This policy covers NASP Rewards, a Shopify app built and maintained by Not A Side Project ("Company", "we", "our", or "us"). It applies to merchants who install the app, people who use our website, and people who contact support.
For shoppers, we process loyalty data on behalf of the merchant who installed the app. That merchant controls its customer data. If you are a shopper with questions about your points or personal data, contact the store you shopped with first.
- What we collect and why
- When we access or disclose information
- Your rights
- How we secure data
- Data retention and uninstall
- Location of data
- Changes and questions
What we collect and why
We collect only what we need to run the product.
Shopify shop and installation
When a merchant installs NASP Rewards, Shopify provides information needed to authenticate the shop and operate the app. This typically includes shop domain, shop identifiers, and session tokens. We store what we need so the app can load in Shopify Admin, verify billing, and process loyalty activity for that shop.
Loyalty program data
To award points and issue store credit, we store program configuration and customer loyalty records for the installing shop, including:
- Earning and redemption rules the merchant configures
- Customer identifiers from Shopify and points balances
- Ledger entries for earns, redemptions, refunds, and adjustments
- Redemption records and status history for store credit issuance
- Order and refund context needed to process points correctly
Billing
Paid plans are billed through Shopify App Pricing. We do not collect or store full credit card numbers. We may store subscription status or related identifiers needed to control access to paid features.
Support correspondence
When you email us, we keep the correspondence, your email address, and any shop details you share so we can respond and understand past context.
Website interactions
We may collect basic technical logs, such as IP address, user agent, and pages requested, to operate and secure the website. We do not sell personal data or build third-party advertising profiles.
When we access or disclose information
To provide the product. We use infrastructure and service providers for hosting, databases, email, DNS, and content delivery. They process data only as needed to provide those services.
Shopify. The app exchanges data with Shopify APIs and webhooks so orders, customers, store credit, billing, and compliance workflows can operate. Shopify's policies also apply to data held there.
Support, with care. A human may inspect shop or loyalty records to resolve a support request, fix an operational error, investigate abuse or security issues, or meet a legal obligation.
Legal process. We may disclose information when required by valid legal process. Where legally allowed, we prefer to notify the affected merchant.
Business transfer. If the Company is acquired or merges with another company, we will notify merchants before personal information becomes subject to a different privacy policy.
We never sell personal information.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing.
- Merchants: emailsupport@notasideproject.comfrom a mailbox associated with the shop, or use Shopify's app uninstall and compliance flows where applicable.
- Shoppers: contact the merchant's store. We also respond to Shopify's mandatory data request and redaction webhooks.
We may need to verify the requester. Some records may be retained where required for security, fraud prevention, accounting, or law.
How we secure data
Data in transit is protected with TLS. Access to production systems is limited. We use practices appropriate to the service, including secret management and restricted infrastructure access. No transmission or storage method is perfectly secure, and we continue working to reduce risk.
Data retention and uninstall
We keep loyalty and shop data while the app is installed and the data is needed to provide the service. When a shop uninstalls, or Shopify sends a shop or customer redaction request, we process deletion or redaction under Shopify's compliance requirements and our operational schedules.
Logs and any backup copies may retain residual data for a limited period after deletion from active systems, then age out.
Location of data
Application infrastructure is operated in locations selected for reliability, currently including servers in Europe. Information may be processed outside your home country.
Changes and questions
We may update this policy to reflect product or legal changes. We will update the date above when we do. Significant changes may also be communicated in the app or by email when practical.
Questions about privacy:support@notasideproject.com.