LEGAL · PRIVACY
Privacy Policy
This Privacy Policy explains how ClaimCheck (“ClaimCheck,” “we,” “us,” or “our”), located in Maryland, handles information when a Shopify merchant installs or uses the ClaimCheck application, visits tryclaimcheck.com, or contacts us.
1. Scope and roles
This policy applies to the ClaimCheck Shopify application and marketing website. For merchant-directed ticket and customer information, the Shopify merchant is generally the controller or business and ClaimCheck acts as its processor or service provider. ClaimCheck is the controller or business for information used to operate its own account, security, support, and internal product analytics. Exact roles depend on applicable law and the merchant’s use.
2. Information we process
Store and authorization information
We process the Shopify shop domain, installation and authorization information, granted access scopes, Shopify session information, staff or user context made available by Shopify, and store or location identifiers needed to authenticate and operate the app.
Service-ticket information
At a merchant’s direction, ClaimCheck processes ticket numbers, one free-text item description per ticket, service type, notes, optional due date, fixed status, Shopify location, timestamps, and related operational identifiers.
Customer and order references
A ticket may include a reference to a Shopify customer and customer details presented by Shopify for the workflow. ClaimCheck may process linked Shopify order identifiers and stored deposit and balance-payment amounts to display ticket payment progress. A customer and a sale are optional.
Internal product analytics and technical data
We may collect restricted, operator-only events about app use, such as feature events, route or surface, shop identity, timestamps, and diagnostic metadata. The implemented analytics design is not intended to include ticket descriptions or customer personal information. These analytics are for ClaimCheck’s internal product operation and are not merchant reporting.
Website and support information
Our hosting infrastructure may receive ordinary request data such as IP address, user agent, requested page, referring page, and timestamps. If you use a contact or support form, we process the name, email address, optional Shopify store domain, selected topic, message, and other information you choose to provide so we can review and respond.
Formspree
ClaimCheck uses Formspree to receive website contact and support form submissions. Form submissions are transmitted to and processed by Formspree in the United States on our behalf. Do not include passwords, payment-card details, or other unnecessary sensitive information in a message.
Google Analytics
If you choose “Allow analytics,” the ClaimCheck website loads Google Analytics 4 to help us understand page visits and website use. Google may process device, browser, approximate location, referral, page, interaction, cookie, and online identifier information according to its terms and policies. Google Signals, advertising storage, ad user data, and ad personalization remain disabled in our implementation. Rejecting optional analytics prevents the Google Analytics tag from loading on subsequent pages.
3. Where information is stored
Service-ticket records are stored in Shopify app-owned metaobjects. ClaimCheck does not maintain a duplicate PostgreSQL ticket database. Separate PostgreSQL storage is used for Shopify app sessions and restricted internal product-analytics events. Information linked from a ticket—such as a customer or order—continues to be held within Shopify’s systems under the merchant’s Shopify account.
4. How we use information
- Provide and secure the Shopify POS and Admin service-ticket workflows.
- Create, find, filter, display, edit, and update tickets at a merchant’s direction.
- Link optional Shopify customers, locations, deposit orders, and later balance-payment orders.
- Authenticate installations, maintain sessions, prevent abuse, troubleshoot, and support merchants.
- Understand product operation and improve ClaimCheck using restricted internal analytics.
- Comply with law and protect the rights, safety, and security of merchants, customers, ClaimCheck, and others.
5. Legal bases
Where the GDPR, UK GDPR, or similar laws apply, our legal bases may include performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where legally required. Merchants are responsible for establishing an appropriate legal basis and providing required notices for the customer information they direct ClaimCheck to process.
6. Sharing and service providers
We disclose information only as needed to provide the service, comply with law, or protect rights. We may also disclose information to professional advisers, authorities where legally required, or in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
ClaimCheck currently relies on the following providers:
- Shopify — commerce platform, app installation and authentication, Shopify POS and Admin integration, ticket metaobject storage, customer and order references, locations, and managed app billing. Shopify may process merchant, staff, customer, order, and ticket information as needed to provide its platform.
