Checkout AI: B2B Discounts

Privacy Policy

Effective July 10, 2026 · Smith Crafts LLC

Checkout AI: B2B Discounts (the “App”) is a Shopify app provided by Smith Crafts LLC (“we”, “us”). This policy explains what data the App accesses, why, and how we handle it. The App is an admin tool for authoring automatic B2B product, order, and shipping discounts that run inside Shopify’s Discount Function runtime. We do not inject scripts or trackers into your storefront, and we do not store your customers’ names, postal addresses, email addresses, phone numbers, IP addresses, order contents, or payment details.

Scopes we request

The App requests the following Admin API access scopes at install and never asks for more than what is required to run today’s features:

The App does not request read_customers, read_companies, read_orders, read_all_orders, write_customers, or any Protected Customer Data (PCD) approval. The Discount Function evaluates customer-tag membership and native B2B purchasingCompany context scope-free inside Shopify’s checkout Function runtime; the App itself never fetches, stores, or transmits customer or company records through the Admin API. Order-level webhooks are not subscribed to.

Protected Customer Data (PCD) posture — Level 0

The App does not retrieve Shopify Customer records through the Admin API or the Customer Account API. Its Shopify-hosted Discount Function evaluates only yes/no membership in the merchant-specified customer tags and optional B2B buyer context during checkout. Smith Crafts LLC does not receive or store customer IDs, names, addresses, email addresses, phone numbers, or the raw Function input, and no customer data is sent to Anthropic. Merchant-entered Shopify Company or Company Location GIDs may be stored as discount-rule configuration; the App does not fetch or persist company contact records. Because no Protected Customer Data fields are read through the Admin, the App requests PCD Level 0 — no protected-customer-data approval — while remaining subscribed to the mandatory Shopify privacy compliance webhooks below.

Webhooks we subscribe to

The App does not subscribe to orders/create, orders/updated, or any other order-, customer-, or checkout-event topic. No order or checkout data is delivered to our servers at runtime.

What we store

What we do not do

Sub-processors

How data is protected

Data retention & deletion

We retain installation, session, discount-program, activation, alert, AI-draft, AI-usage, support-submission, review-prompt, and instrumentation records while the App is installed. When you uninstall, Shopify sends the App’s app/uninstalled webhook and we immediately delete the shop’s Session rows (including the merchant-staff fields listed above). About 48 hours later Shopify sends the mandatory shop/redact webhook; at that point the App deletes every remaining record for the shop across all enumerated tables above. The privacy-webhook audit log retains only the hashed shop identifier and outcome once records for the shop have been purged.

When Shopify sends a customers/redact webhook, the App acknowledges it and confirms that no customer-scoped records exist to delete — the App does not store data keyed to individual customers. A hashed audit row is written to prove the request was received and processed.

When Shopify sends a customers/data_request webhook, the App acknowledges it and responds that the App holds no personal data about the identified customer. Because the App never stores customer names, addresses, emails, phone numbers, IP addresses, or order contents, that response contains no personal-data inventory. Merchants may also email us at the address below to request deletion or a copy of the data we hold for the shop.

Your rights

Depending on your jurisdiction (including the EU/UK GDPR and the California CCPA/CPRA), you may have rights to access, correct, port, or delete data we hold that relates to you. Merchants can exercise these rights via the Shopify privacy webhooks described above or by emailing [email protected]. We respond within the timeframes required by applicable law. End customers of a merchant’s store should direct requests to the merchant, who is the data controller for their store’s customer data; we act as a processor on the merchant’s behalf.

International transfers

The App is operated from the United States. If you access it from elsewhere, your data may be transferred to and processed in the U.S. under the safeguards required by applicable law.

Changes

We may update this policy; material changes will be reflected by the effective date above and, where features that change data handling are added, in a same-release update. Continued use of the App after an update constitutes acceptance of the revised policy.

Contact

Smith Crafts LLC · Data-protection contact: [email protected].