Quarter

Privacy policy

Last updated 2026-08-07

This policy explains what Quarter does with data when you install one of our apps on your store. It covers Quarter Bundles (Shopify) and is written for the merchant installing the app.

Quarter Commerce Labs LTD., trading as Quarter, is the company behind these apps. We are incorporated in British Columbia, Canada. You can reach us at hello@quarter.dev.

The short version

The app stores your store’s bundle configuration and a per-order record of bundle sales so it can show you your own sales figures. It stores no customer names, email addresses, postal addresses, phone numbers or customer IDs. It sets no cookies, runs no tracking, and never sells or shares data.

What we process

Store and session data

Your .myshopify.com domain and the access token Shopify issues when you install the app. Without these the app cannot talk to your store at all.

Bundle configuration

The bundles you build: their container product, how many items a bundle holds, and which product variants a shopper may choose from. The authoritative copy lives in metafields on your own Shopify product; we keep a mirror so the app’s admin screens load quickly.

Order-derived sales data

When an order containing a bundle is placed, updated or cancelled, Shopify notifies the app and we record one row per bundle per order:

The order ID is the only field that can be traced back to a person, and only by you, through your own Shopify admin. We hold nothing that identifies a shopper directly. We still treat that ID as personal data and it is covered by everything below.

Anonymous product analytics

We keep daily counters across all merchants — how many bundles exist, how many were sold, revenue split by currency — to understand how the product is used. These rows carry no store, order or customer identifier and cannot be traced back to your shop. Because they are genuinely anonymous they are not deleted when a store uninstalls; there would be nothing to delete.

What we never collect

One thing worth stating plainly

Shopify’s order webhooks deliver a full order payload, which includes customer details whether an app wants them or not. Our handler reads a single field — the order’s API ID — and discards the rest. That payload is never written to our database and never written to our logs.

Why we process it, and on what basis

PurposeLegal basis (UK/EU GDPR)
Running the app you installedPerformance of our contract with you
Showing you your own bundle sales figuresPerformance of our contract with you
Anonymous cross-merchant usage countersLegitimate interests in understanding and improving the product. The data is anonymous, so it carries no risk to any individual
Security, debugging and abuse preventionLegitimate interests in keeping the service working

We do not use your data to train machine learning models, and we do not use it for marketing.

How long we keep it

DataKept until
Session and access tokenYou uninstall the app
Bundle configuration mirrorYou uninstall the app
Per-order bundle sales rows730 days by default, then automatically purged. Also erased when Shopify sends us a shop erasure request, and erased for a specific order on a customer erasure request
Anonymous daily countersIndefinitely. They contain no identifiers, so there is nothing to erase

Sales rows deliberately survive an uninstall for a short window. Shopify requires erasure when it sends the shop redaction request, which arrives around 48 hours later, and that gap means a merchant who uninstalls and reinstalls does not lose their sales history.

Who else can see it

We use the following subprocessors. We do not sell data, and we do not share it for advertising.

WhoWhat forWhere
Shopify Inc.Source of the data. The app runs as a Shopify app and reads store data through Shopify's APIs under the merchant's own agreement with Shopify.Canada, United States and other regions per Shopify
Render Services, Inc.Application hosting and managed PostgreSQL. All data the app stores is stored here.United States (Oregon, US West)

We may also disclose data where the law requires it. If that ever happens we will tell you, unless we are legally prevented from doing so.

International transfers

We are based in British Columbia, Canada, and the data the app stores is held in the United States (Oregon) by our hosting provider. Where data protected by UK or EU GDPR is transferred, it relies on the Standard Contractual Clauses (with the UK Addendum where applicable), incorporated into our Data Processing Agreement.

Security

All traffic between your store, the app and its database runs over HTTPS. Access to production systems is restricted to people who need it. The app is built to hold as little as possible — not collecting shopper data in the first place is the strongest protection available for it. The technical and organisational measures we commit to are set out in Annex II of the Data Processing Agreement.

Your rights

Depending on where you are, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to complain to a data protection authority. To exercise any of these, email hello@quarter.dev.

For your customers’ data, you are the controller and we act on your instructions. Shopify sends us the standard data request, customer redaction and shop redaction webhooks, and the app handles all three automatically. Because we hold no customer-identifying data, a data request returns nothing personal, and a customer redaction removes the sales rows for that customer’s orders.

Changes

If we change this policy we will update the date at the top. For changes that materially affect how we handle your data, we will notify merchants with an active installation by email before the change takes effect.

Contact

Quarter Commerce Labs LTD., British Columbia, Canada. Email hello@quarter.dev, and we will provide our registered address on request.