01
Summary
This summary is not a substitute for the sections below, but nothing below contradicts it.
- PromoProof reads your Shopify discounts and products. It never edits either.
- It requests no customer access, no order access, and no write scopes of any kind.
- Test carts are built through Shopify’s Storefront Cart API. No order is created, no payment is taken, and no inventory is changed.
- What is stored is your shop’s domain and plan, the session needed to keep the app installed, and the results of checks that have run.
- No personal data of your customers is collected at all, and everything that is stored is held inside the European Union.
02
Who this policy is from
PromoProof is built and run by Huub Ourik Hoegen, an independent developer established in the Netherlands. It is not a registered company, and there is no support desk behind it — messages reach the person who writes the code.
In this policy, “PromoProof”, “we” and “the app” refer to that developer and the software provided at promoproof.app. “You” means the merchant who installs the app on a Shopify store.
For anything in this policy, including a request about your data, write to info@promoproof.app.
03
What PromoProof accesses
When you install the app, Shopify asks you to approve a fixed set of permissions. PromoProof requests these and no others:
read_discounts— to read the discounts you have already created, so they can be explained and tested. Discounts are never created, edited, or deleted.read_products— to find real products to build test carts from. A discount can only be tested against a cart that could actually exist in your store.unauthenticated_read_product_listings,unauthenticated_read_checkoutsandunauthenticated_write_checkouts— the scopes required to mint a storefront access token and drive the Cart API. This is the mechanism that lets PromoProof observe your real discount engine.
The unauthenticated_write_checkouts scope permits creating and updating a cart. A cart is not an order. PromoProof stops before checkout: nothing is submitted, nothing is paid for, and nothing is reserved.
What comes back through these APIs is your discount configuration and your product catalogue — commercial data about your store. None of it is personal data about a person.
04
What it does not access
These permissions are deliberately not requested, so they cannot be used:
- No customer scopes. PromoProof does not request
read_customersor any other customer permission. - No order scopes. It does not read, create, or modify orders.
- No write scopes. It cannot change anything in your store — not discounts, not products, not inventory, not settings.
Because these permissions are never granted, the app has no technical route to this data even in the event of a bug.
05
What you give us directly
Almost nothing, because there is almost nothing to give. PromoProof has no sign-up form, no password, and no profile page. You authenticate through Shopify, and the app receives what Shopify passes it at install: your shop’s myshopify domain and its current Shopify plan.
The only information you supply directly is whatever you choose to put in an email to info@promoproof.app. That is used to answer you and for nothing else.
Staff names and email addresses
The session table PromoProof uses comes from Shopify’s own app template, and that template defines optional columns for a staff member’s first name, last name and email address. PromoProof uses offline sessions only, and Shopify does not attach staff details to an offline session, so those columns are never written to. We have checked: no row contains a value in any of them.
They are named here rather than left unmentioned, because the columns exist in the schema and we would rather say plainly that they stay empty than have you find them and wonder.
06
Your customers' data
PromoProof does not process your customers’ personal data. It does not read customer records, email addresses, names, addresses, or purchase histories, and it holds no permission that would let it.
It also has no presence on your storefront. There is no script tag, no theme extension, no pixel, and no cookie set on any of your customers’ devices. Your customers never interact with PromoProof and are never observed by it.
Some discounts are restricted to particular customers or customer segments. To know whether such a discount can be tested, PromoProof needs to know only that a restriction of that kind exists — not who it applies to. It reads the shape of the restriction, which is enough to mark the discount as untestable by a signed-out cart, and requests no customer access at all.
Test carts are built without a customer identity. They are anonymous carts, which is also why customer-segment discounts cannot be verified and are reported as not tested rather than guessed at.
The app implements Shopify’s mandatory compliance webhooks (customers/data_request, customers/redact, and shop/redact). Since no customer data is collected, a customer data request or redaction request has no customer records to return or erase.
07
What is stored
PromoProof stores the following, and nothing else:
- Your shop’s myshopify domain and its current plan, which identify the store and set the limits that apply to it.
- A Shopify offline session token, which is what keeps the app installed and able to talk to Shopify on your behalf.
