Privacy Policy

Effective Date: December 22, 2024

Last updated: April 26, 2026

Scope: This Privacy Policy covers two distinct contexts: (1) visitors to this marketing website (discountprime.app), and (2) Shopify merchants who install and use the Discount Prime app. Where our data practices differ between these contexts, we note the distinction below.

1. Introduction

At Discount Prime (operated by Aspedan Inc., Toronto, Ontario, Canada), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information.

Data Controller: Aspedan Inc., 325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada is responsible for your personal information as the "Data Controller" under GDPR and similar regulations.

2. Website vs. App: Scope and Roles

Marketing Website (discountprime.app)

This website is a marketing and informational resource for Discount Prime. When you visit this site, we act as the Data Controller for any personal information collected (e.g., contact form submissions, newsletter sign-ups, analytics data).

Shopify App (Discount Prime)

When you install and use Discount Prime via the Shopify App Store, we access and process data from your Shopify store. In this context:

  • You (the Merchant) are the Data Controller for your customers' personal data.
  • Discount Prime acts as a Data Processor under GDPR Article 28, processing your customers' data on your behalf to provide discount functionality.
  • Shopify Inc. is also a Data Processor for your store data per Shopify's Data Processing Addendum.

For details on our data processing relationship with merchants, see our Data Processing Addendum (DPA).

3. Website Visitors: Data We Collect

When you visit discountprime.app (not the Shopify app), we collect the following:

Information You Provide Directly

  • Contact Form: Name, email address, message content
  • Newsletter Sign-up: Email address
  • Demo Requests: Name, email, company name, Shopify store URL

Information Collected Automatically

  • Device Information: Operating system, browser type, screen resolution
  • Network Information: IP address (used to determine region for compliance)
  • Usage Data: Pages visited, time on site, referrer URL
  • Cookies: See Section 6 and our Cookie Policy

4. Shopify Merchants: Data We Process

When you install Discount Prime from the Shopify App Store, we access data from your store via Shopify's API. We process this data on your behalf to provide discount campaign functionality.

Shopify API Scopes We Request

Discount Prime requests the following API permissions:

ScopePurpose
read_productsRead product data to apply discounts to specific products/collections
read_ordersRead order data to calculate ROI and campaign performance
read_customersRead customer segments for targeted discounts (e.g., VIP tiers)
write_discountsCreate and manage automatic discounts via Shopify Functions
read_price_rulesRead existing discount rules to prevent conflicts

Customer Data We Process

We may process the following customer data from your Shopify store:

  • Customer identifiers: Shopify customer ID (pseudonymized)
  • Customer tags/segments: For segment-based discounts
  • Order history: Order totals, product quantities (for volume discount eligibility)
  • Cart contents: Products in cart (for real-time discount calculation)

Important: We do NOT store raw customer PII (names, emails, addresses) in our database. We use Shopify customer IDs and process data in real-time via Shopify Functions.

Merchant Account Data

For your merchant account, we collect:

  • Shopify shop domain and ID
  • Store owner name and email (from Shopify)
  • Billing information (processed via Shopify Billing API)
  • App settings and campaign configurations
  • Support communications

5. How We Use Your Information

Website Visitors

PurposeLegal Basis (GDPR)
Respond to contact form inquiriesLegitimate interest
Send newsletter (if subscribed)Consent
Analyze website traffic and improve UXConsent (for analytics cookies)
Ensure website securityLegitimate interest

Shopify Merchants (App Users)

PurposeLegal Basis (GDPR)
Provide discount campaign functionalityContract (service agreement)
Calculate campaign ROI and analyticsContract / Legitimate interest
Process billing via ShopifyContract
Provide customer supportContract / Legitimate interest
Send transactional emails (receipts, updates)Contract
Improve app features and performanceLegitimate interest

6. Cookies and Similar Technologies

On This Website: We use cookies for analytics, preferences, and optional marketing. See our Cookie Policy for details and to manage your preferences.

In the Shopify App: The Discount Prime app runs within Shopify's admin interface. Cookies in this context are managed by Shopify. We use Shopify session tokens for authentication, not our own cookies.

