Privacy Policy
Effective Date: December 22, 2024
Last updated: April 26, 2026
Scope: This Privacy Policy covers two distinct contexts: (1) visitors to this marketing website (discountprime.app), and (2) Shopify merchants who install and use the Discount Prime app. Where our data practices differ between these contexts, we note the distinction below.
1. Introduction
At Discount Prime (operated by Aspedan Inc., Toronto, Ontario, Canada), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information.
Data Controller: Aspedan Inc., 325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada is responsible for your personal information as the "Data Controller" under GDPR and similar regulations.
2. Website vs. App: Scope and Roles
Marketing Website (discountprime.app)
This website is a marketing and informational resource for Discount Prime. When you visit this site, we act as the Data Controller for any personal information collected (e.g., contact form submissions, newsletter sign-ups, analytics data).
Shopify App (Discount Prime)
When you install and use Discount Prime via the Shopify App Store, we access and process data from your Shopify store. In this context:
- You (the Merchant) are the Data Controller for your customers' personal data.
- Discount Prime acts as a Data Processor under GDPR Article 28, processing your customers' data on your behalf to provide discount functionality.
- Shopify Inc. is also a Data Processor for your store data per Shopify's Data Processing Addendum.
For details on our data processing relationship with merchants, see our Data Processing Addendum (DPA).
3. Website Visitors: Data We Collect
When you visit discountprime.app (not the Shopify app), we collect the following:
Information You Provide Directly
- Contact Form: Name, email address, message content
- Newsletter Sign-up: Email address
- Demo Requests: Name, email, company name, Shopify store URL
Information Collected Automatically
- Device Information: Operating system, browser type, screen resolution
- Network Information: IP address (used to determine region for compliance)
- Usage Data: Pages visited, time on site, referrer URL
- Cookies: See Section 6 and our Cookie Policy
4. Shopify Merchants: Data We Process
When you install Discount Prime from the Shopify App Store, we access data from your store via Shopify's API. We process this data on your behalf to provide discount campaign functionality.
Shopify API Scopes We Request
Discount Prime requests the following API permissions:
| Scope | Purpose |
|---|---|
read_products | Read product data to apply discounts to specific products/collections |
read_orders | Read order data to calculate ROI and campaign performance |
read_customers | Read customer segments for targeted discounts (e.g., VIP tiers) |
write_discounts | Create and manage automatic discounts via Shopify Functions |
read_price_rules | Read existing discount rules to prevent conflicts |
Customer Data We Process
We may process the following customer data from your Shopify store:
- Customer identifiers: Shopify customer ID (pseudonymized)
- Customer tags/segments: For segment-based discounts
- Order history: Order totals, product quantities (for volume discount eligibility)
- Cart contents: Products in cart (for real-time discount calculation)
Important: We do NOT store raw customer PII (names, emails, addresses) in our database. We use Shopify customer IDs and process data in real-time via Shopify Functions.
Merchant Account Data
For your merchant account, we collect:
- Shopify shop domain and ID
- Store owner name and email (from Shopify)
- Billing information (processed via Shopify Billing API)
- App settings and campaign configurations
- Support communications
5. How We Use Your Information
Website Visitors
| Purpose | Legal Basis (GDPR) |
|---|---|
| Respond to contact form inquiries | Legitimate interest |
| Send newsletter (if subscribed) | Consent |
| Analyze website traffic and improve UX | Consent (for analytics cookies) |
| Ensure website security | Legitimate interest |
Shopify Merchants (App Users)
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide discount campaign functionality | Contract (service agreement) |
| Calculate campaign ROI and analytics | Contract / Legitimate interest |
| Process billing via Shopify | Contract |
| Provide customer support | Contract / Legitimate interest |
| Send transactional emails (receipts, updates) | Contract |
| Improve app features and performance | Legitimate interest |
6. Cookies and Similar Technologies
On This Website: We use cookies for analytics, preferences, and optional marketing. See our Cookie Policy for details and to manage your preferences.
In the Shopify App: The Discount Prime app runs within Shopify's admin interface. Cookies in this context are managed by Shopify. We use Shopify session tokens for authentication, not our own cookies.
