What Checkout Guard processes, why it is processed, who processes it, and how long it is kept.
August 26, 2026
Checkout Guard is a Shopify app operated by Parkdale Digital. It helps merchants require shoppers to acknowledge terms and conditions during Shopify checkout.
This policy explains the app's current data practices and is published at parkdale.digital/policies/privacy-policy. It is product privacy documentation, not legal advice. Merchants should review their own legal obligations and customer-facing disclosures.
We process the shop identifier or domain, installed or uninstalled state, a snapshot of the Shopify app scopes granted to Checkout Guard, and installation, uninstall, and update timestamps.
Where Shopify provides it, we process staff first and last name, email address, locale, account-owner and collaborator status, email-verification status, Shopify user ID, session state, online and offline session metadata, access tokens, refresh tokens, token expiry values, and granted scopes. This information authenticates authorized users and lets the app operate within the permissions granted through Shopify.
We process policy names and contents, policy versions and hashes, active policy pointers, validation configuration, and checkout placement settings. Policy versions are immutable so acknowledgement evidence can be associated with the policy presented at the relevant time.
When the workflow is enabled, we process signed acknowledgement metadata written to Shopify cart or order app metafields. This includes the policy version, policy hash, acceptance state, order ID, customer ID when available, order creation timestamp, and schema version. We also write minimal derived customer acknowledgement snapshots to Shopify customer app metafields.
Webhook and audit records may include event type, subject identifiers, idempotency keys, processing timestamps, and related metadata used for deduplication and processing evidence.
For Shopify customer data requests and merchant-scoped privacy workflows, we process the shop domain, customer ID, order IDs, request status, generated export JSON, export filename, export hash, byte length, fulfillment or failure details, error reason when applicable, and timestamps.
Where present, we process shop subscription snapshot or cache fields for billing reconciliation. We also process health checks, application logs, migration records, database connectivity signals, and webhook audit records needed to operate the service reliably.
We use this data to authenticate merchants and authorized staff, keep app installation state synchronized, and let merchants configure checkout terms-and-conditions policies. The app loads the active policy into the checkout extension and, when enabled by the merchant, blocks checkout progress until the shopper's acknowledgement is captured.
We also use data to verify signed order acknowledgement metadata against the active policy version and hash, store minimal compliance evidence on orders and customers, fulfill Shopify privacy webhooks and merchant-scoped privacy access or export workflows, and maintain webhook deduplication, auditability, health monitoring, billing reconciliation, and operational reliability.
Parkdale Digital operates Checkout Guard. Shopify platform services provide app installation, authentication, checkout, cart, order, customer, webhook, privacy request, billing, and metafield functionality. Railway-hosted Checkout Guard infrastructure hosts the application and database services used to operate the app.
This list is limited to the processors and platform services currently identified for Checkout Guard. It does not describe services independently selected or used by Shopify or an individual merchant.
Shopify session records: Shopify session rows are deleted when the app is uninstalled.
Shop installation records: Installation records are deactivated on uninstall and may remain for operational observability.
Policies and operational records: Policy records, immutable policy versions, validation configuration, webhook audit records, migration records, and billing cache records are retained until operator-managed deletion unless a future retention workflow is implemented.
Customer acknowledgement snapshots: These records are minimal by design and may be overwritten by evidence from a later order.
Shopify metafields: Shopify-hosted cart, order, and customer metafields follow Shopify and merchant lifecycle controls.
Privacy request exports: Compliance data request export artifacts have an intended 30-day retention target after fulfillment or terminal failure. Operator scheduling is configured to run this cleanup.
Not every retained record is automatically deleted. Merchants may contact Parkdale Digital for a deletion review. This policy does not claim that historical data from previously used hosting platforms has been migrated or reprocessed.
Merchants can uninstall Checkout Guard through Shopify to stop its ongoing operation for their shop. Uninstalling deletes Shopify session rows and deactivates the shop installation record, but it does not automatically delete every policy, audit, migration, billing, or observability record described above.
Merchants may contact Parkdale Digital for privacy support, a merchant-scoped data export, review of a deletion request, or assistance with a Shopify privacy request. We may need to verify the requesting merchant and relevant Shopify shop before acting.
Data stored in Shopify-hosted cart, order, and customer metafields is also subject to Shopify's platform controls and the merchant's customer and order lifecycle processes.
Merchants remain responsible for deciding whether Checkout Guard is appropriate for their business, configuring the policies presented to shoppers, and addressing the content and enforceability of their checkout terms.
Each merchant is also responsible for its storefront privacy notices and customer-facing disclosures, responding to customer rights requests that apply to the merchant, and meeting the privacy, consumer-protection, recordkeeping, and other legal obligations applicable to its business.
Checkout Guard provides acknowledgement and evidence-management functionality. It does not provide legal advice or guarantee that a merchant's policies, disclosures, or use of the app satisfy a particular law or regulatory requirement.
For privacy questions, support, merchant-scoped exports, or deletion review requests, contact Parkdale Digital at shawn@parkdale.digital.