Privacy Policy
Last updated: July 29, 2026 · App: nba-card
1. Who we are
nba-card (“we”, “us”) is a Shopify app that helps merchants run case-break “Pick Your Team” seat sales on their Online Store. This policy explains what data we process when you install or use the app.
2. Data we process
Depending on how the app is used, we may process:
- Shop / session data — shop domain, OAuth access tokens, and staff session metadata required to run the embedded app.
- Break activity data — break names, pricing, team seats, product/variant IDs, inventory lock logs, and storefront publication status created by the merchant.
- Buyer-related fields on seats — when a seat is sold or marked sold, optional buyer name, contact, order reference, and notes associated with that seat.
- Order webhook payloads — order identifiers and line item details needed to mark seats sold after payment.
- Compliance request logs — exports generated when Shopify sends mandatory
customers/data_requestwebhooks, so merchants can fulfill privacy requests.
3. How we use data
- Operate the embedded admin experience and theme app extension.
- Create and sync seat products, inventory, and sales status.
- Respond to Shopify mandatory compliance webhooks.
- Provide merchants with downloadable customer data exports.
We do not sell personal data. We do not use buyer data for advertising.
4. Storage and retention
App data is stored in our application database hosted for production (currently on Render with managed PostgreSQL). Session records are removed when the app is uninstalled. Remaining shop data is deleted when Shopify sends the shop/redact webhook (typically about 48 hours after uninstall). Customer personal fields on seats are cleared when Shopify sends customers/redact.
5. Sharing
We share data with Shopify as required to operate the app (Admin API, webhooks, Online Store). Hosting providers process data only to run the service. We do not share data with unrelated third parties for their own marketing.
6. Merchant and customer rights
Merchants can view stored customer data-request exports inside the app under Privacy. Buyers should contact the merchant store for storefront privacy requests; Shopify will also notify us via mandatory webhooks when applicable.
7. Contact
Privacy questions: wufenghuo8@gmail.com