Privacy Policy

Last updated: April 17, 2026 · Harrods Health Private Limited ("we", "us", "our")

1. About This Policy

This Privacy Policy describes how DiscountIQ ("App") collects, uses, and protects data when you install and use the App on your Shopify store. By installing DiscountIQ, you agree to the practices described in this policy.

2. Data We Collect

We collect only the data necessary to provide the functionality you enable:

  • Store data: Store domain, currency, timezone, installed/uninstalled timestamps
  • Product data: Product IDs, titles, prices, variants — to configure discount offers
  • Order data: Order totals, discount codes applied, conversion events — for attribution and analytics
  • Customer identifiers: Shopify customer IDs used to build segments for targeted offers
  • App configuration: Offer settings, COGS inputs, campaign schedules, stacking rules
  • Usage telemetry: Feature usage events (offer created, campaign started), stripped of personal data

Customer contact details. Two optional features require us to process customer names and email addresses, because they exist to send email on your behalf:

  • Abandoned cart recovery: when enabled, we store the cart contents and the customer's email address so we can send recovery emails.
  • Review requests: when enabled, we store the customer's name and email address to request and display product reviews.

If you do not enable those features, we hold no customer names or email addresses. We never collect phone numbers or payment information, and we do not build advertising profiles or track customers across sites.

3. How We Use Data

  • To create, manage, and apply discount offers on your store
  • To calculate real-time margin impact using your COGS inputs
  • To schedule campaigns and auto-revert pricing when campaigns end
  • To generate anonymized analytics and performance reports
  • To improve the App and fix bugs

AI processing. Some features send data to a third-party AI provider (Anthropic) to generate text and recommendations:

  • Offer suggestions and store analysis: your store domain, product titles, prices, margins, segment names and aggregated sales figures are sent so the model can suggest offers. No customer personal data is included.
  • Abandoned cart recovery emails (only if you enable the feature): the customer's first name, the contents and total of their cart, and a short summary of their purchase history with your store (months as a customer, number of past orders, whether they bought the item before) are sent so the model can draft a personalized email. Email addresses are never sent to the AI provider.

This data is sent only to produce the output you requested, and is handled under Anthropic's commercial API terms, which do not use API inputs or outputs to train their models. Cart recovery emails are generated only for the optional abandoned-cart recovery feature; if you do not enable it, no cart or customer data is sent to the AI provider.

We do not sell, rent, or share your data with third parties for advertising purposes.

4. Data Storage & Security

Your data is stored in encrypted databases hosted on infrastructure within the European Union and/or United States. We use industry-standard encryption (TLS 1.2+) for data in transit and AES-256 for data at rest. Access is restricted to authorized personnel only.

All webhook payloads from Shopify are verified using HMAC signatures before processing.

5. Data Retention

We retain your store data for as long as DiscountIQ is installed on your store. When you uninstall the App, active sessions and access tokens are deleted immediately.

Shopify then sends us a shop redaction request, normally about 48 hours after uninstall. On receiving it we permanently delete your store record and everything linked to it — offers, campaigns, COGS and stacking settings, analytics, abandoned carts, review requests and any remaining sessions. This deletion is immediate and irreversible; there is no grace period during which the data can be restored by reinstalling. If you reinstall after that point, you start with an empty configuration.

6. Your Rights (GDPR & CCPA)

As a Shopify merchant, you have rights over your data. You may request:

  • Data access: A copy of all data we hold about your store
  • Data deletion: Permanent deletion of all your store data
  • Data portability: Export your data in JSON format
  • Correction: Update incorrect data

To exercise these rights, email us at mail@hemangjain.com. We will respond within 30 days.

Your customers' rights. You are the data controller for your customers' data; we process it on your behalf. We implement Shopify's mandatory privacy webhooks:

  • Data request: we assemble everything we hold about that customer and send it to your registered contact address, so you can respond to them within 30 days.
  • Customer redaction: we erase that customer's personal data across every record we hold — abandoned carts, review requests, and order attributions — within 10 days. Reviews are kept but detached from the person, so your product ratings are unaffected.
  • Shop redaction: we delete all data for your store, including sessions and access tokens.

7. Third-Party Services

DiscountIQ uses the following sub-processors. Each one receives only the data listed against it, and only for the stated purpose:

  • Shopify: Core platform integration — Shopify Privacy Policy
  • Database hosting: Encrypted PostgreSQL database for app data
  • Background jobs: Redis for job queuing (no customer PII stored)
  • Anthropic (AI provider): generates offer suggestions, store analysis and abandoned-cart recovery email copy. Receives store domain, product and offer data, aggregated sales figures, and — for recovery emails only — a customer's first name, cart contents and a summary of their purchase history with your store. It does not receive email addresses, phone numbers, addresses or payment data. See the Anthropic Privacy Policy.
  • Resend (transactional email): delivers the emails the App sends on your behalf. Receives the recipient's email address and the message content — customer email addresses for abandoned-cart recovery and review requests, and your own contact address for merchant notifications. It also receives the customer data export we email to you when Shopify sends a customers/data_request, which contains that customer's personal data. See the Resend Privacy Policy.
  • Our internal ERP endpoint (Harrods Health): a server-to-server webhook operated by us that receives signed lifecycle and usage events — your shop domain, plan, offer and campaign activity, and the shop owner's email address — so we can run billing, support and internal reporting. It is not a third-party analytics or advertising service, and it receives no customer personal data.

No analytics SDKs, advertising pixels, or social media trackers are used.

8. Children's Privacy

DiscountIQ is a B2B application designed for Shopify merchants. We do not knowingly collect data from individuals under 18 years of age.

9. Changes to This Policy

We may update this Privacy Policy periodically. When we do, we will update the "Last updated" date at the top of this page. We will notify you of significant changes via the email address associated with your Shopify Partner account or via an in-app notification.

10. Contact Us

If you have questions about this Privacy Policy or our data practices:

Harrods Health Private Limited
Ambala, Haryana, India
Email: mail@hemangjain.com
Support: mail@hemangjain.com
© 2026 Harrods Health Private Limited · DiscountIQ