Privacy Policy
Effective date: September 4, 2026 Applies to: Postpage and other apps published by Fuji Apps (“we”, “us”)
Fuji Apps builds apps for Shopify merchants. This policy explains what data our apps collect, why, and how it is handled. We keep it short on purpose: we collect as little as the app needs to work.
What Postpage collects
When a merchant installs Postpage, we store:
- Store identity. The store’s
.myshopify.comdomain and the access token Shopify issues to the app. The token lets the app write its own settings to the store and is never used for anything else. - Block settings. The text, links, and layout the merchant configures in the Postpage editor. This is the merchant’s own content.
- Survey answers. When a merchant enables the survey block and a customer answers it on the Thank you or Order status page, we store the chosen answer, the page it came from, the order’s Shopify ID, and a timestamp.
We do not collect customer names, email addresses, phone numbers, addresses, payment details, or browsing behavior. The survey block does not read any customer field; the only link to an order is Shopify’s internal order ID, which is meaningless outside the merchant’s own store.
What we don’t do
- We do not sell data, share it with advertisers, or use it to build profiles.
- We do not track customers across stores or sites.
- We do not send marketing email to customers. Merchants may contact their own customers through their own channels.
Where data lives
Our apps run on Vercel and store data in a Neon PostgreSQL database hosted in the United States (AWS us-east-1). Data is encrypted in transit (TLS) and at rest by the hosting providers.
How long we keep it
- Store settings and survey answers are kept while the app is installed.
- When a merchant uninstalls the app, Shopify’s access token is deleted immediately. Settings and survey answers are deleted when Shopify sends the shop redaction request, at the latest 48 hours after uninstall, or sooner on request.
- We honor Shopify’s mandatory privacy webhooks (
customers/data_request,customers/redact,shop/redact). Because we hold no customer personal data, customer requests are acknowledged with nothing to return or erase.
Merchant and customer rights
Merchants can export or delete their data at any time by emailing us. Customers who want to exercise rights under GDPR, CCPA, or similar laws should contact the merchant they bought from; the merchant can forward the request to us and we will act on it within 30 days.
Cookies
Our apps run inside the Shopify admin and use Shopify’s session tokens rather than cookies of our own. This website (fujiapps.dev) uses no analytics cookies.
Changes
If this policy changes in a way that matters, we will update the effective date above and note the change in the app’s release notes.
Contact
Fuji Apps hello@fujiapps.dev