Google Consent Mode v2: We implement Google Consent Mode v2 on this website, which respects your cookie preferences and communicates them to Google Analytics.
7. How We Share Information
We Do NOT Sell Your Personal Data
Discount Prime does not sell, rent, or share your personal information with third parties for their direct marketing purposes. Under CCPA/CPRA, California residents have the right to opt-out of sale or sharing we do not sell data, so no opt-out is necessary.
Sub-Processors (Data Sharing)
We share data with the following categories of service providers:
- Shopify Inc. (Canada): E-commerce platform, billing, app infrastructure
- Vercel Inc. (USA): Website and app hosting
- Google LLC (USA): Analytics (Google Analytics 4)
- Intercom Inc. (USA): Customer support chat
For a complete list of sub-processors, see our Sub-Processors List.
Other Disclosures
- Legal Requirements: If required by law, court order, or government request
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Protection: To protect the rights, property, or safety of Discount Prime, our users, or others
8. International Data Transfers
Discount Prime is based in Canada. Your data may be transferred to and processed in countries including the United States. For EEA/UK residents, we implement:
- Standard Contractual Clauses (SCCs) with US-based service providers
- Reliance on adequacy decisions (EU-Canada, UK-Canada)
- Additional security measures and encryption
9. Data Retention and Deletion
Website Visitor Data
- Contact form submissions: 2 years
- Newsletter subscriptions: Until unsubscribe + 30 days
- Analytics data: 26 months (Google Analytics default)
- Cookie consent records: 13 months
Shopify Merchant Data
- Account data: Duration of subscription + 90 days after uninstall
- Campaign configurations: Deleted within 48 hours of app uninstall
- Billing records: 7 years (legal requirement)
- Support communications: 3 years
Shopify Uninstall Webhook
When you uninstall Discount Prime from your Shopify store, we receive an app/uninstalledwebhook from Shopify. Within 48 hours, we:
- Delete all campaign configurations and settings
- Delete cached product/order data
- Retain only: merchant email (for re-installation), billing records (legal requirement)
To request complete deletion including billing records (where legally permitted), contact support@discountprime.app.
10. Your Privacy Rights
For All Users
- Access your personal information
- Request corrections to inaccurate information
- Request deletion (subject to legal retention requirements)
- Opt-out of marketing communications
GDPR Rights (EU/EEA Users)
Under GDPR Articles 15-22:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Correct inaccurate information
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Restrict processing
- Portability (Art. 20): Receive data in machine-readable format
- Objection (Art. 21): Object to processing based on legitimate interest
- Lodge a Complaint: Contact your national data protection authority
CCPA/CPRA Rights (California Residents)
- Right to Know: Request what data is collected, used, and shared
- Right to Delete: Request deletion of your data
- Right to Correct: Request correction of inaccurate data
- Right to Opt-Out: We do not sell data; see Do Not Sell My Info
- Non-Discrimination: We do not discriminate for exercising rights
- GPC: We honor Global Privacy Control signals
PIPEDA Rights (Canada)
- Access your personal information
- Request correction of inaccurate information
- Lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC)
Quebec Law 25 Rights
Quebec residents have enhanced rights including breach notification, disclosure of automated decision-making, and data access.
Exercising Your Rights
Contact us at support@discountprime.app. We respond within 30 days (or as required by local law).
11. Children's Privacy
Discount Prime is not intended for children under 13 (16 in EU/EEA). We do not knowingly collect data from children. If we become aware of such collection, we will delete it immediately.
12. Security Measures
We implement industry-standard security measures including TLS/SSL encryption, firewalls, access controls, and regular security audits. No method of transmission is 100% secure.
Data Breach Notification: We will notify affected users and authorities within 72 hours (GDPR) or as required by applicable law.
13. Contact Us
For privacy questions, data requests, or concerns:
- Email: support@discountprime.app
- Address: Aspedan Inc., 325 Front St West, Suite 300, Toronto, ON M5V 2Y1, Canada
For Shopify Merchants
Effective Date: December 22, 2024
Last Updated: April 26, 2026