This policy explains what thankSnap ("we," "us") collects when a merchant installs the thankSnap Shopify app, and when that merchant's customers answer a survey on the Thank you page. If anything here is unclear, the FAQ covers common questions in plain language.
What we collect from merchants
When you install thankSnap on your Shopify store, we store:
- Your store's domain (e.g.
your-store.myshopify.com) and, if provided by Shopify, your store contact email. - A Shopify access token that lets the app act on your store's behalf, limited to what the app needs to function. This token is encrypted at rest (AES-256-GCM) before it's stored - it is never kept as plain text.
- Your survey configuration: the question(s) you've written, their type (single choice, multiple choice, text, rating, or yes/no), and whether the survey is active.
- Your subscription plan and current usage against its included monthly order volume, so the app can show you that information and apply your plan correctly.
What we collect from your customers
When a customer answers the survey on your Thank you page, we store their answer and the order it's attached to (the order's Shopify ID, order number, total, currency, and date). We do not collect or store a customer's name, email address, or phone number as part of a survey response, and the app's checkout extension is built to need nothing beyond that order information.
One exception worth being direct about: if your survey includes a free-text question, a customer could choose to type anything in their answer, including personal information they weren't asked for. That text is stored as the customer entered it. We'd recommend avoiding free-text questions that invite sensitive answers.
How customer data requests are handled
Shopify requires every public app to support data-request, data-redact and shop-redact requests, and thankSnap implements all three automatically:
- Data request: because we never store a customer's name, email, or phone against a survey response, there is no personal data on file to compile for this kind of request.
- Customer redact: when Shopify notifies us that a customer has requested erasure, we delete any order (and its associated survey responses) tied to that customer.
- Shop redact: when a store uninstalls the app, all of that store's data - surveys, responses, orders, and feedback - is deleted automatically.
Where data is stored and who can see it
Data is stored in a Postgres database (hosted via Supabase) with row-level security enabled on every table, and the app itself is hosted on Vercel. A store's data is scoped to that store - the app's own code enforces this on every query, and the database's own access controls block any other path to it. We don't sell survey data or use it for advertising.
Other services we use
This app relies on a small number of other services to run:
- Shopify - the platform thankSnap is built on and installed through.
- Supabase - hosts the Postgres database described above.
- Vercel - hosts the app and this website.
- Sentry - error monitoring only (no analytics or session tracking); if something breaks, Sentry may capture technical details like a stack trace or request URL to help us fix it.
- Google Fonts - this website and the app's admin pages load typefaces from Google's font service, which means a visitor's browser makes a request directly to Google and Google can see that request's IP address, the same as loading any font from any font host.
Data retention
We keep a store's data for as long as the app is installed. If the app is uninstalled, that store's data is deleted automatically (see "Shop redact" above). If a specific order is redacted at Shopify's request, that order and its responses are deleted individually, without affecting the rest of the store's data.
Your rights
If you're a merchant, you can request export or deletion of your store's data at any time by uninstalling the app or contacting us below. If you're a shopper who answered a survey, requests about your data should go through the store you purchased from - Shopify routes these to us automatically, as described above.
Changes to this policy
If this policy changes in a way that matters, we'll update the effective date above. Significant changes will be noted on this page.
Contact
Questions about this policy or your data can be sent to support@thanksnap.com.