Privacy Policy

FireAgent Quantity Ladder (Shopify app) · Effective 25 July 2026

This policy explains what data the FireAgent Quantity Ladder Shopify app collects, stores and shares. It covers the app only. It does not cover fireagent.co.uk, which is a separate retail business operated by the same developer and has its own privacy policy.

Who we are

The app is published by FireAgent, a UK business, which is the data controller for the limited information described below. Questions, access requests and deletion requests: techsupport@fireproai.com.

What the app does

FireAgent Quantity Ladder has two parts. A settings panel renders inside Shopify admin on the discount details page, where the merchant types quantity tiers for a discount of the app's type. A Shopify discount function then applies the deepest matching tier to each qualifying cart line in cart and checkout. Both parts run on Shopify's own infrastructure. The discount function receives only the cart line data Shopify passes to it (product, variant, quantity and price), has no network access, and stores nothing.

Data the app stores

When a merchant installs the app, we store exactly two things about the installation: the store's .myshopify.com domain, and the offline Shopify Admin API access token (with its refresh token, expiry timestamps and granted scopes) that Shopify issues at the end of the OAuth install. These are held in a single record per store (the ShopifyAppToken model) in a managed PostgreSQL database that is encrypted at rest and access-restricted to the application. The token is used only to call the Shopify Admin API for the store that granted it, under the scopes it approved (write_products, write_discounts). Token values are never written to logs.

Discount configuration — the quantity tiers themselves, and any optional per-product tiers — is not stored by us. It is written as metafields on the merchant's own Shopify store (the discount's $app/function-configuration metafield, and the product-level $app:pricing/quantity_breaksmetafield) and remains under the merchant's control in their own Shopify admin.

Customer data: none is collected

The app does not collect, store, process or transmit personal data about a merchant's customers. It does not read customer records, orders, email addresses, names or addresses; it does not request the Shopify scopes that would allow it to. No customer data ever leaves the merchant's Shopify store as a result of installing this app.

Mandatory compliance webhooks

The app subscribes to Shopify's mandatory compliance topics — customers/data_request, customers/redact and shop/redact— at a single endpoint that verifies Shopify's HMAC signature on every request. Because the app holds no customer personal data, a data request returns nothing to export and a customer redaction request has nothing to erase; the app verifies and acknowledges each of those notifications. A shop/redact notification does erase data: on receiving one we delete the store's installation record — its domain and stored tokens — from our database.

Uninstalling

The app also subscribes to app/uninstalled, which it verifies and acknowledges. On uninstall Shopify revokes the access token, so it can no longer be used to reach the store, and we delete the installation record (store domain plus the now-revoked token) from our database. Reinstalling the app creates a fresh record. A merchant may also ask us to confirm that deletion, or request it directly, by emailing techsupport@fireproai.com; we action deletion requests within 30 days. Metafields written to the merchant's own store stay on that store and can be removed by the merchant at any time.

Sharing and sub-processors

We do not sell, rent or share app data, and we do not use it for advertising or profiling. The only third parties involved are the infrastructure providers that run the app: Shopify (the platform the app runs on), our hosting provider and our managed database provider, each acting on our instructions. We disclose data otherwise only where the law requires it.

Analytics and cookies

The app sets no cookies of its own, and neither the discount function nor the in-admin settings panel performs any analytics or tracking. The two web pages the app serves — this policy and the app home page at /shopify-app — are served by the same web application as our retail website, which loads a cookieless website-analytics script (Ahrefs Web Analytics). It records aggregate page views only, sets no cookies, and does not identify individual visitors, merchants or customers.

Retention

The installation record is kept for as long as the app is installed. It is deleted when the app is uninstalled, when we receive a shop/redact notification for the store, or on request. We keep short-lived operational server logs of app requests (store domain, webhook topic, timestamp and outcome) for troubleshooting; these contain no customer data and no token values.

Your rights

Under the UK GDPR and the Data Protection Act 2018 you may ask us to confirm what data we hold about your installation, to correct it, or to delete it. Email techsupport@fireproai.com and we will respond within one month. You also have the right to complain to the UK Information Commissioner's Office.

Changes to this policy

If we change what the app stores or how it is handled, we will update this page and change the effective date shown above.