PromoDrawer™

Legal

Privacy Policy

What PromoDrawer collects, why, who processes it, and how long it is kept.

Last updated October 3, 2026 · Effective September 28, 2026

MightyIdea LLC (“we”, “us”, “our”), a Utah limited liability company, operates the website promodrawer.com and the PromoDrawer app for Shopify. This policy explains what personal information we collect, why we collect it, who else processes it, and how long we keep it.

Contact: contact@promodrawer.com

This policy covers both the website and the app. The app sections apply to every store that installs the app.

1. Our role

Context Our role
A merchant’s account, configuration and billing status Controller
Visitors to promodrawer.com Controller
Shoppers on a merchant’s storefront Processor. The merchant is the controller and decides what runs on their store.

If you are a shopper with a question about a store you visited, contact that store first.

2. Information we collect through Shopify’s APIs

The app requests the minimum access it needs. Each permission and its purpose:

Permission What it gives us Purpose
read_products Titles, images, prices and availability of products and collections the merchant selects To display the product or collection on a card
read_files Images already in the merchant’s Shopify Files To let the merchant choose an image
read_themes The name of the published theme, and which fonts its settings choose To name the theme in the app’s status line, and to draw the theme’s fonts in the admin preview. We do not read or modify theme code
write_pixels, read_customer_events Installation of a Shopify Web Pixel and the two storefront events it subscribes to To count orders that followed an interaction with the drawer
write_files (optional) Upload to the merchant’s Shopify Files Requested only when a merchant first uploads a file or has the app copy a video’s cover image into their Files, never at install
read_locales (optional) The store’s published languages To let the merchant write card text in each language. Requested only when a merchant first uses translations, never at install

We do not request or receive access to customer records, orders, or customer personal information. We hold no customer names, email addresses, phone numbers, postal addresses, Shopify customer IDs, cart contents, or payment information at any time. Where a card shows cart progress (the free shipping card), it reads the cart total in the shopper’s browser and sends it nowhere.

Merchant images remain in the merchant’s own Shopify Files. We do not host them.

3. Information we collect directly from merchants

The store’s .myshopify.com domain, the Shopify access token that authorizes our API calls, the store’s time zone, the current and previous plan, when it changed and how often it is billed, install and uninstall timestamps, which in-app notices the merchant has dismissed, and the drawer configuration the merchant creates, including any translations of it.

If a merchant contacts support, we keep that correspondence. A message sent from the app’s Help page is stored with its subject, text and the reply-to email address the merchant enters, and with a snapshot of the app’s setup on that store when it was sent, so we can answer it: the app version, plan and billing interval, install date and time zone, the theme and whether the app embed is on, each drawer’s settings, the store’s view, open and click totals for the previous seven days, the permissions the app holds, and the browser used to send the message. It contains nothing about the store’s customers.

4. Information we collect from merchants’ customers

When a shopper visits a storefront with the app installed, the widget reports how the drawer performed: a drawer being rendered, opened or closed; a card being viewed or its button clicked; a discount code copied or applied; a product added to the cart; a video play started; a signup form submitted; a social link followed.

Three characteristics of this collection:

  • Aggregates are what is kept. Events are combined before they are written down, into daily counts of the form (store, day, drawer, card, event type, page type, device category). The one exception is attribution: for 7 days we keep which drawer and card a session last opened or clicked, keyed to the pd_s value below, so that an order can be matched to it. Nothing else about an individual event is retained.
  • Collection is gated on consent and fails closed. Before anything is collected, the app checks Shopify’s Customer Privacy API. If processing is not allowed, or the API is unavailable, nothing is collected.
  • The app sets no cookies on a storefront.

Two pseudonymous identifiers are involved:

Identifier Description Retention
pd_s A random value we generate, stored in sessionStorage. Not a cookie; discarded when the browser tab closes. Not retained beyond the session
Shopify clientId Shopify’s own visitor identifier. We do not create it, and it exists whether or not the app is installed. It is paired with pd_s so an order can be attributed to a drawer. 7 days, on every plan

Three further browser keys hold no identifier and describe no person:

Key Where Purpose
pd_v sessionStorage Which events have already been counted this session, so a single drawer view is not counted twice. Discarded with the session
pd_b sessionStorage That this session’s attribution pairing has been sent, so it is sent once. Discarded with the session
pd:hidden localStorage Only where a merchant lets shoppers hide the drawer’s button: which drawers this browser hid, and when. Never sent to us. Kept for 30 days

When an order follows an interaction, we store the order’s identifier (usually a checkout token) and its total and currency. They identify an order, not a person.

