Privacy policy

Last updated 30 July 2026

Prime Lock is built so that as little personal data as possible ever leaves Shopify. This page explains exactly what the website collects, what the app collects, and how to get any of it removed.

Who we are

Prime Lock is a Shopify app built and operated by Aspedan (“we”, “us”). Aspedan also publishes Prime MOQ and Discount Prime.

Registered address: — (to be confirmed). For any privacy question or request, write to support@primelock.app and put “Privacy” in the subject line. We answer within 24 hours and resolve requests within 30 days.

What this website collects

primelock.app collects aggregate, cookie-light analytics: page views, referrer, country and device type. We do not build advertising profiles and we do not sell data.

If you submit the contact form or the early-access form, we store the email address and message you send so we can reply. Nothing else is attached to it.

What the app collects

When a merchant installs Prime Lock, the app reads the shop domain, the plan, and the products, collections and pages it needs to apply locks. Lock configuration itself is stored in the shop’s own Shopify metafields, not in a separate database we control.

If the merchant publishes the registration form, the submissions it receives — the fields the merchant chose, such as company name, phone, VAT number or an uploaded business licence — are written to the merchant’s Shopify customer records as metafields. The merchant is the controller of that data; we process it on their behalf.

We keep aggregate counts of blocked checkouts so merchants can see the gate working. On Pro, the blocked-checkout log stores the timestamp, the lock, the product and whether the visitor was signed in.

  • We do not store customer payment details — checkout stays entirely with Shopify.
  • We do not store customer personal data beyond the registration submissions the merchant configures and keeps.
  • We do not send merchant or customer data to advertising networks.

GDPR and Shopify’s mandatory webhooks

Prime Lock implements Shopify’s three mandatory privacy webhooks: customers/data_request returns any data we hold for the named customer, customers/redact deletes it, and shop/redact deletes all shop data 48 hours after uninstall.

Merchants in the EU/UK can request a data processing addendum by email.

Retention

  • Contact-form messages: 24 months, then deleted.
  • Blocked-checkout logs: 90 days rolling.
  • Shop configuration and metafields: removed on uninstall, and in every case within 48 hours of a shop/redact webhook.
  • Analytics: aggregate only, retained 14 months.

Sub-processors

We use a small number of providers to run the service: Shopify (hosting of app surfaces and all commerce data), Cloudflare (edge delivery and application hosting), and a transactional email provider for approval and support email. The current list is available on request and we will publish material changes here.

Your rights

If you are in the EU, UK, California or another region with equivalent law, you can ask us to access, correct, export or delete your personal data, and to object to or restrict processing. Email support@primelock.app.

If your data reached us through a merchant’s store — for example a wholesale application — contact that merchant first; they control the record and we act on their instruction.

Changes

We update this page when the app changes what it collects. The date at the top always reflects the current version.

Questions about this policy? Contact the team.