Community Connect — Privacy Policy

Last updated: 23 June 2026

This Privacy Policy explains how the Community Connect team ("we", "us", the "App") — the developer of the Community Connect Shopify app — collects, uses, stores, shares, and protects personal data when a merchant installs the App and when their customers interact with it.

We act as a data processor on behalf of the merchant (the data controller) for Shopify customer data, and as a data controller for the limited account/operational data described below.

Contact: zthesuperlouis@gmail.com


1. What the App does

Community Connect gates a merchant's private Discord (and, in future, Telegram) community by customer lifetime net spend (paid orders minus refunds). It resolves each customer to a membership tier, places them in the right community role, keeps that role accurate as spend changes, and lets merchants invite past customers by email.

2. Data we access and why

We request the minimum Shopify scopes needed and access only the fields below. The App is read-only to the Shopify store (no write scopes).

DataShopify scopeWhy we need itStored?
Customer emailread_customers (protected)Send community invites; identify and look up members; honor marketing consentYes — encrypted at rest (emailEnc)
Customer name / display nameread_customers (protected)Show the member in the merchant's CRM and personalize invitesYes — encrypted at rest (nameEnc)
Email marketing consent stateread_customersOnly email invites to customers who have consentedYes (boolean)
Shopify customer IDread_customersStable key to link the customer to their community identity and reconcile stateYes
Orders & refunds (amounts)read_orders, read_all_orders (protected)Compute lifetime net spend to determine tier eligibilityWe store only the derived total (net spend + order count), not order line items
Order line items (titles, dates)read_orders, read_all_ordersShown in the merchant CRM's purchase-history viewFetched on demand, displayed to the merchant, not persisted

We do not collect or store payment card data, shipping/billing addresses, or phone numbers.

Why read_all_orders (a protected scope): tier eligibility is based on lifetime net spend; the standard read_orders scope only exposes the last 60 days of orders. Net spend would be inaccurate without the full order history.

3. Community (Discord) data

When a customer chooses to link their Discord account, they authorize us via Discord OAuth. We receive and store their Discord user ID only. We do not send the customer's Shopify email, name, or order data to Discord — we send only the role assignment for the Discord account the customer authorized. We do not persist Discord OAuth access tokens beyond the moment of placement.

4. How we use data

We do not sell personal data, use it for advertising, or use it to train machine-learning models.

5. Storage and security

6. Data sharing (subprocessors)

We share the minimum data necessary with the following subprocessors:

SubprocessorData sharedPurpose
Zeabur (self-managed VPS)All App data (hosting)Run the application + database
ResendCustomer email + name + invite linkSend community-invitation emails
DiscordDiscord user ID + role assignmentPlace members in the community

We share data with these providers only as needed to operate the App, under data-processing terms.

7. Retention and deletion

8. Your rights

Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA), customers may have the right to access, correct, delete, or port their personal data, and to withdraw consent. Customers should direct requests to the merchant (the data controller); we will assist the merchant in fulfilling them. You may also contact us at zthesuperlouis@gmail.com.

9. International transfers

Data may be processed in Singapore. Where required, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) for cross-border transfers.

10. Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

11. Contact

zthesuperlouis@gmail.com