Merchant information
When a merchant installs Country Shield, we process the permanent Shopify store domain, granted access scopes, encrypted Shopify access and refresh tokens, subscription state, app setup progress, saved protection rules, and optional encrypted Cloudflare connection credentials.
Storefront visitor information
Country Shield processes a visitor's public IP address in memory to make a location and network decision. We do not create an individual visitor profile or retain a request-by-request IP log in the Country Shield application database.
For operational reporting, Country Shield stores aggregate counts grouped by merchant store, hour, country, rule reason, and action.
How information is used
- Authenticate the Shopify app and keep approved access current.
- Load, save, and enforce merchant protection rules.
- Return allow, block, redirect, or challenge decisions to the storefront extension.
- Provide aggregate analytics to entitled merchants.
- Sync supported rules to Cloudflare when a Premium merchant connects a zone.
- Operate Shopify billing and diagnose service or integration errors.
Retention and deletion
Aggregate protection events are retained for the configured retention period, currently 90 days, and may be purged earlier. Shopify installation data is retained while the app is installed. Shopify's mandatory shop-redaction event deletes data tied to the uninstalled shop after the required waiting period.
Security
Shopify and Cloudflare tokens are encrypted at rest. Administrative interfaces require Shopify session-token authentication or separate backend credentials. No method of storage or transmission is perfectly secure, but Country Shield limits stored visitor data and restricts operational access.
Privacy requests
Country Shield does not hold customer-account records. Shopify customer data-request and customer-redaction webhooks are acknowledged, and shop-redaction removes merchant data. Questions or requests can be sent to [email protected].