At a glance
- Fixpoint One builds Shopify apps designed to minimize data collection.
- Shopify remains the system of record for customer accounts, orders, and customer profiles.
- Most apps minimize stored customer data. FP1 - Duplicate Order Check uses limited order data for merchant-facing issue detection, while FP1 - Merge Orders stores limited customer matching information and shipping-address snapshots needed to group and fulfill merchant-approved shipments.
- Some features may use third-party services if enabled (for example, Geo-IP lookup).
- Shop configuration and operational metadata may be stored to provide app functionality.
- Shopify GDPR webhooks and uninstall handling are supported.
- Contact: [email protected]
Contents
- About Fixpoint One
- Apps covered by this policy
- General data handling principles
- FP1 - Cart Shipping Calculator
- FP1 - Duplicate Order Check
- FP1 - Merge Orders
- FP1 - Postcode Shipping Guard
- FP1 - Hide Payment Methods
- GDPR and data privacy compliance
- How data access and deletion requests are handled
- Contact
About Fixpoint One
Fixpoint One develops Shopify apps based in Canada.
Apps covered by this policy
This Privacy Policy applies to all Fixpoint One Shopify apps, including:
- FP1 - Cart Shipping Calculator
- FP1 - Duplicate Order Check
- FP1 - Merge Orders
- FP1 - Postcode Shipping Guard
- FP1 - Hide Payment Methods
Future Fixpoint One apps will follow the same data handling principles unless otherwise noted. For implementation help, visit the support page.
General data handling principles
- Fixpoint One apps are designed to minimize the amount of data collected or stored.
- Data is used only for the core functionality of each app.
- Customer data is not sold. Customer data is not shared with third parties except where required to provide a feature you enable (for example, a Geo-IP lookup), and only to the extent necessary.
- Fixpoint One apps rely on Shopify’s infrastructure and APIs. Shopify remains the primary system of record, while an app may store the limited operational records described in its section below.
- Where needed for plan enforcement, an app may store shop-level Free-usage counters, subscription identifiers, selected Free-plan rule identifiers, and paid-through timestamps. This is operational billing metadata and does not include payment-card details.
- Any data processed or stored by Fixpoint One apps is handled securely and only as needed for each feature.
Website analytics
Fixpointone.com uses Google Analytics 4 to understand page visits and clicks to app pages and Shopify listings. When a visitor arrives with advertising or campaign parameters, the site may read UTM values and advertising click identifiers such as gclid, wbraid, gbraid, fbclid, or msclkid. These attribution values are limited in length and may be kept in browser sessionStorage for the current browsing session so later clicks can be attributed consistently.
Analytics requests are sent to Google. As with normal web requests, analytics providers may receive technical request information such as an IP address, browser information, and the page being visited. Fixpoint One uses this information for aggregate website and campaign measurement and does not use the website analytics code to collect Shopify customer records, payment-card details, or Shopify login credentials.
FP1 - Cart Shipping Calculator
Data the app uses
- Cart contents (product quantities, weights, and totals) needed to request shipping rates.
- Destination details provided by the shopper (country, and province/state if required).
- Postal/ZIP code entered by the shopper for more accurate rate estimates.
- If Geo-IP is enabled, an estimated country/region may be used to pre-fill location.
Geo-IP lookup
If Geo-IP auto-detection is enabled, the app may estimate a shopper’s country/region via a Geo-IP lookup
service
(for example, ipwho.is),
routed through a secure proxy. Geo-IP data is used only to help pre-fill location information for
shipping-rate estimation.
If Geo-IP is disabled, no Geo-IP lookups are performed.
A shopper’s IP address may be processed for the Geo-IP lookup request. Fixpoint One does not store the shopper’s IP address in the app’s database as part of this feature. However, the Geo-IP provider may receive the IP address in order to return an estimate, and may keep standard server logs (see the provider’s privacy policy). Fixpoint One systems may also generate short-lived operational logs for security and debugging.
What the app stores
- No cart or customer address data is stored on Fixpoint One systems.
- Merchant configuration is stored (for example: Geo-IP enabled/disabled and widget readability setting).
- Temporary values are used to request shipping rates from Shopify (for example via Shopify’s cart shipping rates endpoint) and are not stored long-term.
- Shop-level free-tier usage accounting is stored, including the successful-calculation total and short idempotency or deduplication receipt identifiers needed to count a logical calculation once. These usage records do not contain shopper addresses or cart contents.
FP1 - Duplicate Order Check
Data the app uses
- Shopify order identifiers, order names, status, timestamps, totals, and currency needed to evaluate order issues.
- Cart or checkout correlation data plus line-item identities and quantities needed for conservative possible-duplicate checks.
- Refund, cancellation, fulfillment, and shipping-state signals needed to identify orders that may still ship.
- Partially fulfilled order state and timing needed to identify stuck orders.
- Shop information needed for secure authentication and app operation.
What the app stores
- Merchant settings, including enabled checks, optional email alerts, alert email, and stuck-order delay.
