Collective Payment Guard

Privacy policy

Effective date: August 31, 2026

This policy explains how Sahab Technologies Ltd processes information when a merchant installs Collective Payment Guard.

Information processed

The app stores the shop domain and Shopify shop ID; Shopify order and fulfillment-order IDs; order name, amount, currency, Collective detection result, payment state, hold IDs, timestamps, operational errors, merchant settings, and an optional alert email. The app does not intentionally store customer profiles, shipping or billing addresses, phone numbers, customer emails, or payment credentials.

Purpose and sharing

Information is used only to authenticate the merchant, detect relevant Collective orders, protect fulfillment, reconcile Shopify state, display operational status, and send configured alerts. Data is shared only with Shopify, the app's hosting/database providers, and the configured email delivery provider as needed to operate the service.

Retention and deletion

OAuth sessions are removed on uninstall. Shopify's authenticated shop-redaction request deletes the shop's application records. Backup copies expire under the operator's infrastructure retention policy.

Security and merchant rights

The app uses Shopify-authenticated requests, encrypted HTTPS transport, tenant isolation, minimum API scopes, and restricted access to secrets. Merchants can request access, correction, or deletion by contacting the operator.

Contact

omar@sahabtech.co.uk