Video and fonts. Shopify-hosted videos, images and fonts are served by Shopify. If a merchant adds a YouTube or Vimeo video, the shopper’s browser loads that provider’s player: YouTube in its privacy-enhanced mode, Vimeo with its Do Not Track setting. A looping video loads when the drawer is opened; a tap-to-play video loads only when the shopper taps play. That provider’s own privacy policy then applies.

The app does not record sessions, capture heatmaps, build visitor profiles, track shoppers across sites, or derive location from IP addresses. The email signup card posts to the merchant’s own Shopify customer form; subscriber details (an email address and, if the merchant asks for it, a first name) go to that merchant’s admin and are never transmitted to us.

5. Information we collect on this website

Purpose Provider Data Cookies
Audience measurement Google Analytics 4 Pages viewed, referrer, approximate location derived from IP, device and browser _ga, _ga_*
Usability analysis Microsoft Clarity Interactions, clicks, scrolling, and session replays of your visit to this website _clck, _clsk
Measuring our ads on Google Google Ads, and Google Analytics linked to it Pages viewed, clicks on links to our App Store listing, the ad click that brought you here, referrer, IP address, device and browser. Google can link this to a Google account you are signed in to _gcl_au, _gcl_aw on this site; Google’s own
Measuring our ads on X X (formerly Twitter) Pages viewed, clicks on links to our App Store listing, referrer, IP address, device and browser. X can link this to an X account you are signed in to _twclid on this site; X’s own, such as muc_ads and personalization_id
Traffic measurement Cloudflare Web Analytics Page views and performance timings None
Security and delivery Cloudflare IP address and request metadata, in server logs None

Session replays. Anything you type into a form is masked: Microsoft Clarity masks the contents of input fields and drop-down menus in every configuration, and masked content is never uploaded. Our Clarity project additionally uses Balanced masking, which masks numbers and email addresses appearing in page content. We use replays only to identify layout and usability problems on this website.

Consent. In the European Economic Area, the United Kingdom and Switzerland, Google Analytics, Google Ads, Microsoft Clarity and X’s pixel are not loaded, and set no cookies, unless you accept them; this website asks on your first visit. Everywhere else, including the United States, they load when you arrive, and you can turn them off at any time. We tell which applies from your browser’s time zone, without looking up your location; if the time zone is unknown we ask first. Your answer is recorded in your browser’s local storage rather than in a cookie, and declining stores nothing beyond it.

Checklists. A guide on this website with a checklist, such as the Black Friday checklist, remembers which items you ticked in your browser’s local storage (a key starting pd-checklist:). It never leaves your browser, and clearing your browser’s storage removes it.

Opting out, or changing your answer, takes one click wherever you are: select Cookie settings in the footer of any page (in California, Do not sell or share my personal information) and choose Decline. Clearing your browser’s storage for this site resets the choice.

Global Privacy Control. If your browser sends a GPC signal we treat it as an opt-out wherever you are: we load nothing and do not ask, because you have already answered. Firefox, Brave and DuckDuckGo send it by default; other browsers support it through an extension.

You may also use the Google Analytics opt-out add-on, Google’s My Ad Center, the opt-out described in the Microsoft privacy statement, X’s personalization and data settings and privacy policy, or your browser’s cookie controls. Nothing on this website requires cookies to function.

The demo. The interactive demo runs in an isolated frame, sends us nothing, and sets no cookies. Its sample images and its sample video are served by Shopify’s CDN.

We do not display advertising on this website or sell personal information. We advertise on Google and X, and this website tells them about your visit so we can see which of our ads lead to installs, and so they can show our ads to people who have visited. Several US state laws call that “sharing” personal information for cross-context behavioral advertising, or targeted advertising. In the EEA, the UK and Switzerland it happens only if you accept; elsewhere, including every US state, you can opt out. Either way, choosing Decline under Cookie settings in the footer (in California, Do not sell or share my personal information), or sending a GPC signal, stops it.

