Legal

Privacy Policy

Last updated: June 2026

1. Introduction

MerchantKits ("we", "us", "our") operates the SignShield application available on the Shopify App Store. This Privacy Policy explains how we collect, use, store, and protect information when you use SignShield. By installing or using SignShield, you agree to the practices described in this policy.

If you have questions about this policy, please contact us at support@merchantkits.com.

2. Who We Are

MerchantKits is operated by SignShield International. Our services are hosted in the European Union on Google Cloud Platform (europe-west1 region, Belgium). Our website is merchantkits.com.

3. Information We Collect

We collect information necessary to provide the SignShield service:

Merchant account data

Your Shopify store name, domain, email address, and the access tokens required to operate the app on your behalf.

Order data

Shopify order IDs, and customer names and email addresses associated with signing requests triggered by those orders.

Documents

PDFs you upload as document templates, and the completed signed documents (with Certificate of Completion) generated through the service.

Signature data

Drawn or typed signatures, initials, and other field values entered by signers during the signing ceremony.

Technical data

IP addresses, browser and device information, and timestamps recorded during the signing ceremony. This data forms part of the legally significant audit trail and Certificate of Completion.

Usage data

Basic app usage patterns (e.g., features used, error logs) to help us improve the service.

4. How We Use Your Information

We use the information we collect to:

  • · Provide and operate the SignShield signing service
  • · Send signing request and confirmation emails to signers on your behalf
  • · Generate PDF Certificates of Completion and store signed documents
  • · Enable the public document verification feature
  • · Update Shopify order notes and metafields after signing
  • · Improve and maintain the service

We do not sell your data. We do not use your data for advertising.

5. Data Storage and Security

All data is stored on Google Cloud Platform in the europe-west1 region (Belgium, EU). Data is encrypted at rest and in transit using industry-standard TLS encryption. We follow industry-standard security practices and conduct regular security reviews.

6. Third-Party Services

We share data only as necessary with the following third-party service providers:

Shopify
App platform provider. Your use of Shopify is governed by Shopify's own Privacy Policy.
Google Cloud
Infrastructure provider for storage, database, and compute. All data stored in the EU (europe-west1).
Resend
Email delivery service. Signer email addresses are passed to Resend solely to deliver signing request and confirmation emails.

We do not share your data with any other third parties.

7. Data Retention

Documents and signing data are retained while your merchant account is active. Upon account closure or app uninstallation, your data will be deleted within 30 days. You may request earlier deletion by contacting support@merchantkits.com.

8. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights regarding your personal data:

  • · Access: Request a copy of the personal data we hold about you
  • · Rectification: Request correction of inaccurate or incomplete data
  • · Erasure: Request deletion of your personal data
  • · Restriction: Request restriction of processing in certain circumstances
  • · Portability: Receive your data in a portable format
  • · Objection: Object to processing based on legitimate interests

To exercise any of these rights, contact support@merchantkits.com. You also have the right to lodge a complaint with your local data protection supervisory authority.

9. Signer Rights

Individuals who sign documents via SignShield may contact us at support@merchantkits.com to request access to or deletion of their signing data. Please note that some data may be retained by the merchant who requested the signature, as part of their legal records.

10. Cookies

SignShield uses minimal cookies. We set only the session cookies required for authentication within the Shopify admin. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

11. Shopify App Store

SignShield is distributed through the Shopify App Store. We request only the Shopify API scopes strictly required to provide the service. We comply with Shopify's Partner Program requirements, API terms, and privacy guidelines.

12. Children's Privacy

SignShield is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately at support@merchantkits.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify merchants via email of any material changes. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of SignShield after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: