← Optimmerce

Remote Shipping Zones Rules Privacy Policy

Last updated: 14 August 2026

This Privacy Policy explains what data the Remote Shipping Zones Rules Shopify app ("the App", "we") collects, why, and how it's handled. The App is built and operated by Optimmerce ("we", "us").

What the App does

The App lets merchants define rules for remote or hard-to-serve ZIP/postal codes (for example, Alaska, Hawaii, and other remote regions) and either block checkout delivery to those addresses or flag them for review. Rules are configured by the merchant and applied automatically at checkout through Shopify's own checkout infrastructure.

Who this applies to

This policy covers data collected from merchants who install the App, and explains how customer (shopper) checkout data is handled when the App's rules are applied.

Data we collect

Shop access token

When a merchant installs the App, Shopify issues us an offline access token for that store, which we store so the app continues to function without the merchant re-authenticating on every visit. This token is tied to the store, not to any individual staff member. The App does not request "online" (per-user) access, so we never receive or store the name, email, or other details of the person who installed it.

Rule configuration

The ZIP/postal code rules a merchant creates (which codes or regions are covered, and whether matching addresses are blocked or flagged) are written to metafields on that merchant's own Shopify store via the Shopify Admin API. This is Shopify-hosted data belonging to the merchant, not a separate copy held by us. We read and write it to power the app's admin screens and to supply the rules a Shopify Function uses at checkout.

Billing information

Subscription plan selection is handled entirely by Shopify's own hosted billing pages. We never see or store payment details. Shopify manages that relationship directly with the merchant.

How customer checkout data is handled

Rule matching happens inside a Shopify Function that runs as part of Shopify's own checkout process. At checkout, the function reads the cart's delivery address (including its ZIP/postal code) directly within Shopify's infrastructure, compares it against the merchant's configured rules, and blocks or flags the delivery option accordingly.

Because this evaluation happens inside Shopify's checkout, the customer's address is not sent to or stored on our servers. We do not receive, log, or retain any shopper name, email, address, ZIP code, or order details as part of this process.

Mandatory privacy webhooks

As required by Shopify for all public apps, the App implements the customers/data_request, customers/redact, and shop/redact webhooks. Because the App never stores customer data, the first two are no-ops. shop/redact deletes the store's access token from our database.

Data retention

The shop access token and rule configuration are retained for as long as the app remains installed, and deleted (or, for rule configuration, left in the merchant's own store) when the merchant uninstalls the app, with the access token removed immediately on request via shop/redact.

Subprocessors / where data lives

The App's application code runs on Fly.io, and the shop access token described above is stored in a Supabase-hosted PostgreSQL database. Neither provider is given access to your store's product, order, or customer data. They are only given the offline access token needed to authenticate this app's own requests to the Shopify Admin API.

Your rights

Merchants can request deletion of their store's data at any time by uninstalling the app, or by contacting us at the email below. If you believe any personal data about you has been collected in error, contact us and we'll investigate and correct or delete it promptly.

Contact

Questions about this policy or your data: hello@optimmercehq.com

Changes to this policy

We'll update the "last updated" date above if this policy changes, and post the updated version at this same location.