- The results of checks — which promotion was tested, when it ran, and what was found. This is what makes test history and the store health overview possible.
- Reports produced by Autotest, the daily automatic check on the Pro plan.
- A marker of which alerts you have already seen, so the app does not show you the same finding twice as though it were new.
Test results describe your promotions and the carts PromoProof constructed. They do not describe your customers, because no customer is involved in a test.
This website
The marketing site you are reading is separate from the app, and collects nothing. It has no contact form, no analytics, no advertising, and sets no tracking cookies.
One thing is saved on your own device: if you switch this site between its light and dark theme, that choice is kept in your browser’s local storage under promoproof-theme so the page doesn’t change back on your next visit. It never leaves your browser, and clearing your site data removes it.
08
Logs and analytics
PromoProof runs no analytics and no behavioural tracking, either in the app or on this website. There is no product analytics service, no session recording, no heatmap, and no advertising network.
Nor does the app keep a separate record of how you move around it — which screens you opened, what you clicked, how long you stayed. The stored check results listed above are the only record of your use of PromoProof, and they exist because they are the product: they are what test history and the store health overview are made of.
09
Why it is stored
Data is stored only to provide the service you installed the app for: keeping you authenticated, running the checks you ask for, showing you the results and their history, and enforcing the limits of your plan.
There is no secondary purpose. It is not used for advertising, not sold, not shared for anyone else’s benefit, not used to train any model, and not used to build a profile of you or your store beyond what the product itself displays back to you.
11
Where your data is held
The operator of PromoProof is established in the Netherlands, inside the European Union, and so is the infrastructure the app runs on:
- The application is hosted on Railway in Amsterdam, the Netherlands.
- The database is Neon Postgres in Frankfurt, Germany.
Both regions are within the EU, so no personal data is transferred outside the European Union and no transfer mechanism for third countries is required.
Shopify is a separate controller of your store’s data and operates its own infrastructure under its own terms; where Shopify holds your data is described in Shopify’s privacy policy, not this one.
12
Retention and deletion
Stored checks are deleted six months after they run. The single exception is the most recent check of each promotion, which is kept for as long as the app is installed — that result is not history, it is that promotion’s current state, and deleting it would empty the screen you use the app for.
Your session and your shop’s domain and plan are kept for as long as the app is installed, because they are what keeps it installed.
When you uninstall PromoProof, Shopify sends a shop/redact webhook and your shop’s data is erased on receipt of it. Shopify sends that webhook 48 hours after uninstallation. There is no separate archive and no backup copy kept beyond that point.
You can also ask for deletion at any point without uninstalling, by writing to info@promoproof.app.
13
Billing data
Paid plans are charged entirely through Shopify App Pricing. You approve the charge on Shopify’s own plan page and it appears on your regular Shopify invoice alongside your other apps.
PromoProof never sees, receives, or stores card numbers or any other payment details. There is no payment form anywhere in the app or on this website. What the app stores about your plan is only which plan you are on, so it knows which limits to apply.
14
Your rights
Depending on where you are established, you may have the right to access, correct, export, or erase the data described in this policy, and to object to or restrict its processing.
To exercise any of these, contact info@promoproof.app. If you believe your data has been handled improperly, you may also complain to your local data protection authority. In the Netherlands, where the operator is established, that is the Autoriteit Persoonsgegevens.
15
Security
Access to your store is limited by the scopes listed above, which are the smallest set the product can function with. The app holds no ability to change your store, so the worst case for a compromised session is disclosure of your discount and product configuration — not modification of it.
Sessions are stored server-side and communication with Shopify uses encrypted connections.
16
Changes to this policy
If the app’s behaviour changes in a way that affects this policy — a new scope, a new subprocessor, a new category of stored data — this page is updated and the date at the top changes with it.
Any change that expands what PromoProof accesses would require you to approve the new permissions in Shopify before it could take effect.
17
Contact
Questions about this policy, or about what PromoProof does with your data, can go to info@promoproof.app. It reaches Huub Ourik Hoegen directly, and it is the right address for a data access, correction, or deletion request as well as for anything else.
See also the Terms of Service, which cover the use of the service itself and the limits of what its results mean.