Promo Drawer

Legal

Privacy Policy

What Promo Drawer collects, why, who processes it, and how long it is kept.

Last updated August 22, 2026 · Effective August 22, 2026

MightyIdea LLC (“we”, “us”, “our”), a Utah limited liability company, operates the website promodrawer.com and the Promo Drawer app for Shopify. This policy explains what personal information we collect, why we collect it, who else processes it, and how long we keep it.

Contact: contact@promodrawer.com

This policy covers both the website and the app. The app has not yet been released; the app sections describe how it is built and take effect when it becomes available.

1. Our role

Context Our role
A merchant’s account, configuration and billing status Controller
Visitors to promodrawer.com Controller
Shoppers on a merchant’s storefront Processor. The merchant is the controller and decides what runs on their store.

If you are a shopper with a question about a store you visited, contact that store first.

2. Information we collect through Shopify’s APIs

The app requests the minimum access it needs. Each permission and its purpose:

Permission What it gives us Purpose
read_products Titles, images, prices and availability of products and collections the merchant selects To display the product or collection on a card
read_files Images already in the merchant’s Shopify Files To let the merchant choose an image
read_themes The name of the published theme To name it in the app’s status line. We do not read or modify theme code
write_pixels, read_customer_events Installation of a Shopify Web Pixel and the two storefront events it subscribes to To count orders that followed an interaction with the drawer
write_files (optional) Upload to the merchant’s Shopify Files Requested only when a merchant clicks Upload, never at install

We do not request or receive access to customer records, orders, or customer personal information. We hold no customer names, email addresses, phone numbers, postal addresses, Shopify customer IDs, cart contents, or payment information at any time.

Merchant images remain in the merchant’s own Shopify Files. We do not host them.

3. Information we collect directly from merchants

The store’s .myshopify.com domain, the Shopify access token that authorizes our API calls, the store’s time zone, the current and previous plan and when it changed, install and uninstall timestamps, and the drawer configuration the merchant creates. If a merchant contacts support, we keep that correspondence.

4. Information we collect from merchants’ customers

When a shopper visits a storefront with the app installed, the widget reports how the drawer performed: a drawer being rendered, opened or closed; a card being viewed or its button clicked; a coupon code copied; a video play started; a signup form submitted; a social link followed.

Three characteristics of this collection:

  • Only aggregates are stored. Events are combined before they are written down, into daily counts of the form (store, day, drawer, card, event type, page type, device category). No record of an individual event is retained.
  • Collection is gated on consent and fails closed. Before anything is collected, the app checks Shopify’s Customer Privacy API. If processing is not allowed, or the API is unavailable, nothing is collected.
  • The app sets no cookies on a storefront.

Two pseudonymous identifiers are involved:

Identifier Description Retention
pd_s A random value we generate, stored in sessionStorage. Not a cookie; discarded when the browser tab closes. Not retained beyond the session
Shopify clientId Shopify’s own visitor identifier. We do not create it, and it exists whether or not the app is installed. It is paired with pd_s so an order can be attributed to a drawer. 7 days, on every plan

We also store the identifier of an order that followed an interaction, usually a checkout token. It identifies an order, not a person.

The app does not record sessions, capture heatmaps, build visitor profiles, track shoppers across sites, or derive location from IP addresses. The newsletter signup card posts to the merchant’s own Shopify customer form; subscriber details go to that merchant’s admin and are never transmitted to us.

5. Information we collect on this website

Purpose Provider Data Cookies
Audience measurement Google Analytics 4 Pages viewed, referrer, approximate location derived from IP, device and browser _ga, _ga_*
Usability analysis Microsoft Clarity Interactions, clicks, scrolling, and session replays of your visit to this website _clck, _clsk
Traffic measurement Cloudflare Web Analytics Page views and performance timings None
Security and delivery Cloudflare IP address and request metadata, in server logs None
Launch notification list Formspree The email address you submit and metadata about the submission None

Session replays. Anything you type into a form is masked: Microsoft Clarity masks the contents of input fields and drop-down menus in every configuration, and masked content is never uploaded. Our Clarity project additionally uses Balanced masking, which masks numbers and email addresses appearing in page content. We use replays only to identify layout and usability problems on this website.

Consent. Google Analytics and Microsoft Clarity are not loaded, and set no cookies, unless you accept them. On your first visit this website asks, and records your answer in your browser’s local storage rather than in a cookie. Declining stores nothing beyond that answer.

Withdrawing or changing consent is as easy as giving it: select Cookie settings in the footer of any page. Clearing your browser’s storage for this site also resets the choice.

