ThanhBT: Discounts Combine Privacy Policy

ThanhBT: Discounts Combine ("the App") lets a merchant's customers combine multiple discount codes into one order, either through a storefront widget (Basic Combine) or a merchant-configured checkout discount (Combined+). This Privacy Policy describes what data the App accesses and stores when a merchant installs it on a Shopify-supported store, and how that data is used.

Who This Policy Covers

The App is installed and configured by the merchant (store owner/staff). The App does not create accounts for, or knowingly collect personal information directly from, the merchant's end customers. Any data about an order — including discount codes used — is received from Shopify as part of operating the discount-combine feature, not collected directly from the shopper.

Data We Access and Store

When a merchant installs the App, we access and store the following through the Shopify Admin API and Shopify's OAuth flow:

We do not collect or store any personal information about the merchant's customers (no customer ID, name, email, or address is retained in our database). Combine history is recorded at the shop and order level only.

How We Use This Data

We use the data above solely to operate the App's core function — looking up discount codes, calculating combined discounts, creating draft orders, applying Combined+ discounts at checkout, and tracking code usage/limits. We do not use this data for advertising, and we do not sell or rent it to third parties.

Third-Party Sharing

Some operations that require Shopify's GraphQL Admin API (BOGO/automatic discount lookups, discount usage updates, and Combined+ Shopify Function management) are performed by a backend service we operate at thanhbtapp.com. Requests to that service include the relevant shop domain and discount-code data needed to complete the operation — it is part of our own infrastructure, not an independent third party, and is not used for any purpose beyond fulfilling the App's features.

We may also disclose data to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful request, or to protect our rights.

Cookies

The merchant-facing admin UI uses a standard PHP session cookie to keep the merchant logged in to the embedded admin app. This cookie is not used for tracking or advertising, and no advertising or analytics cookies are set by the App.

Data Retention and Deletion

We retain shop configuration and combine history for as long as the App is installed, so the merchant can view their Processed List and settings. When a merchant uninstalls the App, we delete the shop's access token and settings. We also honor Shopify's mandatory shop/redact webhook, which deletes all remaining shop-scoped data (settings, combo codes, combine history, and Combined+ discount records) for that store. Because we do not store customer-identifiable data, Shopify's customers/data_request and customers/redact webhooks have no corresponding records to return or erase.

Your Rights

If you are a merchant using the App, or a European resident, you have the right to ask what data we hold about your store and to request its correction, update, or deletion (including via uninstalling the App, which triggers the deletion described above). If you would like to exercise this right, or have questions about this policy, please contact us using the information below.

Please note that data is processed and stored outside of Europe, including in the United States, on infrastructure operated by Heroku with a PostgreSQL database accessed over an encrypted (SSL/TLS) connection.

Changes

We may update this privacy policy from time to time to reflect changes to our practices or for other operational, legal, or regulatory reasons.

Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at thanhbt001@gmail.com.