Privacy Policy
Effective 17 September 2026
This policy describes how SRH Web Agency (“we”, “us”, “Quick Sticky ATC”) handles information when merchants install and use the Shopify app Quick Sticky Add to Cart Bar (a sticky add to cart bar and Theme App Extension). It is written for Shopify’s App Store listing and for merchants who need to know what the app accesses on their shop.
Quick Sticky Add to Cart Bar is a merchant tool. Shoppers on a merchant’s storefront may see the sticky bar; they do not create a Quick Sticky ATC account.
1. Who is responsible
SRH Web Agency operates Quick Sticky Add to Cart Bar and the production app at https://stickycart.srhwebagency.com. Shopify remains responsible for the merchant’s store, Admin, and Checkout. Merchants remain responsible for their own storefront privacy notices to shoppers.
2. Shopify permissions we request
Quick Sticky Add to Cart Bar uses the Shopify Admin GraphQL API only (not the REST Admin API). After install, the app requests these access scopes:
read_products— product titles, images, variants, prices, tags, and related catalog fields used in the admin product picker and display rules. Current requested scopes:read_products.
Quick Sticky Add to Cart Bar does not request read_customers, read_orders, read_checkouts, or similar customer-profile scopes. We do not read customer names, emails, addresses, payment methods, or order history from Shopify.
3. Merchant data we store
All application data is scoped to the installing shop (multi-tenant). We store:
- Shop identity and sessions. Shop domain, install time, plan label (free / premium / advanced), whether the shop is a Shopify development store, and OAuth session records (offline access token and, for online sessions, staff first name, last name, email, and user id as provided by Shopify’s session storage). Billing subscriptions themselves are stored by Shopify.
- App configuration. Display options you save (When to show, mobile and desktop layout, colors, button label, display rules, selected products) as app-owned metafields on the shop’s app installation. This is merchant configuration, not shopper personal data.
- Sticky bar analytics. Aggregated daily counts of impressions, clicks, and sticky-attributed add-to-cart events (with estimated revenue from the variant price).
- Support messages. If a merchant uses Contact in the admin, we receive the name, email, and message they submit and send it to our support inbox over SMTP when email is configured.
- Compliance audit. Non-PII webhook identifiers and topics for GDPR compliance requests (ComplianceRequest). Raw webhook bodies are not stored.
4. Shopper (customer) data
Quick Sticky Add to Cart Bar does not create shopper accounts and does not store Shopify customer profiles. The sticky bar runs in the merchant’s Shopify theme. Add to cart uses Shopify’s cart Ajax on the shop domain.
Storefront analytics beacons send only an event type (impression, click, or attributed add-to-cart) and an optional variant price in cents. They do not include shopper names, emails, IP addresses, cart contents, or a visitor id. We do not write a Quick Sticky ATC cookie or localStorage identifier for analytics uniqueness.
If a future product feature stores customer PII, this policy and the GDPR webhook handlers will be updated in the same change.
5. How we use this data
- Provide the sticky add to cart bar on the theme.
- Show merchants their bar settings and analytics in Admin.
- Respond to uninstall and mandatory compliance webhooks.
- Deliver merchant support messages when Contact is configured.
We do not sell personal data. We do not use shopper data for advertising networks. We do not train third-party AI models on merchant settings or analytics counts.
6. Where data is stored
- PostgreSQL (Supabase) — primary store for sessions, Shop tenant rows, analytics rollups, optional queue jobs, and compliance audit rows. Local development may use SQLite.
- Shopify — OAuth and the merchant’s bar settings metafield remain on Shopify. Product data shown in the picker is read from Shopify, not copied into a second catalog.
- Hostinger (Node.js) — the app process.
- Email — if the merchant submits Contact, the message is sent to our support inbox over SMTP. Reply-To is the merchant’s email.
Access tokens are stored in the shop’s session row. They are used only to call Shopify Admin GraphQL for that shop.
7. GDPR and Shopify mandatory webhooks
Quick Sticky Add to Cart Bar implements Shopify’s mandatory compliance webhooks. Shopify authenticates each request before we process it.
customers/data_request— Shopify asks us to provide data we hold about a customer. We do not store Shopify customer profiles. We log the request (shop domain, Shopify webhook request id, topic, timestamp, and status — never the raw customer body) and respond that we do not hold customer personally identifiable information from the Customers API.customers/redact— Shopify asks us to delete customer personal data. We do not store customer profiles. We record a non-PII audit row and return HTTP 200.shop/redact— after uninstall (typically within 48 hours), we purge shop Session, Shop tenant data, shop-scoped queue jobs, and sticky analytics. If that purge fails we return an error so Shopify retries.app/uninstalled— we run the same cleanup when the merchant uninstalls, without waiting forshop/redact.
Compliance webhook receipts are stored in a separate audit table keyed by shop domain (not a foreign key to the shop). That audit trail is kept after tenant data is purged. The row stores only shop domain, request id, topic, status, and timestamp.
8. Data retention
- While the app is installed: sessions, Shop row, metafield settings, and analytics rollups are kept so the bar and admin work.
- After uninstall: we delete sessions, Shop tenant data, queue jobs for that shop, and sticky analytics.
- Shop redact: the same deletion path runs if tenant data is still present when Shopify sends
shop/redact. - Compliance audit logs: retained after purge for legal and App Store compliance evidence.
- Support email: if a merchant contacts us, copies may remain in our support inbox.
9. Cookies and similar technology
The embedded admin uses Shopify’s session cookies to keep the merchant logged in. The storefront Theme App Extension does not set a Quick Sticky ATC cookie and does not write an analytics visitor id to localStorage.
10. International transfers
The app process is hosted on Hostinger (Node.js). PostgreSQL is hosted on Supabase. Shopify remains the merchant’s store, Admin, and Files host. If a merchant or shopper is in the EEA, UK, or another region, data described above may be processed in the US to provide the app. Shopify also processes data under the merchant’s Shopify agreement.
11. Your choices and requests
Merchants can:
- Uninstall Quick Sticky Add to Cart Bar, which starts deletion of shop-scoped data.
- Use Shopify Admin → Apps to review permissions, or Shopify’s customer data request / redaction tools (those trigger the webhooks above).
- Contact us using Quick Sticky ATC → Contact in the app, or email sohilhunani11@gmail.com.
Shoppers should contact the merchant first. The merchant can use Shopify’s customer privacy tools; we will receive the corresponding webhook.
12. Children
Quick Sticky Add to Cart Bar is a B2B Shopify app. We do not knowingly collect personal information from children. Analytics counts come from the merchant’s storefront widget, not from child accounts we create.
13. Changes
We will update this page when our data practices or Shopify requirements change. The effective date at the top will change. The current version is always at this URL. Scopes stay least privilege; if scopes are added, this policy is updated in the same change.
14. Contact
SRH Web Agency — Quick Sticky Add to Cart Bar
Email: sohilhunani11@gmail.com
In-app: Quick Sticky ATC → Contact
App origin: https://stickycart.srhwebagency.com