1. Who we are
MarginShip is a Shopify application operated by PRX COMERCIO DE PERFUMES E COSMETICOS LTDA, Brazil. This Policy explains how we process information when Shopify merchants install or use the app, visit marginship.com or contact support.
2. Our privacy approach
MarginShip is designed around data minimization. The shipping rule does not require Shopify customer, order, customer-address or payment scopes. A merchant can separately authorize optional, read-only order access to use the Impact report. We do not sell personal information or use merchant or buyer information for advertising.
3. Information we process
- Shop and installation information: the store's
.myshopify.comdomain, OAuth session information, access and refresh tokens where applicable, token expiration, granted scopes and authentication state. - Shopify administrator information: when supplied in the authenticated session, administrator identifiers, name, email, locale, account-owner or collaborator status and email-verification status.
- MarginShip configuration: rule status, optional threshold, shipping ratio, promotional cap, message, product or collection exclusions and related Shopify discount/metafield identifiers.
- Cart and checkout calculations: Shopify Functions process the product subtotal, discounts reflected by Shopify, delivery-group information, option identifiers and prices, and currency conversion data inside Shopify's Function environment. Those checkout values are not sent to or stored by the MarginShip application server.
- Shopify rate-preview inputs: when a merchant intentionally runs a Growth or Scale preview, selected Shopify variant identifiers, quantities, country/region/postal destination fields and entered discount values are sent to Shopify's Storefront API to request a cart, delivery groups and available options. Inputs and returned rates are processed for that request and are not intentionally stored or logged by MarginShip. The preview does not create an order, initiate payment or save a customer address.
- Plan entitlement: the active MarginShip subscription and billing interval returned by Shopify's Partner API are used to determine feature access.
- Optional Impact report: after the merchant explicitly authorizes Shopify's
read_ordersscope, MarginShip reads order identifier/number, timestamps, financial status, store-currency subtotal and total, shipping-line title and prices, and shipping discount allocations for the selected period (up to Shopify's standard 60-day order window). The report uses this information to identify confirmed MarginShip shipping benefits and calculate aggregate indicators. It does not request or read customer names, email addresses, phone numbers or delivery addresses, and the order results are analyzed live rather than retained in the MarginShip database. - Technical and security logs: timestamps, environment, event type, request identifiers, webhook topic, shop domain and normalized error information. Hosting infrastructure can also generate standard access metadata such as IP address, request time, URL, user agent and network information.
- Support communications: information voluntarily provided in emails or attachments, such as name, email, store domain, description and screenshots.
4. End-customer and protected customer data
The shipping rule does not require protected order data. The optional Impact report requires Shopify's read-only order scope because order-level results are protected customer data, but MarginShip minimizes that access to non-identifying order and shipping values needed for the report. It does not request protected customer fields such as names, addresses, emails or phone numbers and does not store buyer profiles or order history. Mandatory privacy webhooks can contain identifiers or contact details supplied by Shopify; those payloads are authenticated, processed only to fulfill the request and are not intentionally logged or retained.
5. Why we process information
We process information to authenticate stores, operate rules and simulations, enforce plan access, maintain security and reliability, provide support, administer the service, comply with Shopify requirements and meet legal obligations. Legal bases can include contract performance, legitimate interests, legal obligations or consent where required.
6. Service providers and disclosures
We use Shopify for installation, OAuth, APIs, Functions, extensions, discounts, metafields, billing and App Store distribution; Hostinger for VPS hosting, database and infrastructure logs in São Paulo, Brazil; and Namecheap Private Email for support, privacy and general-contact mailboxes. We can disclose information when required by law or reasonably necessary to protect the service, users or others. We do not sell or rent personal information or share it for cross-context behavioral advertising.
7. International transfers
The MarginShip application server is hosted in Brazil. Shopify, Namecheap and their providers can process information in other countries under their contractual, privacy and transfer safeguards.
8. Retention and deletion
- Installation sessions and OAuth data are retained while needed for an active installation and deleted in response to uninstall and
shop/redactworkflows. - Checkout calculation data is not stored by the MarginShip server.
- Simulator inputs and returned rates are not intentionally stored by MarginShip.
- Order-level results used by the optional Impact report are read live from Shopify and are not retained in the MarginShip database.
- Configuration in Shopify remains subject to Shopify's platform behavior and retention.
- Technical logs and support correspondence are retained only as reasonably necessary for security, troubleshooting, support, dispute resolution and legal obligations.
MarginShip implements Shopify's customers/data_request, customers/redact and shop/redact privacy workflows.
9. Your privacy rights
Depending on your location, you may request access, correction, deletion, restriction, portability, objection or information about processing. Contact privacy@marginship.com. We can verify your identity or authority for a store before acting.
10. Security
MarginShip uses HTTPS/TLS, Shopify OAuth and authenticated webhooks, restricted credentials, request validation and logical separation from unrelated applications. No internet service can guarantee absolute security.
11. Changes
We may update this Policy as the service, providers, law or Shopify requirements change. The current version will remain at this URL with its updated date.
12. Contact
Privacy: privacy@marginship.com
Product support: support@marginship.com
General inquiries: hello@marginship.com