Last updated: 2 July 2026. Applies to the Order Tag Automator Shopify app.
Order Tag Automator reads a small amount of order data from your Shopify store so it can apply the tagging rules you configure, and writes those tags back to the matching orders in your store. It does not store personal customer data outside your Shopify store, it does not sell or share your data, and it contains no advertising or cross-site tracking.
To evaluate your tagging rules against an order, the app reads the following fields from each order:
These fields are read only to decide which tags apply. The app does not read or retain customer names, email addresses, phone numbers, full shipping addresses, or line-item product details beyond what is described above.
The order data listed above is used solely to evaluate the tagging rules you have set up and to apply the resulting tags to the corresponding orders in your Shopify store. It is not used for any other purpose, is not used to build customer profiles, and is not used for marketing.
The app stores your store configuration — your tagging rules and the app's own session credentials for your store — in the app's database, so it can run your rules. It does not keep a copy of your customers' personal data outside your Shopify store. The order fields it reads are processed to compute and write the tags; the resulting tags live on the orders inside your own Shopify store, which remains the system of record.
The app does not sell, rent, or share your data with third parties for their own purposes. Data is exchanged only with Shopify, via Shopify's official APIs, in order to read orders and write tags to your store.
Store configuration is retained only while the app is installed. When you uninstall the app, or on request, the app's stored configuration and session credentials for your store are deleted. The app also honours Shopify's mandatory GDPR webhooks:
customers/data_request — responds to a customer's request to view their data;customers/redact — deletes any data the app holds about a specific customer;shop/redact — deletes the store's data after the app is uninstalled.Because the app does not retain customer personal data outside your Shopify store, redaction requests are satisfied by removing any store-level configuration the app holds.
If you are located in the European Economic Area, you have the right to access, rectify, or erase the personal data an organisation holds about you, to restrict or object to its processing, and to data portability. As the app processes order data on behalf of the merchant (the store owner, who is the data controller), requests about a specific order should be directed to the store you purchased from. Merchants can exercise the app-level rights above by contacting us or uninstalling the app.
Communication with Shopify uses encrypted HTTPS connections, and the app authenticates to your store using Shopify's OAuth session tokens rather than storing your Shopify password.
If this policy changes, the updated version will be published on this page with a new "last updated" date.
Questions about this policy: info@getcompliant.online.