Privacy policy
Last updated
This policy covers https://saliapps.com — this website — and explains, separately, how our Shopify apps handle merchant and customer data. If you are a merchant looking specifically for what an app stores, jump to Data our apps process.
Sali Digital LLC ("we", "us") is the data controller for this website. You can reach us at privacy@saliapps.com.
What this website collects
We collect as little as we can get away with, because storing data we do not need is a liability rather than an asset.
- Contact form submissions. Your name, email address, an optional store URL, the topic you chose and your message. We keep these so we can reply to you and so we can see what people are actually asking about.
- Newsletter signups. Your email address and which part of the site you signed up from.
- A hashed identifier for the request. When you submit a form we store a one-way hash of your IP address, salted with a secret only our server knows. It lets us spot a flood of submissions from one source without keeping your address. It cannot be reversed back into an IP.
- A session cookie, but only if you are us. The admin dashboard sets one httpOnly cookie for the site owner. If you are reading this, that is not you.
We do not run advertising trackers, we do not sell or share anything with data brokers, and we do not build a profile of you across sites.
What this website does not collect
- No third-party analytics or advertising cookies are set by default. If we ever add analytics, it will be a cookieless, self-hosted tool, and this section will say so before it happens.
- No payment details are ever entered on this site. App billing runs entirely through Shopify.
- We do not fingerprint your browser or device.
Cookies
One cookie, and only for the site owner's admin session. See the cookie policy for the full detail.
Data our apps process
Our Shopify apps run on infrastructure we control and operate under a data processing agreement with the merchant — the merchant is the controller, we are the processor. Each app's specifics are documented on that app's own privacy page:
In summary, across every app we publish:
- We request the narrowest Shopify access scopes each feature actually needs, and we expand them only when a feature requires it.
- We implement all three of Shopify's mandatory compliance webhooks —
customers/data_request,customers/redactandshop/redact— so a merchant can service a customer's access or erasure request through Shopify itself. - Access tokens are encrypted at rest and never logged.
- Free-text fields that may contain personal information are encrypted at rest.
- Survey responses are retained for as long as the app is installed, so historical reporting does not silently truncate. They are deleted when the app is uninstalled, and on a verified customer erasure request.
Who else touches your data
We use a small number of sub-processors. Each is contractually bound to protect the data it handles.
| Sub-processor | What they do | Where |
|---|---|---|
| Hostinger International Ltd. | Application and database hosting | European Union |
| Shopify Inc. | Merchant authentication, billing, and app delivery | Canada / United States |
| Resend, Inc. | Transactional email delivery | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
We will update this list before adding a sub-processor, not afterwards.
How long we keep things
- Contact submissions: kept while they remain useful for support history, and deleted on request.
- Newsletter signups: kept until you unsubscribe.
- App data: see the relevant app's privacy page. Survey responses are retained for as long as the app is installed, so historical reporting does not silently truncate. They are deleted when the app is uninstalled, and on a verified customer erasure request.
- After an app is uninstalled, remaining store data is erased within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, or delete the personal data we hold about you, and to object to processing. Email privacy@saliapps.com and we will action it. We will not charge you for it and we will not make you explain why.
If you are an end customer of a store that uses one of our apps, the merchant is your first point of contact — they control the data, we only process it on their behalf. We will help them respond.
International transfers
Our servers are in the European Union. Some sub-processors are in the United States and Canada; transfers to them rely on Standard Contractual Clauses or an equivalent recognised mechanism.
Security
We keep the database and cache reachable only from the application server itself, never from the public internet. Passwords are hashed with bcrypt. Sessions are signed and httpOnly. Backups are encrypted before they leave the server. No system is perfectly secure, but these are the specific measures in place rather than a general assurance.
Changes
If we change this policy materially, we will update the date at the top and, where the change affects how we handle data you have already given us, tell you directly.
Contact
privacy@saliapps.com — Sali Digital LLC.