Privacy Policy
Last updated: 21 July 2026
This policy explains what data the FirstTry: Product Trial Promos app (“the App”) accesses when a merchant installs it on their Shopify store, why, how long it is kept, and how it is deleted.
Who we are
The App is provided by SmallRocks Studio (“we”, “us”), contactable at support@smallrocks.studio. For data processed on a merchant’s behalf, the merchant is the data controller and we act as a data processor.
What we access, and why
When a merchant installs the App it requests access to the following Shopify data through Shopify’s official APIs, and uses it only to run first-purchase promotions:
| Data | Why we access it |
|---|---|
| Order history (including orders older than 60 days) | To determine whether a customer has already bought a promoted product, so the discount applies only on a genuine first purchase. |
| Customer records (customer ID, tags, and an app-owned “purchased products” metafield) | To record and read each customer’s first-purchase eligibility, and to evaluate an optional required customer tag on a promotion. |
| Product information | To let the merchant choose promoted products and to publish a storefront badge marking eligible products. |
We do not access data unrelated to this purpose, and we do not use any of it for advertising, profiling, or resale. We never sell personal data.
What we store, and where
Inside the merchant’s Shopify store
Each customer’s first-purchase history is stored as a customer metafield on the merchant’s own store (namespace $app:first_try). It holds only the numeric IDs of promoted products that customer has bought — no names, emails, addresses, or payment data.
In the App’s own database
The App runs on a private server hosted by Hetzner Online GmbH, in Finland (European Union). Its database holds:
- Merchant staff account details supplied by Shopify when signing in — name, email address, locale, and the access token for the store.
- Promotion configuration — titles, percentages, selected product IDs, schedules and checkout labels. No personal data.
- Background job records. Order, refund and cancellation events are queued for processing, and the queued record contains the webhook payload Shopify sent us. For order events that payload can include the buyer’s name, email address, and billing/shipping address. These records are working data: they are processed and then retained only as described under Retention below.
Diagnostic events
The App sends a small number of usage events to Shopify’s App Events service (for example, that an order used a first-purchase discount). These carry no personal data — at most an order reference such as an order name.
Data in transit
All traffic between the merchant’s browser, Shopify, and the App is encrypted with TLS/HTTPS.
Sub-processors
- Shopify Inc. — the platform the App runs on and the primary store of customer purchase-history data.
- Hetzner Online GmbH — hosts the App server and its database in Finland (EU). No personal data is transferred outside the European Economic Area.
We share data with no other third parties.
Retention and deletion
- Purchase-history metafields persist inside the merchant’s store while the App is installed, so promotions stay accurate.
- Job records containing webhook payloads are deleted once processed and no longer needed for retries, and in any case within 30 days.
- On uninstall, all of that store’s data — promotions, sessions, and job records — is deleted from the App’s database.
The App implements Shopify’s mandatory privacy webhooks:
- Customer data request — we compile the purchase-history data the App holds for that customer and make it available to the merchant.
- Customer redaction — we delete that customer’s App-owned metafields and erase their personal data from any job records the App still holds.
- Shop redaction — we delete all of that store’s data from the App’s database.
Merchants can also delete all promotion data at any time from the App’s Settings page.
Your rights
Buyers should direct privacy requests to the merchant whose store they shopped at — the data controller — who can fulfil them using the mechanisms above. Depending on your jurisdiction (for example GDPR or CCPA) you may have the right to access, correct, delete, or restrict processing of your personal data, and to lodge a complaint with your supervisory authority. Merchants can contact us at support@smallrocks.studio for assistance.
Changes to this policy
We may update this policy; material changes are reflected in the “Last updated” date above.
Contact
SmallRocks Studio — support@smallrocks.studio