- Internal issue records, limited order references, statuses, and timestamps needed to track open and resolved issues.
- Limited derived comparison and scan state needed to avoid duplicate issue creation and operate the checks reliably.
- Shop-level lifetime Free usage accounting, including the number of unique orders counted and one-way hashed order receipt identifiers used to count the same Shopify order only once. The receipt records do not store the raw Shopify order ID. These usage records can remain across an ordinary uninstall/reinstall so the lifetime allowance cannot be reset, and are removed when Shopify sends the store-redaction privacy request.
- The app does not store payment-card information or Shopify login credentials.
How the data is used
FP1 - Duplicate Order Check uses order data only to identify high-confidence possible duplicates, refunded or cancelled orders that may still ship, and stuck orders that remain incomplete too long. Issues appear on the app Home page for merchant review. The app does not automatically cancel, refund, fulfill, or otherwise change the affected order.
Optional email alerts
If email alerts are enabled, the app can send an internal notification to the merchant-configured address when a new issue appears. The message may include a direct link to the affected Shopify order. Issues still appear on Home when email alerts are disabled, and Fixpoint One does not receive Shopify login credentials.
FP1 - Merge Orders
Data the app uses
- Recent Shopify order identifiers, order names, dates, currency, and fulfillment status.
- Customer identifier, email address, or phone number when present on an order.
- Shipping address information needed to confirm that separate orders belong in the same shipment.
- Fulfillment-order, location, and fulfillment-service information needed to check whether Shopify allows the app to fulfill each order.
- Tracking company, tracking number, and tracking link entered by the merchant for a combined shipment.
What the app stores
- Merchant settings, matching rules, plan and usage records, and operational queue state.
- Candidate order identifiers and names, merge-group records, limited customer matching information, and shipping-address snapshots.
- Merchant-approved tracking details, fulfillment results, status records, and audit events needed to operate and troubleshoot the workflow.
- The app does not store payment-card information and does not financially combine the original Shopify orders.
How the data is used and removed
FP1 - Merge Orders uses this information only to find matching open orders, let the merchant review or automatically group exact matches, create one packing list, apply shared tracking, and fulfill the original orders when Shopify allows it. Shopify privacy webhooks are used to process customer and store data requests. App data and Shopify sessions are removed when the app is uninstalled, except for minimal eligibility or abuse-prevention history where legally permitted.
FP1 - Postcode Shipping Guard
Data the app uses
- Postal/ZIP code entered at checkout.
- Country (and optionally region) associated with the checkout address.
- Your configured rule list (blocked codes, prefixes, and optional country targeting).
- Shop information for secure authentication and app operation.
What the app stores
- Merchant settings and rule configuration (blocked codes/prefixes, optional country targeting, and message settings if applicable).
- Operational metadata needed to run the rules (for example, save timestamps and internal identifiers).
- The app does not store full customer addresses or customer profiles outside Shopify.
How checkout blocking works
FP1 - Postcode Shipping Guard evaluates the Postal/ZIP code entered at checkout against the rules you configure. If a rule matches, checkout is blocked for that destination with a clear message. This evaluation is performed only to apply your rules and prevent restricted destinations.
FP1 - Hide Payment Methods
Data the app uses
- Checkout context required to apply payment method rules (for example: available payment method names/IDs, cart total, currency, and shipping country).
- Your configured rule list (conditions, actions, and payment method matchers).
- Shop information for secure authentication and app operation.
What the app stores
- Merchant settings and rule configuration (enabled/disabled state, rule conditions, actions, and payment method matchers).
- Operational metadata needed to run the rules (for example, save timestamps and internal identifiers).
- The app does not store customer addresses or full customer profiles outside Shopify.
- The app does not process or store payment details (credit card numbers or payment credentials).
How payment customization works
FP1 - Hide Payment Methods uses Shopify Functions (Payment Customization) to apply hide, rename, and put-first operations at checkout based on your saved rules. Multiple enabled rules can apply at the same checkout when their conditions match. Conflict safeguards are deterministic: for example, hiding a method takes precedence over renaming or reordering it, and unsupported or ambiguous operations fail safely. Only the checkout context needed for the saved rules is used.
GDPR and data privacy compliance
Fixpoint One apps implement Shopify-required GDPR endpoints:
customers/data_requestcustomers/redactshop/redact
The app/uninstalled webhook is processed to remove shop configuration and access tokens.
How data access and deletion requests are handled
The amount of customer-related data held by a Fixpoint One app depends on the app. Most store data remains in Shopify, while FP1 - Merge Orders stores the limited matching, address-snapshot, tracking, and fulfillment records described above. Customer access and deletion requests should be initiated through Shopify’s privacy tools. Shopify may notify Fixpoint One apps through GDPR webhooks when action is required, and those requests are processed promptly.
If you have any questions about a privacy request or how it relates to your store’s use of Fixpoint One apps, please use the contact information below.
Contact
Email: [email protected]
Mailing address
570 Hood Road Unit 14, #1537Markham, ON L3R 4G7
Canada