Global Privacy Control. If your browser sends a GPC signal we treat it as a decline, load nothing, and do not ask — you have already answered. Firefox, Brave and DuckDuckGo send it by default; other browsers support it through an extension.

You may also use the Google Analytics opt-out add-on, the opt-out described in the Microsoft privacy statement, or your browser’s cookie controls. Nothing on this website requires cookies to function.

The demo. The interactive demo runs in an isolated frame, sends us nothing, and sets no cookies. Its sample images are served by Shopify’s CDN. If you press play on the sample video card, YouTube is loaded in privacy-enhanced mode at that point and Google’s terms then apply.

We do not display advertising, run retargeting pixels, sell personal information, or share it for cross-context behavioral advertising.

6. How we use information

  • To operate the app and display each merchant’s drawer as configured.
  • To report performance analytics to the merchant whose store generated them.
  • To provide support and respond to inquiries.
  • To administer plans and billing through Shopify.
  • To detect, investigate and fix errors, abuse and security problems.
  • To measure and improve this website.
  • To send one notification when the app is released, if you asked for it.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (operating the app for a merchant); consent (website analytics, the launch notification list, and storefront analytics, which is gated on the consent signal Shopify provides); legitimate interests (securing our services and diagnosing faults); and legal obligations.

7. How long we keep information

Data Retention
Storefront visitor identifiers 7 days, on every plan
Daily aggregate counts and attributed orders Free plan: 90 days · Basic: 12 months · Pro: while the app remains installed
Merchant account, configuration and access token While the app is installed
All data belonging to a store Deleted within 48 hours of uninstall, on Shopify’s shop/redact request
Support correspondence Up to 24 months
Launch notification email address Until the notification is sent, or until you ask us to delete it

Deletion removes data from our production systems. Our database provider retains point-in-time history for 7 days for disaster recovery, so deleted records may remain restorable from backups for up to one week. We do not query backups except to recover from an incident.

8. Who else processes information, and where

Recipient Purpose Location
Shopify Platform, merchant authentication, product data, billing Global
Cloudflare DNS, content delivery, the analytics ingest endpoint, and web analytics Global
Cloud application hosting Runs the merchant admin application United States
Managed database Stores merchant configuration and aggregate analytics United States
Static site hosting Serves promodrawer.com Global
Error monitoring Diagnoses faults in the admin application United States
Internal team messaging Notifies us of installs, uninstalls and plan changes — store domain and event only United States
Google, Microsoft, Formspree This website only, as described in §5 United States

We will provide the current list of named sub-processors to any merchant on request, and to merchants who require one as part of a data processing agreement.

Error reports are scrubbed before transmission: access tokens, session tokens, database connection strings and credentials appearing in URLs are removed.

International transfers. We are established in the United States and are not established in Europe. Personal information is stored and processed in the United States. Where information is transferred from the EEA, the United Kingdom or Switzerland, that transfer relies on the Standard Contractual Clauses or another lawful transfer mechanism operated by the provider concerned.

9. Your rights

Subject to your jurisdiction, you may have the right to access, correct, delete, port or restrict the processing of your personal information, to object to processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Utah, Virginia and other US states with comprehensive privacy laws have equivalent rights, including the right not to be discriminated against for exercising them.

We do not sell personal information and do not share it for cross-context behavioral advertising.

To exercise a right, email contact@promodrawer.com. We respond within 30 days and may need to verify your identity or your authority to act for a store. If you are in the EEA or the UK and are dissatisfied with our response, you may lodge a complaint with your supervisory authority.

Shoppers. We hold no information that identifies you. Where a merchant sends us a redaction request through Shopify, we act on it; the pseudonymous identifiers described in §4 expire within 7 days in any event.

10. Security

Traffic is encrypted in transit. Access tokens are held in an access-controlled database, are never written to logs, and are removed from error reports. Access to production data is limited to personnel who require it. The storefront widget reads its configuration from Shopify rather than from us, so a shopper’s browser makes no request to our infrastructure other than the analytics endpoint, which holds no sensitive data.

No system is entirely secure. To report a vulnerability, email contact@promodrawer.com and allow us a reasonable opportunity to remediate before public disclosure.

11. Children

Neither the website nor the app is directed to children under 13, and we do not knowingly collect information from them.

12. Changes

We will update this policy when our practices change and will revise the date above. Material changes affecting merchants will be notified in the app or by email.

13. Contact

MightyIdea LLC · Utah, United States contact@promodrawer.com

See also our Terms of Service.