Preboost PreOrder & Presale
Privacy Policy
Effective date: 19 August 2026 · Last updated: 19 August 2026
This policy describes how the Shopify app Preboost PreOrder & Presale (“the App”, “we”, “us”) collects, uses, stores, and shares information. It is written for Shopify’s app review and Protected customer data requirements, and for merchants who install the App.
We process only the data needed to run pre-order campaigns and to send shipping-update emails that a merchant chooses to send. We do not sell personal data. We do not use customer data for advertising or profiling.
1. Who is responsible
When a merchant installs the App on their Shopify store, the merchant is the controller of their customers’ personal data. We act as a processor on the merchant’s instructions, through Shopify’s APIs.
Shopify Inc. also processes store and customer data under Shopify’s own terms and Consumer Privacy Policy.
Contact for privacy requests: privacy@blackpopup.com
2. Data we process
Merchant / shop data
- Shop domain and Shopify shop name
- Offline access token and session (so the App can run in admin)
- Campaign settings the merchant configures (button text, discounts, design, products, selling-plan IDs)
Customer data (only after Shopify grants Protected customer data access)
We request Shopify Admin API access to Orders, customer name, and customer email. We do not request phone numbers or street addresses.
- Order ID and order name (for example #1001)
- Order date, totals, currency, payment status, fulfillment status
- Line items that use this App’s pre-order selling plan
- Customer display name (to show in the merchant’s Pre-orders list)
- Customer email (only as the To address when the merchant sends a shipping-delay message)
We do not load or store billing/shipping addresses or phone numbers.
Storefront
On the merchant’s online store, the theme embed reads product metafields and selling plans to show the pre-order button. It does not collect visitor names or emails by itself. Checkout and order creation stay on Shopify.
3. Why we process it (purpose limitation)
- App functionality: create and publish pre-order selling plans on products the merchant selects.
- Store management: list pre-orders (id, date, customer name, total, paid/fulfilled status) in the merchant admin.
- Customer service: send a merchant-triggered shipping delay email, with {order} and {orderName} replaced from that order.
We do not use this data for ads, lookalike audiences, resale, or unrelated analytics products.
4. Legal bases (where GDPR/UK GDPR apply)
- Merchant contract: installing and using the App.
- Merchant’s legitimate interest / contract with their customer: showing order status and sending fulfillment updates the merchant initiates for people who already placed a pre-order.
5. How we obtain data
Only through Shopify Admin GraphQL after OAuth, on stores where the App is installed, and only for orders that include this App’s selling plan. We do not scrape storefronts. We do not buy contact lists.
Emails used for send are read from Shopify at send time (customer.defaultEmailAddress.emailAddress). We do not accept a list of addresses from the browser or from unauthenticated HTTP clients.
6. Sharing / processors
- Shopify — platform, auth, Admin API.
- Vercel — hosts the App (HTTPS).
- Neon (PostgreSQL) — sessions, campaign settings, and shipping-update send logs.
- Amazon SES (eu-north-1) — delivers the email. From address:
preorder@blackpopup.com. The visible From name is the merchant’s Shopify shop name.
We do not sell personal data. We do not share it with advertisers. Processors may only use data to provide their service to us.
7. Retention
- Shopify sessions / tokens: while the App stays installed and the session is valid.
- Campaign configuration: until the merchant deletes the campaign or uninstalls.
- Shipping-update send logs (shop, order id, order name, email, sent time): kept to enforce a 24-hour per-order cooldown and a 50-email-per-hour shop cap. We intend to delete these logs after 24 months, or sooner on a valid deletion request.
After uninstall we stop calling the shop’s Admin API. Session rows for that shop should be treated as ended. Contact us to confirm deletion of remaining send logs.
8. Security
- HTTPS / TLS in transit
- Encryption at rest on Neon Postgres and Vercel’s platform
- Shopify session required for admin actions and for send
- Send is limited: max 25 orders per request, 50 emails per shop per hour, 24-hour cooldown per order
- Unauthenticated requests (for example Postman without a Shopify session) cannot list orders or send mail
No method of transmission is perfectly secure. Merchants should also protect their Shopify staff accounts.
9. Merchant and customer rights
Depending on location (including GDPR, UK GDPR, and CCPA/CPRA), people may request access, correction, deletion, or a copy of personal data, or object to certain processing.
- Customers should contact the merchant first (the store they bought from).
- Merchants can email privacy@blackpopup.com with the shop domain. We will help with App-held data.
- We honor Shopify mandatory compliance webhooks when they are configured for the App (
customers/data_request,customers/redact,shop/redact). - We do not sell personal data, so a “do not sell” request is already met.
We do not use personal data for automated decisions that produce legal or similarly significant effects.
10. Children
The App is for merchants operating Shopify stores. It is not directed at children under 16. We do not knowingly collect data from children.
11. International transfers
Shopify, Vercel, Neon, and AWS may process data in the United States, the EU (SES eu-north-1), or other regions where they operate. Merchants should review Shopify’s and those providers’ terms.
12. Changes
We may update this policy. The “Last updated” date at the top will change. Material changes should be reflected in the App listing privacy URL as well.
13. Contact
Preboost PreOrder & Presale
Privacy: privacy@blackpopup.com
App URL: https://pre-order-blush.vercel.app
Partner Dashboard privacy policy URL to paste: https://pre-order-blush.vercel.app/privacy