Last updated: 23 June 2026
This Privacy Policy explains how the Community Connect team ("we", "us", the "App") — the developer of the Community Connect Shopify app — collects, uses, stores, shares, and protects personal data when a merchant installs the App and when their customers interact with it.
We act as a data processor on behalf of the merchant (the data controller) for Shopify customer data, and as a data controller for the limited account/operational data described below.
Contact: zthesuperlouis@gmail.com
Community Connect gates a merchant's private Discord (and, in future, Telegram) community by customer lifetime net spend (paid orders minus refunds). It resolves each customer to a membership tier, places them in the right community role, keeps that role accurate as spend changes, and lets merchants invite past customers by email.
We request the minimum Shopify scopes needed and access only the fields below. The App is read-only to the Shopify store (no write scopes).
| Data | Shopify scope | Why we need it | Stored? |
|---|---|---|---|
| Customer email | read_customers (protected) | Send community invites; identify and look up members; honor marketing consent | Yes — encrypted at rest (emailEnc) |
| Customer name / display name | read_customers (protected) | Show the member in the merchant's CRM and personalize invites | Yes — encrypted at rest (nameEnc) |
| Email marketing consent state | read_customers | Only email invites to customers who have consented | Yes (boolean) |
| Shopify customer ID | read_customers | Stable key to link the customer to their community identity and reconcile state | Yes |
| Orders & refunds (amounts) | read_orders, read_all_orders (protected) | Compute lifetime net spend to determine tier eligibility | We store only the derived total (net spend + order count), not order line items |
| Order line items (titles, dates) | read_orders, read_all_orders | Shown in the merchant CRM's purchase-history view | Fetched on demand, displayed to the merchant, not persisted |
We do not collect or store payment card data, shipping/billing addresses, or phone numbers.
Why read_all_orders (a protected scope): tier eligibility is
based on lifetime net spend; the standard read_orders scope only
exposes the last 60 days of orders. Net spend would be inaccurate without the full order
history.
When a customer chooses to link their Discord account, they authorize us via Discord OAuth. We receive and store their Discord user ID only. We do not send the customer's Shopify email, name, or order data to Discord — we send only the role assignment for the Discord account the customer authorized. We do not persist Discord OAuth access tokens beyond the moment of placement.
We do not sell personal data, use it for advertising, or use it to train machine-learning models.
We share the minimum data necessary with the following subprocessors:
| Subprocessor | Data shared | Purpose |
|---|---|---|
| Zeabur (self-managed VPS) | All App data (hosting) | Run the application + database |
| Resend | Customer email + name + invite link | Send community-invitation emails |
| Discord | Discord user ID + role assignment | Place members in the community |
We share data with these providers only as needed to operate the App, under data-processing terms.
customers/redact — we delete that customer's stored data.shop/redact — we delete all of the shop's stored data.customers/data_request — the data we hold about the customer (tier, net spend,
identity links) is available to the merchant through the in-app Member CRM to fulfill the
request.Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA), customers may have the right to access, correct, delete, or port their personal data, and to withdraw consent. Customers should direct requests to the merchant (the data controller); we will assist the merchant in fulfilling them. You may also contact us at zthesuperlouis@gmail.com.
Data may be processed in Singapore. Where required, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) for cross-border transfers.
We may update this policy; material changes will be reflected by the "Last updated" date above.
zthesuperlouis@gmail.com