6. How we use information

  • To operate the app and display each merchant’s drawer as configured.
  • To report performance analytics to the merchant whose store generated them.
  • To provide support and respond to inquiries.
  • To administer plans and billing through Shopify.
  • To detect, investigate and fix errors, abuse and security problems.
  • To measure and improve this website.

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (operating the app for a merchant); consent (website analytics and storefront analytics, which is gated on the consent signal Shopify provides); legitimate interests (securing our services and diagnosing faults); and legal obligations.

7. How long we keep information

Data Retention
Storefront visitor identifiers and attribution records 7 days, on every plan
Daily aggregate counts and attributed orders Free plan: 90 days · Basic: 12 months · Pro: while the app remains installed
Merchant account, configuration and access token While the app is installed
All data belonging to a store Deleted within 48 hours of uninstall, on Shopify’s shop/redact request
Support correspondence Up to 24 months

Deletion removes data from our production systems. Our database provider retains point-in-time history for 7 days for disaster recovery, so deleted records may remain restorable from backups for up to one week. We do not query backups except to recover from an incident.

8. Who else processes information, and where

Recipient Purpose Location
Shopify Platform, merchant authentication, product data, billing Global
Cloudflare DNS, content delivery, the analytics ingest endpoint, and web analytics Global
Cloud application hosting Runs the merchant admin application United States
Managed database Stores merchant configuration and aggregate analytics United States
Static site hosting Serves promodrawer.com Global
Error monitoring Diagnoses faults in the admin application United States
Internal team messaging Notifies us of installs, uninstalls and plan changes (store domain and event only), and of support messages sent from the app United States
Transactional email Delivers support messages sent from the app to our support inbox United States
Google, Microsoft, X This website, as described in §5, including Google Ads and X for measuring our advertising. Google Fonts also serves the theme’s fonts to the admin preview, in the merchant’s browser only United States

We will provide the current list of named sub-processors to any merchant on request, and to merchants who require one as part of a data processing agreement.

Error reports are scrubbed before transmission: access tokens, session tokens, database connection strings and credentials appearing in URLs are removed.

International transfers. We are established in the United States and are not established in Europe. Personal information is stored and processed in the United States. Where information is transferred from the EEA, the United Kingdom or Switzerland, that transfer relies on the Standard Contractual Clauses or another lawful transfer mechanism operated by the provider concerned.

9. Your rights

Subject to your jurisdiction, you may have the right to access, correct, delete, port or restrict the processing of your personal information, to object to processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Utah, Virginia and other US states with comprehensive privacy laws have equivalent rights, including the right not to be discriminated against for exercising them.

We do not sell personal information. The one way this website shares it for cross-context behavioral or targeted advertising is through Google Ads and X’s pixel (§5). To opt out of that sharing, select Do not sell or share my personal information in the footer (Cookie settings outside California) and choose Decline, or send a Global Privacy Control signal, which we honor as an opt-out in every state. The PromoDrawer app shares nothing for advertising.

To exercise a right, email contact@promodrawer.com. We respond within 30 days and may need to verify your identity or your authority to act for a store. If you are in the EEA or the UK and are dissatisfied with our response, you may lodge a complaint with your supervisory authority.

Shoppers. We hold no information that identifies you. Where a merchant sends us a redaction request through Shopify, we act on it; the pseudonymous identifiers described in §4 expire within 7 days in any event.

10. Security

Traffic is encrypted in transit. Access tokens are held in an access-controlled database, are never written to logs, and are removed from error reports. Access to production data is limited to personnel who require it. The storefront widget reads its configuration from Shopify rather than from us, so a shopper’s browser makes no request to our infrastructure other than the analytics endpoint, which holds no sensitive data.

No system is entirely secure. To report a vulnerability, email contact@promodrawer.com and allow us a reasonable opportunity to remediate before public disclosure.

11. Children

Neither the website nor the app is directed to children under 13, and we do not knowingly collect information from them.

12. Changes

We will update this policy when our practices change and will revise the date above. Material changes affecting merchants will be notified in the app or by email.

13. Contact

MightyIdea LLC · Utah, United States contact@promodrawer.com

See also our Terms of Service.