Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how Kavach: COD & Checkout Rules ("Kavach", "we", "us", or "our") processes information when a merchant installs or uses the Kavach Shopify application.
Information we process
To provide checkout validation, payment-method customization, rule management, billing, diagnostics, and support, Kavach may process:
- Merchant and store information, including the Shopify store domain, installation status, app permissions, and plan information.
- Rule configuration supplied by the merchant, such as cart thresholds, product criteria, customer criteria, location or postal-code criteria, and payment-method selections.
- Limited order, customer, product, inventory, discount, shipping, and checkout information when required to evaluate a merchant's configured rules.
- Operational information such as synchronization status, errors, security events, and minimal webhook metadata. Raw webhook request bodies are not retained in operational logs.
- Information submitted in support requests, including contact details and the content of the request.
How we use information
We use information only to operate and secure Kavach, apply merchant-configured checkout and payment rules, synchronize Shopify Functions, provide billing and customer support, troubleshoot errors, meet legal obligations, and improve reliability. We do not sell personal information or use it for unrelated advertising.
Sharing and service providers
Information may be processed by Shopify and by service providers that support our hosting, database, email, monitoring, and infrastructure operations. We disclose only the information needed for those services or when required by law. We do not disclose merchant or customer information to independent third parties for their own marketing.
Storage, security, and retention
We use administrative, technical, and organizational safeguards designed to protect information in transit and at rest. Access is restricted to authorized personnel and service providers who need it to perform their duties.
We retain information only for as long as needed to provide the app, comply with legal obligations, resolve disputes, and enforce agreements. Operational webhook metadata is retained for limited periods based on its status. Privacy-request exports are scheduled for deletion after 30 days unless a shorter period is required. Merchant data is deleted or anonymized following a valid deletion request or app-uninstall redaction request, subject to legally required retention.
Merchant choices and privacy requests
Merchants control the rules they configure and can uninstall Kavach through Shopify. Shopify may send Kavach verified requests for customer data access, customer erasure, and shop erasure. We process these requests through Shopify's required privacy webhooks.
For questions or requests concerning access, correction, deletion, or other applicable privacy rights, contact us at support@shiviteq.co.in. We may need to verify the requester and the affected Shopify store before completing a request.
International processing
Information may be processed in countries other than the country where a merchant or customer is located. Where required, we use appropriate safeguards for international data transfers.
Children's privacy
Kavach is a business service for Shopify merchants and is not directed to children. We do not knowingly collect children's personal information for our own purposes.
Changes to this policy
We may update this policy to reflect changes to Kavach, our practices, or legal requirements. We will publish the revised policy on this page and update the date above.
Contact
Shiviteq
Email: support@shiviteq.co.in