VeteranCrowd Reward — Privacy Policy
Last updated: June 2026
Introduction
This Privacy Policy describes how VeteranCrowd, Inc. ("VeteranCrowd," "we," "us," or "our") collects, uses, and shares information in connection with the VeteranCrowd Rewards app for Shopify ("the App"). By installing or using the App, you ("Merchant," "you," or "your") agree to the practices described in this policy.
This policy applies specifically to the App and its integration with your Shopify store. For information about VeteranCrowd's broader services, please refer to the VeteranCrowd website privacy policy at https://www.veterancrowd.com/privacy.
Information We Collect
Information Collected From Merchants
When you install and use the App, we collect the following information:
-
Shopify store information: Your store name, myshopify.com domain, primary domain URL, and contact email address, retrieved via Shopify's Admin API upon installation.
-
VeteranCrowd account credentials: Your email address and password when you sign in to or create a VeteranCrowd merchant account during onboarding. Authentication is handled securely through AWS Cognito; we do not store your password directly.
-
Merchant profile information: Your merchant display name and any optional details you provide during onboarding (e.g., business description, tagline, mailing address, tax ID, point-of-contact phone number).
Information Collected Automatically
-
Session data: We store temporary session information required for Shopify's OAuth handshake and app authentication. This data is stored in AWS DynamoDB and is transient in nature.
-
App usage data: Basic interaction data related to the onboarding flow and app settings.
Information We Do Not Collect
The App does not collect, access, store, or transmit:
-
Buyer or customer personal information — The App does not access your customers' names, email addresses, shipping addresses, payment details, or any other personally identifiable information.
-
Order or transaction data — The App does not read, process, or relay any Shopify order, cart, or payment information.
-
Browsing behavior or tracking data — The checkout extension displays static content only and does not use cookies, pixels, or tracking technologies to monitor buyer behavior.
How We Use Your Information
We use the information we collect for the following purposes:
-
To connect your Shopify store to your VeteranCrowd merchant account and maintain that connection.
-
To display awareness content at checkout — The App renders a customizable, static banner on your Thank You page inviting buyers to learn about VeteranCrowd Rewards. This content does not collect any buyer data.
-
To provide the App's features, including onboarding, the admin dashboard, and links to the VeteranCrowd merchant portal.
-
To handle app lifecycle events, such as installation, reinstallation, and uninstallation.
-
To comply with Shopify's platform requirements, including responding to mandatory GDPR compliance webhooks.
We do not use your information for advertising, profiling, or selling to third parties. We do not use merchant or customer data to train artificial intelligence or machine learning models.
How We Share Your Information
We may share your information in the following limited circumstances:
-
With Shopify: As required by Shopify's platform for app installation, authentication, and checkout extension rendering. Shopify's use of your data is governed by Shopify's Privacy Policy.
-
With AWS (Amazon Web Services): Your VeteranCrowd account authentication is processed through AWS Cognito, and transient session data is stored in AWS DynamoDB. AWS processes this data as a service provider under our instructions.
-
With VeteranCrowd's backend services: Your merchant account information is stored and managed through VeteranCrowd's internal APIs to maintain the link between your Shopify store and your VeteranCrowd merchant account.
-
For legal compliance: We may disclose information if required by law, regulation, legal process, or governmental request.
We do not sell, rent, or trade your personal information to third parties.
Data Retention
-
Merchant account data: Your VeteranCrowd merchant account information is retained for as long as your account is active. If you uninstall the App, your VeteranCrowd store record is archived (not deleted), allowing you to reinstall and reconnect without losing your merchant setup.
-
Session data: Temporary session data used during the Shopify OAuth handshake is retained only for the duration of your active session and is cleaned up automatically. Shopify's mandatory shop/redact webhook triggers final cleanup of any remaining session data approximately 48 hours after uninstallation.
-
Checkout extension data: The checkout extension displays static content configured by you; no buyer data is stored.
You may request deletion of your VeteranCrowd merchant account data at any time by contacting us (see Contact Information below).
Data Security
We implement industry-standard security measures to protect your information, including:
-
Encrypted data transmission (TLS/SSL) for all communications between the App, Shopify, and VeteranCrowd services.
-
Secure authentication through AWS Cognito with encrypted credential handling.
-
Access controls limiting data access to authorized personnel and systems.
While we take reasonable precautions to protect your data, no method of transmission over the Internet or electronic storage is completely secure.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
-
Access: Request a copy of the personal information we hold about you.
-
Correction: Request that we correct inaccurate or incomplete information.
-
Deletion: Request that we delete your personal information, subject to legal and contractual obligations.
-
Portability: Request a copy of your data in a structured, commonly used format.
-
Restriction: Request that we restrict the processing of your personal information under certain circumstances.
-
Objection: Object to the processing of your personal information for certain purposes.
To exercise any of these rights, please contact us using the information provided below. We will respond to your request within 30 days, or as required by applicable law.
GDPR Compliance
For merchants and buyers in the European Economic Area (EEA), United Kingdom, or Switzerland:
-
Legal basis for processing: We process merchant data on the basis of contractual necessity (to provide the App's services) and legitimate interest (to maintain and improve the App).
-
Data subject requests: The App is configured to respond to Shopify's mandatory GDPR compliance webhooks (customers/data_request, customers/redact, and shop/redact). Since the App does not collect or store buyer personal data, customer data requests and redaction requests are acknowledged without action.
-
International transfers: Your data may be processed in the United States, where VeteranCrowd and AWS infrastructure are located. We rely on standard contractual clauses and AWS's compliance certifications to ensure adequate data protection.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
-
The right to know what personal information we collect and how it is used.
-
The right to delete your personal information.
-
The right to opt out of the sale or sharing of personal information. We do not sell or share your personal information.
-
The right to non-discrimination for exercising your privacy rights.
To exercise your rights, contact us using the information below.
Children's Privacy
The App is intended for use by Shopify merchants (businesses) and is not directed at individuals under the age of 16. We do not knowingly collect personal information from children.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of any material changes by updating the "Last updated" date at the top of this policy. We encourage you to review this policy periodically.
Contact Information
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
VeteranCrowd, Inc. Email: support@veterancrowd.com Website: https://www.veterancrowd.com
