Privacy Policy
For the Shopify app Bolt: Low Stock Counters ("Bolt", "the app"). Last updated August 17, 2026.
Bolt is installed by Shopify merchants to display low-stock and urgency badges on their own storefronts. This policy explains what the app collects, why, and how long it is kept.
What the app collects
Store and account information. When a merchant installs Bolt, Shopify provides an access token and the store's .myshopify.com domain. These are stored so the app can authenticate requests to Shopify on the store's behalf. Depending on the install flow, Shopify may also supply the installing user's name, email, and locale as part of the session record.
Merchant configuration. The settings a merchant chooses in the app — thresholds, messages, colors, display styles, per-collection and per-tag rules, and feature toggles — are stored and associated with their store domain.
Storefront analytics events. To report how badges affect conversion, the app records aggregate events: badge impressions, add-to-carts, completed orders, and units sold. Each event stores the product or variant identifier, an order identifier, the line amount and quantity where applicable, and a randomly generated session identifier used only to connect a shopper's badge view to a later purchase within a 24-hour window.
Merchant feedback. If a merchant submits feedback through the app, the message and optional star rating are stored alongside their store domain.
What the app does not collect
Bolt does not collect shopper names, email addresses, phone numbers, shipping or billing addresses, or payment details. The app is deliberately designed to avoid Shopify's protected customer data: it does not use the order-creation webhook, and instead matches purchase events against badge views using only the pseudonymous session identifier described above. That identifier is not linked to any named individual and is not used for advertising, cross-site tracking, or profiling.
How the information is used
Data is used solely to operate the app for the installing merchant: to render badges on their storefront, to power the analytics shown in their dashboard, to enforce plan entitlements through Shopify Billing, and to respond to support requests. Merchant data is never sold, rented, or shared with third parties for their own purposes.
Where data is stored and who can access it
Application data is stored in a hosted PostgreSQL database and served from a hosted application environment, both operated by third-party infrastructure providers acting as processors on the app's behalf. Access is limited to the app operator for the purposes of running, debugging, and supporting the service. Traffic between Shopify, storefronts, and the app is transmitted over HTTPS.
How long data is kept
Storefront analytics events are automatically deleted after 90 days. Store configuration and session records are retained while the app is installed. When a merchant uninstalls, the app deletes that store's session and settings records, and honours Shopify's shop data-erasure request (typically delivered 48 hours after uninstall) as the durable deletion step. The app implements Shopify's mandatory compliance webhooks for customer data requests, customer redaction, and shop redaction.
Merchant and shopper rights
Merchants can remove all stored configuration and analytics for their store at any time by uninstalling the app. Requests for access to, or deletion of, data held about a store can also be made directly by emailing the address below, and will be actioned within the timeframes required by applicable law. Because the app does not store shopper personal information, customer data requests forwarded by Shopify are answered on that basis.
Changes to this policy
If this policy changes materially, the updated version will be published on this page with a revised date above.
Contact
Questions about this policy or about data handling can be sent to boltapp.support@gmail.com.