Google Consent Mode v2: We implement Google Consent Mode v2 on this website, which respects your cookie preferences and communicates them to Google Analytics.

7. How We Share Information

We Do NOT Sell Your Personal Data

Discount Prime does not sell, rent, or share your personal information with third parties for their direct marketing purposes. Under CCPA/CPRA, California residents have the right to opt-out of sale or sharing we do not sell data, so no opt-out is necessary.

Sub-Processors (Data Sharing)

We share data with the following categories of service providers:

  • Shopify Inc. (Canada): E-commerce platform, billing, app infrastructure
  • Vercel Inc. (USA): Website and app hosting
  • Google LLC (USA): Analytics (Google Analytics 4)
  • Intercom Inc. (USA): Customer support chat

For a complete list of sub-processors, see our Sub-Processors List.

Other Disclosures

  • Legal Requirements: If required by law, court order, or government request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Protection: To protect the rights, property, or safety of Discount Prime, our users, or others

8. International Data Transfers

Discount Prime is based in Canada. Your data may be transferred to and processed in countries including the United States. For EEA/UK residents, we implement:

  • Standard Contractual Clauses (SCCs) with US-based service providers
  • Reliance on adequacy decisions (EU-Canada, UK-Canada)
  • Additional security measures and encryption

9. Data Retention and Deletion

Website Visitor Data

  • Contact form submissions: 2 years
  • Newsletter subscriptions: Until unsubscribe + 30 days
  • Analytics data: 26 months (Google Analytics default)
  • Cookie consent records: 13 months

Shopify Merchant Data

  • Account data: Duration of subscription + 90 days after uninstall
  • Campaign configurations: Deleted within 48 hours of app uninstall
  • Billing records: 7 years (legal requirement)
  • Support communications: 3 years

Shopify Uninstall Webhook

When you uninstall Discount Prime from your Shopify store, we receive an app/uninstalledwebhook from Shopify. Within 48 hours, we:

  • Delete all campaign configurations and settings
  • Delete cached product/order data
  • Retain only: merchant email (for re-installation), billing records (legal requirement)

To request complete deletion including billing records (where legally permitted), contact support@discountprime.app.

10. Your Privacy Rights

For All Users

  • Access your personal information
  • Request corrections to inaccurate information
  • Request deletion (subject to legal retention requirements)
  • Opt-out of marketing communications

GDPR Rights (EU/EEA Users)

Under GDPR Articles 15-22:

  • Access (Art. 15): Request a copy of your personal data
  • Rectification (Art. 16): Correct inaccurate information
  • Erasure (Art. 17): Request deletion ("right to be forgotten")
  • Restriction (Art. 18): Restrict processing
  • Portability (Art. 20): Receive data in machine-readable format
  • Objection (Art. 21): Object to processing based on legitimate interest
  • Lodge a Complaint: Contact your national data protection authority

CCPA/CPRA Rights (California Residents)

  • Right to Know: Request what data is collected, used, and shared
  • Right to Delete: Request deletion of your data
  • Right to Correct: Request correction of inaccurate data
  • Right to Opt-Out: We do not sell data; see Do Not Sell My Info
  • Non-Discrimination: We do not discriminate for exercising rights
  • GPC: We honor Global Privacy Control signals

PIPEDA Rights (Canada)

  • Access your personal information
  • Request correction of inaccurate information
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC)

Quebec Law 25 Rights

Quebec residents have enhanced rights including breach notification, disclosure of automated decision-making, and data access.

Exercising Your Rights

Contact us at support@discountprime.app. We respond within 30 days (or as required by local law).

11. Children's Privacy

Discount Prime is not intended for children under 13 (16 in EU/EEA). We do not knowingly collect data from children. If we become aware of such collection, we will delete it immediately.

12. Security Measures

We implement industry-standard security measures including TLS/SSL encryption, firewalls, access controls, and regular security audits. No method of transmission is 100% secure.

Data Breach Notification: We will notify affected users and authorities within 72 hours (GDPR) or as required by applicable law.

13. Contact Us

For privacy questions, data requests, or concerns:


Effective Date: December 22, 2024
Last Updated: April 26, 2026