Privacy policy

Last updated September 29, 2026

Mint Upsell is a Shopify app made by Mint Labs ("we", "us"). It shows "frequently bought together" add-ons on product pages, product offers in the cart, and a product recommendation on the Thank you page of a merchant's Shopify store. This policy explains what the app handles, why, and when it's deleted. For anything relating to a merchant's shoppers we act as a service provider (processor) to the merchant.

The short version

  • We don't collect or store shoppers' names, email addresses, phone numbers, addresses, customer IDs or IP addresses.
  • Our database holds the merchant's settings (product IDs), daily totals, and paid order IDs for 30 days.
  • The storefront scripts set no cookies and store nothing on the shopper's device.
  • We never sell or share data, use it for advertising, or combine it across stores.

Information about merchants

InformationWhy
Store domain and a Shopify access tokenTo connect to the store: product pickers, saving add-on picks on products, the bought-together discount and publishing settings.
Add-on sets, cart offers and settings (product IDs and handles, texts, discount percentage)To show the add-ons and offers the way the merchant set them up.
Plan and subscription statusRead from Shopify to decide which features apply. Payments are handled entirely by Shopify.

Information from the storefront and orders

InformationHow it's usedStored by us?
Widget views and add-to-cart clicks (Pro)The storefront widgets send anonymous counts (for example "1 view of Frequently bought together") through Shopify's app proxy.Daily totals per store only. No shopper identifiers.
Items added through the appMarked with a hidden line item property (_mint_upsell) so the merchant can see which items the app sold. It stays on the merchant's order in Shopify.No
Paid orders (Pro, orders/paid webhook)We read the line items that carry the property above and add their quantity and price to the store's daily totals. Customer fields in the webhook are not read, used or stored.Daily totals, plus the order ID for 30 days so a repeated webhook isn't counted twice
The shopper's cart (storefront)Read in the shopper's browser to decide which cart offer to show. It is not sent to us.No
The order on the Thank you pageRead inside Shopify's checkout by the app's extension to choose a product to recommend. It is not sent to us.No

Customer privacy requests

  • Access requests (Shopify's customers/data_request): we hold no shopper-level data, so there is nothing to return beyond what the merchant has in Shopify. We confirm this to the merchant on request.
  • Erasure requests (customers/redact): we hold no shopper-level data to delete.
  • Store deletion (shop/redact, sent 48 hours after a merchant uninstalls): we permanently delete the store's sets, offers, settings, totals, order IDs and access tokens.

Where data is processed and how it's protected

The app runs on Cloudflare (hosting and database) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers. See our security policy.

Retention

  • Settings, sets, offers and daily totals: while the app is installed; deleted with the store's data 48 hours after uninstall.
  • Paid order IDs: 30 days.
  • Rate-limit counters for the storefront counts: 1 day.
  • Access tokens: deleted as soon as the app is uninstalled.

Your rights

Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly; shoppers should contact the store, or email us and we'll pass the request on. We respond within 30 days.

Changes

If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.

Contact

Mint Labs — support@stickermint.com