Skip to document
STUDIO8022 / CHECKOUTPILOT

CheckoutPilot — Privacy notice

Version 2026-10-04 · David Duff, trading as Studio8022

← Main websiteAll app agreementsPrivacyService termsData processingBusiness details

This notice covers CheckoutPilot and related support. Last updated 4 October 2026. Our separate general notice covers the Studio 8022 website and PostcodePilot.

Who is responsible

CheckoutPilot is provided by David Duff, trading as Studio 8022, Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus. Contact support@studio8022.com for support or privacy requests.

Information we receive from Shopify

To authenticate the app, we store the shop domain, Shopify access and refresh tokens, granted permissions and session expiry information. Depending on the session Shopify supplies, this can include an authorised staff member’s account identifier, name, email address, language and account-role information. Tokens are credentials used by our server, not information that you should send to support.

We read product and variant information for rule selection and offers, payment customisation and validation settings, store compatibility information and the app subscription status needed to determine plan access. We store rule drafts, their revisions and reviewed, current or previous release configuration and recovery status. These may contain product or variant identifiers and payment-method names. We do not maintain a separate customer database, order history or payment-card database.

Checkout and storefront processing

Our payment and cart-validation Functions execute within Shopify. Shopify supplies the relevant cart, product, amount, currency, quantity, country and available payment-method information to evaluate merchant rules. CheckoutPilot does not act as a payment provider, collect card numbers or security codes, take deposits or settle payments.

The optional offer block uses Shopify product information and Shopify’s cart endpoints in the customer’s browser. It adds a product only after the customer chooses to add it. It does not send customer cart contents to a CheckoutPilot analytics service or install advertising trackers. Shopify and the merchant’s storefront operate their own services and may use their own cookies.

Information you provide and technical records

We receive the rules and settings you save and any information you choose to send to support. Please do not include passwords, payment credentials or unnecessary customer information in messages or rule names. Support correspondence includes your email address and message contents.

Hosting infrastructure processes connection data, including IP addresses, to deliver and protect the service. Routine HTTP access logging is not enabled for our public website or app proxy. Application diagnostic logs can contain operational events and shop identifiers; we do not intentionally record access tokens, card details or customer webhook bodies. CheckoutPilot does not use advertising analytics or sell personal information.

Why we use information

We use account, subscription and configuration information to provide the service, authenticate authorised staff, enforce plan access, apply merchant rules, recover from faults and answer support requests. We rely on the service relationship for providing the app and on legitimate interests for proportionate security, maintenance and support. Information may also be retained to meet a legal obligation.

We are responsible for our merchant relationship and support records. Where we process personal information on a merchant’s behalf to operate the integration, the merchant remains responsible for its customer notices and lawful instructions. Rules make checkout decisions according to the merchant’s configuration; we do not use this information for advertising, unrelated profiling or training AI models.

Providers and location

OVHcloud hosts the app, website and support email service. Shopify provides the platform, authentication, checkout execution and app subscription facilities. The operator is based in Cyprus. Provider services can involve processing outside Cyprus or the European Economic Area; see Shopify’s privacy policy and OVHcloud’s data-protection information. We restrict access to the people and providers needed to operate and support the service.

CheckoutPilot’s database, credentials and server-side recovery snapshots are kept on encrypted storage on our VPS. App-level snapshots and the existing OVHcloud recovery arrangements protect recovery copies under restricted access. Encryption and access controls reduce risk but do not guarantee that incidents cannot occur.

Retention and deletion

We retain operational account and rule information while the app is installed and needed to provide the service. On receipt and successful processing of Shopify’s authenticated uninstall or shop-redaction event, we delete that shop’s sessions, saved drafts and release state from the active app database. Delivery or processing failures can delay deletion; we investigate failures rather than treating a failed callback as completed. Uninstalling also removes access through Shopify. Shopify manages its own platform and subscription records separately.

Recovery snapshots can temporarily contain information removed from the active database. The scheduled backup process retains the newest seven recovery points and replaces older points when it runs successfully. Separate deployment or incident snapshots are restricted to recovery and retained while the relevant verification or investigation is open, then reviewed for removal. They are not used to resume an uninstalled shop’s service. Applicable deletions must be reapplied before any recovered database returns to service. Contact us if a deletion request needs to include recovery copies.

We keep support correspondence while needed to resolve the enquiry and related follow-up, normally no longer than 12 months after resolution, unless an ongoing dispute or legal obligation requires longer retention. Diagnostic records are restricted to troubleshooting and security; contact us about records relating to your shop.

Shopify’s customer-data and customer-redaction callbacks are authenticated and handled without retaining their customer payloads. There are no stored customer cart or order records in CheckoutPilot to export or erase. Information voluntarily included in support messages is handled separately through the support contact.

Your choices and rights

You can edit saved rules in the app and uninstall it through Shopify. Required permissions are necessary for the corresponding functionality. Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of personal information, or object to processing. We may need to verify your identity. Customers should normally contact the merchant whose store they used. You may raise concerns with the competent data-protection authority, including the Commissioner for Personal Data Protection in Cyprus.

Changes to this notice

We will update this notice when our data handling changes and communicate material changes where required. Questions can be sent to support@studio8022.com.

Your app agreement

CheckoutPilot service terms · Data-processing agreement · Providers and integrations · All app agreements

This notice explains processing; it is not blanket consent to unrelated processing or marketing. Mandatory rights are unaffected.

David Duff, trading as Studio8022
Asprou Potamou 1, Oikia 2, Agios Georgios Peyias, 8570, Cyprus
support@studio8022.com

Legal & privacy · Help & support · Main website

Independent of Shopify.