- Vercel — hosting and delivery of the ClaimCheck application at app.tryclaimcheck.com. Vercel may process application traffic, IP addresses, request logs, diagnostic data, and application data transmitted through its infrastructure.
- Supabase — managed PostgreSQL infrastructure used to store Shopify application sessions and restricted internal product-analytics events. Ticket descriptions and customer personal information are not intended to be stored in this database.
- Netlify — hosting and delivery of tryclaimcheck.com. Netlify may process website traffic, IP addresses, request logs, and diagnostic data.
- Formspree — processing and delivery of contact and support form submissions, including the information a visitor enters in a form.
- Google Analytics — optional website measurement after a visitor grants consent. Google processes pseudonymous website usage, device, browser, referral, and approximate-location information. Advertising features are disabled.
Providers may use their own infrastructure vendors and may process information in the United States and other countries under their published terms and data-protection commitments. We will update this list when providers that materially process personal information are added or replaced.
7. Shopify privacy requests and webhooks
ClaimCheck implements Shopify’s mandatory privacy webhook flows for customer data requests, customer redaction, and shop redaction. When Shopify sends a valid request, ClaimCheck can locate relevant customer references and personal details in affected ticket records, anonymize or remove those fields where required, remove shop session data on uninstall or redaction, and process associated internal records in accordance with this policy.
Because ticket data is stored in Shopify app-owned metaobjects, deletion and retention outcomes may depend on Shopify platform behavior, the request type, legal obligations, and technical access available after uninstall. Merchants should not treat ClaimCheck as their sole record-retention or deletion system.
8. Retention and deletion
We retain information only as long as reasonably necessary to provide and secure ClaimCheck, fulfill the purposes described in this policy, meet contractual and legal obligations, and resolve disputes. Ticket records remain subject to the merchant’s Shopify account and applicable Shopify deletion processes. Application session records are removed when they are no longer needed, including through applicable uninstall or shop-redaction handling. Contact and support records are retained as needed to respond, maintain business records, and meet legal obligations. Internal analytics, infrastructure logs, backups, and optional Google Analytics data are retained according to operational need and the retention controls available from the applicable provider, then deleted or de-identified.
9. Security
We use administrative, technical, and organizational measures intended to protect information, including Shopify authentication, access controls, security headers, validation of Shopify requests and webhooks, and restricted access to internal analytics. No service can guarantee absolute security.
10. International transfers
ClaimCheck is located in Maryland, United States. ClaimCheck and its providers may process information in the United States and other countries, which may have different data-protection laws than the country where a merchant or customer is located. Where applicable law requires a transfer safeguard, we rely on the provider’s applicable contractual commitments, including standard contractual clauses or another legally recognized transfer mechanism.
11. Rights and choices
Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing, to request portability, or to complain to a regulator. Customers should normally direct requests to the Shopify merchant that collected their information. Merchants and other individuals may submit privacy questions or verified requests through our contact form. We may need to verify identity and authority before responding.
You can accept or reject optional website analytics in the consent notice. We store that choice in your browser for up to 12 months and may ask again after it expires or our consent practices materially change. After making a choice, use “Privacy choices” in the site footer to review it. If your browser sends a Global Privacy Control signal, ClaimCheck treats it as a request to keep optional website analytics disabled. You may also clear this site’s local storage through your browser.
12. Children
ClaimCheck is a business application and is not directed to children. Merchants are responsible for ensuring that their use of customer information complies with laws applicable to minors.
13. Changes
We may update this policy as ClaimCheck, our providers, or legal requirements change. We will post the updated date and provide any additional notice required by law.
14. Contact
For privacy questions, rights requests, or other data-protection matters, contact ClaimCheck through our contact form. Please choose the privacy topic and include enough information for us to understand and verify the request. Do not submit passwords or payment-card details.