Slack Technologies | Delivers lead alerts, only if the merchant enables a Slack webhook | Quote reference and requester details in the alert body | United States |
An up-to-date list is maintained on our sub-processor page. We give at least 30 days' notice before adding or replacing a sub-processor, by email to the address on the merchant's account and by updating that page; merchants can also ask for change notices to be sent to an additional address.
7. International transfers
Personal data may be transferred outside the EEA and the UK to the locations listed above. Where it is, we rely on appropriate safeguards — such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — together with the technical measures described in Section 9.
8. How long we keep it
Quote records are retained for 24 months by default. Merchants can change this in the App's settings, or opt to retain indefinitely.
When the retention period expires, we anonymise rather than delete: the requester's name, email address, phone number, company, form answers and notes are permanently removed from the record, while the quote itself — its number, status, dates and line items — is kept as the merchant's business record. This means the merchant keeps their sales history without keeping personal data longer than needed.
Personal data is also removed, sooner, in each of these cases:
- A merchant deletes a quote. The record and its line items are deleted immediately.
- Shopify sends a customer redaction request. We anonymise every matching quote for that store, as above.
- Shopify sends a shop redaction request, or the merchant uninstalls the App. We delete all data belonging to that store — quotes, line items, staff, forms, display rules, settings, alert logs and access tokens.
9. How we protect it
- Encryption in transit. All connections use TLS: the App is served only over HTTPS, and traffic to Shopify, Amazon SES, Slack and our database is encrypted.
- Encryption at rest. The database is stored on encrypted volumes (AES-256) by our hosting provider.
- Access control. Every request to the App is authenticated with a Shopify session token, and every database query is scoped to the requesting store, so one merchant's data cannot be reached from another's session.
- Minimal permissions. The App requests only the Shopify permissions it needs, and holds no permission to read customer records.
- No personal data in logs. Our application logs record identifiers and counts only — never names, email addresses, phone numbers or form answers.
- Minimal dependencies. The App runs on a deliberately small set of third-party libraries to reduce supply-chain risk.
No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs, we notify affected merchants without undue delay and in any event within 72 hours of becoming aware of it, as set out in our Data Processing Agreement.
10. Your rights
If you are in the EEA, the UK, or another region with comparable law, you have rights to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable form.
If you are a shopper, the merchant whose store you used is the controller of your data — please contact them first. If you contact us directly, we will forward your request to the relevant merchant and assist them in responding. We cannot act on your data without the merchant's instruction, because it is not ours to act on.
If you are a merchant, contact us at [email protected] and we will respond within the period required by applicable law, and in any event within 30 days.
You also have the right to complain to your local data protection authority.
11. Cookies
The App's storefront quote form sets no cookies and uses no browser storage.
The App's admin interface, which merchants use inside Shopify Admin, also relies on no cookies of its own — it authenticates using Shopify session tokens. Shopify itself sets cookies on its own domains; those are governed by Shopify's privacy policy.
12. Children
The App is a business tool for merchants and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted personal data through a merchant's quote form, contact us and we will assist that merchant in removing it.
13. Changes to this policy
We may update this policy. When we make a material change we will update the date at the top and, where the change materially affects merchants, notify them by email or within the App before it takes effect.
14. Contact
Company: Dragon Apps
Registered address: PO Box 2210, Sunnybank Hills QLD 4109, Australia
Email: [email protected]
Website: https://dragonapps.io
See also our Data Processing Agreement and sub-processor list.
For full contact details, visit our contact page.