Quarter

Privacy policy

Last updated 2026-08-23

This policy explains what Quarter does with data when you install one of our apps on your store. It covers Quarter Bundles, Quarter Product Badges and is written for the merchant installing the app.

Quarter Commerce Labs LTD., trading as Quarter, is the company behind these apps. We are incorporated in British Columbia, Canada. You can reach us at hello@quarter.dev.

The short version

Quarter Bundles stores your store’s bundle configuration and a per-order record of bundle sales, so it can show you your own sales figures. Quarter Product Badges stores the badges you design and the rules that place them — it never sees an order or a shopper at all.

Neither app stores customer names, email addresses, postal addresses, phone numbers or customer IDs. Neither sets cookies, runs tracking, or sells or shares data.

What we process

The apps are separate products with separate databases. Each section below says which app it applies to; where only one is named, the other does not process that data at all.

Store and session data

Both apps. Your .myshopify.com domain and the access token Shopify issues when you install the app. Without these the app cannot talk to your store at all. Each app holds its own copy for its own install.

Bundle configuration

Quarter Bundles only. The bundles you build: their container product, how many items a bundle holds, and which product variants a shopper may choose from. The authoritative copy lives in metafields on your own Shopify product; we keep a mirror so the app’s admin screens load quickly.

Order-derived sales data

Quarter Bundles only. When an order containing a bundle is placed, updated or cancelled, Shopify notifies the app and we record one row per bundle per order:

The order ID is the only field that can be traced back to a person, and only by you, through your own Shopify admin. We hold nothing that identifies a shopper directly. We still treat that ID as personal data and it is covered by everything below.

Badge configuration

Quarter Product Badges only. The badges you design and the rules that decide where they show:

None of this describes a person. The app reads your products and inventory levels to decide which badges apply; it holds no orders, no customers and no shopper data of any kind, and it is not subscribed to Shopify’s order webhooks.

Anonymous product analytics

Quarter Bundles only. We keep daily counters across all merchants — how many bundles exist, how many were sold, revenue split by currency — to understand how the product is used. These rows carry no store, order or customer identifier and cannot be traced back to your shop. Because they are genuinely anonymous they are not deleted when a store uninstalls; there would be nothing to delete.

What we never collect

One thing worth stating plainly

Quarter Bundles only — Product Badges does not subscribe to order webhooks. Shopify’s order webhooks deliver a full order payload, which includes customer details whether an app wants them or not. Our handler reads a single field — the order’s API ID — and discards the rest. That payload is never written to our database and never written to our logs.

Why we process it, and on what basis

PurposeLegal basis (UK/EU GDPR)
Running the app you installedPerformance of our contract with you
Showing you your own bundle sales figuresPerformance of our contract with you
Anonymous cross-merchant usage countersLegitimate interests in understanding and improving the product. The data is anonymous, so it carries no risk to any individual
Security, debugging and abuse preventionLegitimate interests in keeping the service working

We do not use your data to train machine learning models, and we do not use it for marketing.

How long we keep it

DataKept until
Session and access token (both apps)You uninstall the app
Bundle configuration mirror (Bundles)You uninstall the app
Published badge configuration (Badges)You uninstall the app
Badges, rules and assignments (Badges)Erased when Shopify sends us the shop erasure request, about 48 hours after uninstall. They survive the uninstall itself so that reinstalling does not lose the badges you built
Per-order bundle sales rows730 days by default, then automatically purged. Also erased when Shopify sends us a shop erasure request, and erased for a specific order on a customer erasure request
Anonymous daily counters (Bundles)Indefinitely. They contain no identifiers, so there is nothing to erase
Webhook delivery log (Badges)Indefinitely. Each row is a Shopify webhook ID, its topic and your store domain, kept so a redelivered webhook is not processed twice

Sales rows deliberately survive an uninstall for a short window. Shopify requires erasure when it sends the shop redaction request, which arrives around 48 hours later, and that gap means a merchant who uninstalls and reinstalls does not lose their sales history.

Who else can see it

We use the following subprocessors. We do not sell data, and we do not share it for advertising.

WhoWhat forWhere
Shopify Inc.Source of the data. The app runs as a Shopify app and reads store data through Shopify's APIs under the merchant's own agreement with Shopify.Canada, United States and other regions per Shopify
Vercel Inc.Application hosting. The apps' server code runs here, so store data passes through it in transit and appears in runtime logs. Nothing is stored on Vercel; the app writes to the database below.United States (Washington, D.C., US East)
Render Services, Inc.Managed PostgreSQL. All data the apps store is stored here. Render also hosts the quarter.dev website, which processes no merchant data.United States (Oregon, US West)

We may also disclose data where the law requires it. If that ever happens we will tell you, unless we are legally prevented from doing so.

International transfers

We are based in British Columbia, Canada. The app itself runs on servers in the United States, and the data it stores is held in the United States (Oregon) by our database provider. Where data protected by UK or EU GDPR is transferred, it relies on the Standard Contractual Clauses (with the UK Addendum where applicable), incorporated into our Data Processing Agreement.

Security

All traffic between your store, the app and its database runs over HTTPS. Access to production systems is restricted to people who need it. The app is built to hold as little as possible — not collecting shopper data in the first place is the strongest protection available for it. The technical and organisational measures we commit to are set out in Annex II of the Data Processing Agreement.

Your rights

Depending on where you are, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a data protection authority. To exercise any of these, email hello@quarter.dev.

For your customers’ data, you are the controller and we act on your instructions. Shopify sends us the standard data request, customer redaction and shop redaction webhooks, and the app handles all three automatically. Because we hold no customer-identifying data, a data request returns nothing personal, and a customer redaction removes the sales rows for that customer’s orders.

Changes

If we change this policy we will update the date at the top. For changes that materially affect how we handle your data, we will notify merchants with an active installation by email before the change takes effect.

Contact

Quarter Commerce Labs LTD., British Columbia, Canada. Email hello@quarter.dev, and we will provide our registered address on request.