Lead Rescue Privacy Policy
Last Updated: January 2025
Lead Rescue ("we," "our," or "the App") is committed to protecting the privacy of merchants and their customers. This policy explains how we collect, use, and protect data.
1. Data We Collect
From Merchants:
- Shopify store URL and authentication tokens
- App settings and preferences
From Store Customers (via Shopify API):
- Email addresses
- Names
- Email marketing consent status
- Order count
- Customer IDs
2. How We Use Data
We use customer data solely to:
- Identify customers eligible for email marketing subscription
- Update email marketing consent status via Shopify's API
- Track subscription activity for merchant reporting
- Attribute revenue to rescued subscribers
We DO NOT:
- Sell or share customer data with third parties
- Send emails directly to customers
- Store customer data outside of what's necessary for app functionality
- Access payment information, addresses, or other sensitive data
3. Email Capture Feature
When the Email Capture feature is enabled in your theme, Lead Rescue monitors email input fields across your website. When visitors type their email address into any field (even if they don't submit the form), we capture and add it to your Shopify customer list.
Data Handling:
- Email addresses are transmitted through Lead Rescue servers via encrypted HTTPS connection
- We immediately add them to your Shopify customer database
- We do NOT store emails in our own database (pass-through only)
- Emails are only used for adding customers to your store
- Customers added this way are eligible for email marketing subscription via Lead Rescue's automated process
- Captured customers are tagged with "lead-rescue-captured" for tracking
Merchant Responsibilities:
- Merchants must ensure their own privacy policy discloses email capture practices
- Merchants are responsible for compliance with local laws regarding email collection
- The feature can be disabled at any time in the theme editor
4. Compliance & Ethical Practices
Lead Rescue is built with compliance as a priority:
GDPR Compliance:
- We never subscribe customers with REDACTED status (those who exercised their "right to be forgotten")
- All shop data is deleted when the app is uninstalled
- Merchants can request data deletion at any time
Consent Respect:
- We never re-subscribe customers who explicitly unsubscribed
- We respect double opt-in flows (PENDING status customers are not modified)
- We only target customers who have not made an explicit consent decision
Data Minimization:
- We only access data necessary for app functionality
- We do not store unnecessary customer information
- Subscription logs are maintained for merchant transparency
5. Data Storage & Security
- Data is stored securely on Railway infrastructure
- Database connections are encrypted
- Access tokens are stored securely per Shopify requirements
- We do not store customer payment information
6. Data Retention
- Subscription logs are retained for merchant reporting
- All shop-specific data is permanently deleted upon app uninstall
- Merchants may request data deletion at any time
7. Merchant Responsibilities
By using Lead Rescue, merchants acknowledge:
- They are responsible for compliance with applicable laws in their jurisdiction
- The app uses single opt-in for subscriptions
- They should review their local email marketing regulations
- Customers can unsubscribe at any time through standard email unsubscribe links
8. Third-Party Services
Lead Rescue integrates with:
- Shopify Admin API (to access customer data and update consent)
- Railway (hosting infrastructure)
We do not integrate with or share data with advertising networks, analytics services, or other third parties.
9. Changes to This Policy
We may update this policy periodically. Continued use of the app constitutes acceptance of any changes.
10. Contact
For privacy questions or data requests:
Email: up-and-down@thechiputt.com
11. Shopify Data Protection
As a Shopify app, we comply with Shopify's API Terms of Service and data protection requirements, including handling of customer data request and deletion webhooks.
© 2025 Lead Rescue. All rights reserved.