1. Introduction
MerchantKits ("we", "us", "our") operates the SignShield application available on the Shopify App Store. This Privacy Policy explains how we collect, use, store, and protect information when you use SignShield. By installing or using SignShield, you agree to the practices described in this policy.
If you have questions about this policy, please contact us at support@merchantkits.com.
2. Who We Are
MerchantKits is operated by SignShield International. Our services are hosted in the European Union on Google Cloud Platform (europe-west1 region, Belgium). Our website is merchantkits.com.
3. Information We Collect
We collect information necessary to provide the SignShield service:
Merchant account data
Your Shopify store name, domain, email address, and the access tokens required to operate the app on your behalf.
Order data
Shopify order IDs, and customer names and email addresses associated with signing requests triggered by those orders.
Documents
PDFs you upload as document templates, and the completed signed documents (with Certificate of Completion) generated through the service.
Signature data
Drawn or typed signatures, initials, and other field values entered by signers during the signing ceremony.
Technical data
IP addresses, browser and device information, and timestamps recorded during the signing ceremony. This data forms part of the legally significant audit trail and Certificate of Completion.
Usage data
Basic app usage patterns (e.g., features used, error logs) to help us improve the service.
4. How We Use Your Information
We use the information we collect to:
- · Provide and operate the SignShield signing service
- · Send signing request and confirmation emails to signers on your behalf
- · Generate PDF Certificates of Completion and store signed documents
- · Enable the public document verification feature
- · Update Shopify order notes and metafields after signing
- · Improve and maintain the service
We do not sell your data. We do not use your data for advertising.
5. Data Storage and Security
All data is stored on Google Cloud Platform in the europe-west1 region (Belgium, EU). Data is encrypted at rest and in transit using industry-standard TLS encryption. We follow industry-standard security practices and conduct regular security reviews.
6. Third-Party Services
We share data only as necessary with the following third-party service providers:
We do not share your data with any other third parties.
7. Data Retention
Documents and signing data are retained while your merchant account is active. Upon account closure or app uninstallation, your data will be deleted within 30 days. You may request earlier deletion by contacting support@merchantkits.com.
8. Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights regarding your personal data:
- · Access: Request a copy of the personal data we hold about you
- · Rectification: Request correction of inaccurate or incomplete data
- · Erasure: Request deletion of your personal data
- · Restriction: Request restriction of processing in certain circumstances
- · Portability: Receive your data in a portable format
- · Objection: Object to processing based on legitimate interests
To exercise any of these rights, contact support@merchantkits.com. You also have the right to lodge a complaint with your local data protection supervisory authority.
9. Signer Rights
Individuals who sign documents via SignShield may contact us at support@merchantkits.com to request access to or deletion of their signing data. Please note that some data may be retained by the merchant who requested the signature, as part of their legal records.
10. Cookies
SignShield uses minimal cookies. We set only the session cookies required for authentication within the Shopify admin. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
11. Shopify App Store
SignShield is distributed through the Shopify App Store. We request only the Shopify API scopes strictly required to provide the service. We comply with Shopify's Partner Program requirements, API terms, and privacy guidelines.
12. Children's Privacy
SignShield is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately at support@merchantkits.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify merchants via email of any material changes. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of SignShield after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: