Legal
Privacy Policy
What Promo Drawer collects, why, who processes it, and how long it is kept.
Last updated August 22, 2026 · Effective August 22, 2026
MightyIdea LLC (“we”, “us”, “our”), a Utah limited liability company, operates the website promodrawer.com and the Promo Drawer app for Shopify. This policy explains what personal information we collect, why we collect it, who else processes it, and how long we keep it.
Contact: contact@promodrawer.com
This policy covers both the website and the app. The app has not yet been released; the app sections describe how it is built and take effect when it becomes available.
1. Our role
| Context | Our role |
|---|---|
| A merchant’s account, configuration and billing status | Controller |
| Visitors to promodrawer.com | Controller |
| Shoppers on a merchant’s storefront | Processor. The merchant is the controller and decides what runs on their store. |
If you are a shopper with a question about a store you visited, contact that store first.
2. Information we collect through Shopify’s APIs
The app requests the minimum access it needs. Each permission and its purpose:
| Permission | What it gives us | Purpose |
|---|---|---|
read_products |
Titles, images, prices and availability of products and collections the merchant selects | To display the product or collection on a card |
read_files |
Images already in the merchant’s Shopify Files | To let the merchant choose an image |
read_themes |
The name of the published theme | To name it in the app’s status line. We do not read or modify theme code |
write_pixels, read_customer_events |
Installation of a Shopify Web Pixel and the two storefront events it subscribes to | To count orders that followed an interaction with the drawer |
write_files (optional) |
Upload to the merchant’s Shopify Files | Requested only when a merchant clicks Upload, never at install |
We do not request or receive access to customer records, orders, or customer personal information. We hold no customer names, email addresses, phone numbers, postal addresses, Shopify customer IDs, cart contents, or payment information at any time.
Merchant images remain in the merchant’s own Shopify Files. We do not host them.
3. Information we collect directly from merchants
The store’s .myshopify.com domain, the Shopify access token that authorizes our API calls, the
store’s time zone, the current and previous plan and when it changed, install and uninstall
timestamps, and the drawer configuration the merchant creates. If a merchant contacts support, we
keep that correspondence.
4. Information we collect from merchants’ customers
When a shopper visits a storefront with the app installed, the widget reports how the drawer performed: a drawer being rendered, opened or closed; a card being viewed or its button clicked; a coupon code copied; a video play started; a signup form submitted; a social link followed.
Three characteristics of this collection:
- Only aggregates are stored. Events are combined before they are written down, into daily counts of the form (store, day, drawer, card, event type, page type, device category). No record of an individual event is retained.
- Collection is gated on consent and fails closed. Before anything is collected, the app checks Shopify’s Customer Privacy API. If processing is not allowed, or the API is unavailable, nothing is collected.
- The app sets no cookies on a storefront.
Two pseudonymous identifiers are involved:
| Identifier | Description | Retention |
|---|---|---|
pd_s |
A random value we generate, stored in sessionStorage. Not a cookie; discarded when the browser tab closes. |
Not retained beyond the session |
Shopify clientId |
Shopify’s own visitor identifier. We do not create it, and it exists whether or not the app is installed. It is paired with pd_s so an order can be attributed to a drawer. |
7 days, on every plan |
We also store the identifier of an order that followed an interaction, usually a checkout token. It identifies an order, not a person.
The app does not record sessions, capture heatmaps, build visitor profiles, track shoppers across sites, or derive location from IP addresses. The newsletter signup card posts to the merchant’s own Shopify customer form; subscriber details go to that merchant’s admin and are never transmitted to us.
5. Information we collect on this website
| Purpose | Provider | Data | Cookies |
|---|---|---|---|
| Audience measurement | Google Analytics 4 | Pages viewed, referrer, approximate location derived from IP, device and browser | _ga, _ga_* |
| Usability analysis | Microsoft Clarity | Interactions, clicks, scrolling, and session replays of your visit to this website | _clck, _clsk |
| Traffic measurement | Cloudflare Web Analytics | Page views and performance timings | None |
| Security and delivery | Cloudflare | IP address and request metadata, in server logs | None |
| Launch notification list | Formspree | The email address you submit and metadata about the submission | None |
Session replays. Anything you type into a form is masked: Microsoft Clarity masks the contents of input fields and drop-down menus in every configuration, and masked content is never uploaded. Our Clarity project additionally uses Balanced masking, which masks numbers and email addresses appearing in page content. We use replays only to identify layout and usability problems on this website.
Consent. Google Analytics and Microsoft Clarity are not loaded, and set no cookies, unless you accept them. On your first visit this website asks, and records your answer in your browser’s local storage rather than in a cookie. Declining stores nothing beyond that answer.
Withdrawing or changing consent is as easy as giving it: select Cookie settings in the footer of any page. Clearing your browser’s storage for this site also resets the choice.
Global Privacy Control. If your browser sends a GPC signal we treat it as a decline, load nothing, and do not ask — you have already answered. Firefox, Brave and DuckDuckGo send it by default; other browsers support it through an extension.
You may also use the Google Analytics opt-out add-on, the opt-out described in the Microsoft privacy statement, or your browser’s cookie controls. Nothing on this website requires cookies to function.
The demo. The interactive demo runs in an isolated frame, sends us nothing, and sets no cookies. Its sample images are served by Shopify’s CDN. If you press play on the sample video card, YouTube is loaded in privacy-enhanced mode at that point and Google’s terms then apply.
We do not display advertising, run retargeting pixels, sell personal information, or share it for cross-context behavioral advertising.
6. How we use information
- To operate the app and display each merchant’s drawer as configured.
- To report performance analytics to the merchant whose store generated them.
- To provide support and respond to inquiries.
- To administer plans and billing through Shopify.
- To detect, investigate and fix errors, abuse and security problems.
- To measure and improve this website.
- To send one notification when the app is released, if you asked for it.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (operating the app for a merchant); consent (website analytics, the launch notification list, and storefront analytics, which is gated on the consent signal Shopify provides); legitimate interests (securing our services and diagnosing faults); and legal obligations.
7. How long we keep information
| Data | Retention |
|---|---|
| Storefront visitor identifiers | 7 days, on every plan |
| Daily aggregate counts and attributed orders | Free plan: 90 days · Basic: 12 months · Pro: while the app remains installed |
| Merchant account, configuration and access token | While the app is installed |
| All data belonging to a store | Deleted within 48 hours of uninstall, on Shopify’s shop/redact request |
| Support correspondence | Up to 24 months |
| Launch notification email address | Until the notification is sent, or until you ask us to delete it |
Deletion removes data from our production systems. Our database provider retains point-in-time history for 7 days for disaster recovery, so deleted records may remain restorable from backups for up to one week. We do not query backups except to recover from an incident.
8. Who else processes information, and where
| Recipient | Purpose | Location |
|---|---|---|
| Shopify | Platform, merchant authentication, product data, billing | Global |
| Cloudflare | DNS, content delivery, the analytics ingest endpoint, and web analytics | Global |
| Cloud application hosting | Runs the merchant admin application | United States |
| Managed database | Stores merchant configuration and aggregate analytics | United States |
| Static site hosting | Serves promodrawer.com | Global |
| Error monitoring | Diagnoses faults in the admin application | United States |
| Internal team messaging | Notifies us of installs, uninstalls and plan changes — store domain and event only | United States |
| Google, Microsoft, Formspree | This website only, as described in §5 | United States |
We will provide the current list of named sub-processors to any merchant on request, and to merchants who require one as part of a data processing agreement.
Error reports are scrubbed before transmission: access tokens, session tokens, database connection strings and credentials appearing in URLs are removed.
International transfers. We are established in the United States and are not established in Europe. Personal information is stored and processed in the United States. Where information is transferred from the EEA, the United Kingdom or Switzerland, that transfer relies on the Standard Contractual Clauses or another lawful transfer mechanism operated by the provider concerned.
9. Your rights
Subject to your jurisdiction, you may have the right to access, correct, delete, port or restrict the processing of your personal information, to object to processing, and to withdraw consent. Residents of California, Colorado, Connecticut, Utah, Virginia and other US states with comprehensive privacy laws have equivalent rights, including the right not to be discriminated against for exercising them.
We do not sell personal information and do not share it for cross-context behavioral advertising.
To exercise a right, email contact@promodrawer.com. We respond within 30 days and may need to verify your identity or your authority to act for a store. If you are in the EEA or the UK and are dissatisfied with our response, you may lodge a complaint with your supervisory authority.
Shoppers. We hold no information that identifies you. Where a merchant sends us a redaction request through Shopify, we act on it; the pseudonymous identifiers described in §4 expire within 7 days in any event.
10. Security
Traffic is encrypted in transit. Access tokens are held in an access-controlled database, are never written to logs, and are removed from error reports. Access to production data is limited to personnel who require it. The storefront widget reads its configuration from Shopify rather than from us, so a shopper’s browser makes no request to our infrastructure other than the analytics endpoint, which holds no sensitive data.
No system is entirely secure. To report a vulnerability, email contact@promodrawer.com and allow us a reasonable opportunity to remediate before public disclosure.
11. Children
Neither the website nor the app is directed to children under 13, and we do not knowingly collect information from them.
12. Changes
We will update this policy when our practices change and will revise the date above. Material changes affecting merchants will be notified in the app or by email.
13. Contact
MightyIdea LLC · Utah, United States contact@promodrawer.com
See also our Terms of Service.