Privacy Policy
1. Introduction
RabbitROI ("we", "our", "us") is a Shopify application that provides a customizable Cash on Delivery (COD) checkout form, order and profit analytics, fulfillment tracking, and advertising attribution for Meta and TikTok. This policy explains what data we collect, why we collect it, and how it's handled — for both the merchants who install the app and the customers who submit orders through it.
RabbitROI is operated by Areez Mahmood, sole proprietor, trading as RabbitROI, who is the data controller responsible for the data described in this policy.
By installing or using RabbitROI, you agree to the practices described here.
2. Data We Collect From Your Store
To operate the app's features, we access the following via the Shopify Admin API:
- Orders, draft orders, and fulfillments — to build analytics (expected revenue, cash collections, net profit, return rate) and to track which orders are fulfilled, in transit, or unfulfilled.
- Products and variants — to display product details in the COD form builder's live preview and to fetch real-time pricing when a customer submits an order.
- Theme files (read-only) — specifically your active theme's
config/settings_data.json, so the "Auto" color option in the Form Builder can match the COD form to your store's own color scheme. - Shop details — domain, currency, and access token, to maintain your authenticated session and route requests to the right store.
- UTM parameters on orders — for campaign attribution when reporting on ad performance.
3. Data Collected From Your Customers
When a customer submits the COD form on your storefront, we process the fields your form is configured to collect — typically name, phone number, delivery address, city, and any order notes — solely to create a real Shopify order on your behalf via the draftOrderCreate / draftOrderComplete APIs, marked with a pending/unpaid financial status appropriate for Cash on Delivery.
This customer data is used only to fulfill that specific order. It is never sold, shared with advertisers, or used for any purpose beyond order creation and the fulfillment/analytics features described above.
4. How We Use Data
- Render and operate the COD form on your storefront (via a storefront script).
- Create real Shopify orders from COD form submissions.
- Compute analytics dashboards: revenue, cash collections, profit, returns.
- Track fulfillment status and surface orders that may need attention.
- Match the COD form's "Auto" colors to your theme.
- Report ad performance when you connect Meta or TikTok ad accounts (see Section 8).
- Diagnose technical issues and maintain the reliability of the app.
We do not sell, rent, or share your store's or customers' data with third parties for marketing purposes.
5. Data Storage and Security
Data is stored on Amazon Web Services (AWS) infrastructure in the ap-south-1 (Mumbai) region, behind services that enforce:
- Encrypted connections (HTTPS/TLS) for all data in transit.
- Encrypted storage for databases at rest.
- Access limited to the infrastructure and personnel required to operate the app.
AWS is our only data processor. Content delivery and certificate services run from AWS's us-east-1 (United States) region, so data may be processed in India and the United States. No other vendor, contractor, or affiliate has access to your data.
6. Data Retention
We retain your store's data for as long as RabbitROI remains installed. Upon uninstallation, your store's data is deleted within 30 days, except where retention is required to comply with a legal obligation.
7. Third-Party Services
We rely on the following third parties to operate the app:
- Shopify — for authentication, order creation, and store data access.
- Amazon Web Services (AWS) — for hosting and data storage.
- Meta (Facebook) Marketing API — only if you connect a Meta ad account, to read campaign and ad-account identifiers for attribution reporting.
- TikTok Marketing API — only if you connect a TikTok ad account, for the same attribution purpose.
Each provider is governed by its own privacy policy in addition to this one.
8. Meta and TikTok Ad Integrations
Connecting a Meta or TikTok ad account is optional. If connected, we access campaign and ad-account identifiers and performance metrics needed to attribute COD orders back to the ad campaigns that drove them. We do not post on your behalf, and we do not access personal profile data beyond what each platform's ads API exposes for account and campaign identification.
Access is read-only. On Meta we request the ads_read permission only — never ads_management — and the app cannot create, edit, pause, or delete campaigns, ad sets, ads, audiences, budgets, or creatives, and does not manage Business Manager assets. We read only the ad accounts you select during the connection flow, and only daily spend and performance figures for them. Ad-platform data is used solely to render your own reporting inside your Shopify admin: it is never sold, never shared with other merchants, never used to build cross-merchant profiles, and never used to attempt re-identification of aggregated or de-identified information. Access tokens are stored server-side, scoped to the single store that authorized them, never exposed to the browser, and deleted when you disconnect the ad account or uninstall the app.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access or export the data we hold about your store.
- Request deletion of your store's data.
- Withdraw consent at any time by uninstalling the app.
To exercise these rights, contact us at areezmahmood7@gmail.com.
10. Government and Law Enforcement Requests
We have received no national security requests and no government requests for user data to date.
If we receive a request from any public authority for merchant or customer data, we will:
- Review its legality and require valid legal process before disclosing anything.
- Challenge or refuse requests that are unlawful, overbroad, or improperly served.
- Disclose only the minimum data strictly required by the request, never a full account or dataset.
- Record the request, our legal reasoning, our response, and everyone involved.
Where we are not legally prohibited from doing so, we will notify the affected merchant before disclosing their data.
11. Children's Privacy
RabbitROI is intended for use by Shopify merchants operating businesses. We do not knowingly collect data from individuals under 13 years of age.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the app after a change constitutes acceptance of the revised policy.
13. Contact Us
Questions about this policy? Email areezmahmood7@gmail.com.