Privacy Policy
Last updated: August 24, 2026
Kosonova (“the app”, “we”, “us”) is a Gift With Purchase application for Shopify stores. This policy explains what data we process, why, and for how long, on behalf of the merchants (“you”, the store owner) who install it.
What we process — and what we deliberately don't
The app is built to need as little personal data as possible to work. We never collect, store, or have access to a customer's name, email address, phone number, or shipping/billing address. We do not build customer profiles, and we never sell, rent, or share any data with third parties.
What we do store, tied to your shop:
- Order records (order id, order name, total price, currency, which gift variant(s) were applied and their value, and whether the order used a Gift With Purchase campaign) — used to calculate the analytics you see in the app (attributed revenue, average-order-value comparison, gift redemption counts).
- Campaign configuration you create in the app (spend tiers, chosen gift products) — used to run your Gift With Purchase campaigns.
- Your store's access token (issued by Shopify when you install the app) — used to call the Shopify Admin API on your behalf (e.g. to create the discount that applies the free gift).
We also read and write one metafieldon a customer record in your Shopify store: a single timestamp of when that customer last received a free gift, used to enforce a per-customer cooldown so the same customer can't claim unlimited gifts. This value lives in your Shopify store's own data — not in our database — and contains no other information about the customer.
How long we keep it
Order records are automatically and permanently deleted after 24 months. Campaign configuration is kept only as long as your campaign exists in the app (you can delete a campaign at any time). If you uninstall the app, your store's access token is deleted immediately; order records are deleted on the same 24-month schedule regardless of installation status.
Security
All data in transit is encrypted (HTTPS/TLS). All data at rest is encrypted by our database provider. Every request between your storefront, your store's admin, and our servers is verified using Shopify's own signing mechanisms (HMAC verification), so only genuine, signed requests from Shopify are ever processed.
Your customers' rights (GDPR)
We support Shopify's mandatory customer privacy webhooks:
- Data request— if a customer asks what data we hold about them, we have none to disclose beyond what's described above (no PII is ever stored on our side).
- Customer redaction— if a customer's data must be erased, any order records tied to them are deleted.
- Shop redaction — if your store uninstalls the app and requests full data erasure, all campaign configuration and order records for your shop are deleted.
Changes to this policy
If this policy changes, the “last updated” date above will change too. Material changes will be communicated to installed merchants.
Contact
This app is developed by Théo Guilbert. For any question about this policy or your data, contact: theo@theodatagrowth.com.