Negative Space LLC (“Negative Space,” “we,” “us,” or “our”) provides the Hybrid Cart Shopify application and related services (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and protect information when Shopify merchants install or use the Service and when shoppers interact with a merchant’s storefront where the Service is enabled.
This policy applies to the Hybrid Cart application and its analytics, rewards, discount, and cart-related functionality. It does not govern a merchant’s own privacy practices, Shopify’s services, or third-party services that a merchant uses with Hybrid Cart.
1. Our role
For information about a merchant, its personnel, and its use of Hybrid Cart, Negative Space generally determines why and how that information is processed.
For information about a merchant’s shoppers that we process to provide Hybrid Cart to that merchant, the merchant generally determines why the information is processed, and Negative Space acts as the merchant’s service provider or processor. Merchants are responsible for providing required privacy notices, configuring Shopify’s customer privacy settings, establishing an appropriate legal basis, and responding to shopper requests. Nothing in this policy changes the merchant’s responsibilities under applicable law.
2. Information we collect
A. Information received from Shopify
Depending on the features a merchant enables and the permissions granted to the Service, we may receive or generate:
- Store information, including Shopify shop ID,
.myshopify.comdomain, reporting time zone, default currency, installation status, and app permissions. - Authentication and security information, including Shopify access and refresh tokens. These credentials are kept server-side and are not exposed to storefront visitors.
- Catalog and market information used to configure rewards and cart experiences, including product and variant IDs, titles, handles, images, market names, country codes, selling plans, and availability-related information.
- Configuration information supplied in Shopify or Hybrid Cart, including reward tiers, thresholds, eligible products, merchant-authored display text, market-specific values, discount settings, and identifiers for Shopify Functions, discounts, cart transforms, and metafields managed by the Service.
- Minimized order and refund information used for analytics, attribution, and billing, including order and line identifiers, order number, timestamps, test-order status, order source, currency, amounts, discounts, refund amounts, product and variant IDs, quantities, selling plan IDs, cart and checkout tokens, and Hybrid Cart attribution properties.
- App subscription and usage information, including plan status, billing-cycle dates, usage quantities, and identifiers used to submit usage events to Shopify.
- Privacy and compliance requests sent by Shopify, including the shop and order identifiers needed to locate, provide, or delete relevant information.
Shopify order and privacy webhook requests can contain additional customer fields. Hybrid Cart is designed to discard customer names, email addresses, phone numbers, postal addresses, cart notes, and unrelated line-item properties before ordinary order or refund webhook data is stored. We do not intentionally retain those fields as part of Hybrid Cart analytics.
B. Storefront analytics information
When the merchant enables Hybrid Cart analytics and Shopify’s customer privacy controls permit the web pixel to run, we may collect:
- Random or pseudonymous identifiers, including Shopify customer-event IDs, anonymous visitor IDs, Hybrid Cart session IDs, cart tokens, checkout tokens, and offer-instance IDs.
- Event timestamps and event types, such as cart opened, product added to cart, upsell viewed, upsell added, checkout started, and checkout completed.
- Cart and commerce context, including currency, cart value, item count, product and variant IDs, quantities, line value, offer IDs, recommendation source, cart feature and placement, and whether an attributed item was purchased or refunded.
- Coarse context, including page category, device category, and, when available, a two-letter country code.
- Technical metadata needed to operate the pixel, including schema and cart-package versions and event delivery status.
Hybrid Cart does not intentionally collect full page URLs, raw user-agent strings, raw IP addresses, customer names, customer email addresses, customer phone numbers, postal addresses, or payment-card information through its analytics events.
The pixel uses browser session storage to keep a random session identifier. The identifier is renewed after 30 minutes of inactivity. If browser storage is unavailable, the pixel uses a temporary identifier for the current page load. Hybrid Cart does not use this identifier for cross-store tracking or targeted advertising.
Our server necessarily receives network information when a device connects to it. We do not intentionally persist raw IP addresses for analytics. For abuse prevention and rate limiting, we may derive a keyed network fingerprint that is not intended to identify the individual directly.
C. Information provided directly by merchants
We may collect information that merchants or their personnel submit directly, including:
- Hybrid Cart settings, reward configurations, product selections, and merchant-authored content.
- Support requests, feedback, and communications, which may include a name, business contact information, and any information included in the message.
- Administrative and diagnostic information generated when a merchant uses the Service, such as authentication results, feature status, and sanitized error records.
Please do not send us customer personal information unless it is necessary for a support request. If it is necessary, disclose only the minimum information required.
D. Information we do not collect for payment processing
App charges are handled through Shopify’s billing systems. We do not receive or store a merchant’s payment-card number through the Service.
3. How we use information
We use information to:
- Install, authenticate, operate, maintain, and secure the Service.
- Provide the merchant dashboard, cart analytics, attribution reporting, rewards, discounts, cart transforms, and related storefront functionality.
- Connect pseudonymous cart activity with completed orders and refunds so merchants can measure performance.
- Configure and synchronize merchant-selected products, markets, discounts, Functions, and storefront settings.
- Administer subscriptions, calculate permitted usage quantities, and communicate billing events to Shopify.
- Troubleshoot errors, prevent abuse, monitor reliability, and improve the Service.
- Provide support and respond to merchant communications.
- Process access, deletion, and other privacy requests.
- Comply with law, enforce our agreements, and protect the rights, safety, and security of merchants, shoppers, Negative Space, Shopify, and others.
We do not use merchant or shopper data to build advertising profiles, track shoppers across unaffiliated stores, or create cross-merchant benchmarks. We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable United States privacy laws.
4. Legal bases for processing
Where the law requires a legal basis, we process information as follows:
- To perform a contract, including providing and supporting the Service requested by a merchant.
- For legitimate interests, including securing, maintaining, troubleshooting, and improving the Service, provided those interests are not overridden by applicable privacy rights.
- To comply with legal obligations, including privacy, tax, accounting, fraud-prevention, and lawful government requirements.
- With consent where consent is required. Storefront analytics are delivered through a Shopify web pixel that is designed to respect the customer’s consent choices and the merchant’s Shopify customer privacy configuration.
When we act as a processor or service provider for a merchant, we process shopper information on the merchant’s documented instructions and as needed to provide the Service.
5. How we disclose information
We may disclose information to:
- Shopify, to authenticate the app, receive API and webhook data, run customer events and web pixels, manage app features, process privacy requests, and administer app billing.
- Railway, which provides application hosting and operational infrastructure.
- PlanetScale, which provides the managed PostgreSQL database used for application and analytics data.
- Vendors and contractors that provide security, monitoring, customer support, communications, or other services on our behalf, subject to appropriate confidentiality and data-protection obligations.
- Professional advisers, auditors, insurers, regulators, courts, law enforcement, or other parties when reasonably necessary to comply with law, establish or defend legal claims, or protect rights and safety.
- A buyer, investor, successor, or other relevant party in connection with a proposed or completed merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate safeguards.
We may also disclose information at a merchant’s direction or with the merchant’s authorization. Our service providers may process information only to provide services to us or as otherwise permitted by law and contract.
6. Data retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this policy:
- Raw storefront event records are generally retained for up to 90 days.
- Minimized Shopify order and refund webhook records are generally retained for up to 30 days.
- Derived cart sessions, normalized order and refund analytics, merchant configuration, billing records, and aggregate reporting data are generally retained while the app remains installed and until the shop’s data is deleted following uninstallation or a valid deletion request.
- Application and security logs are kept on a limited, rolling basis for service operation, troubleshooting, abuse prevention, and legal compliance.
- Residual copies in managed backups, if any, are isolated from ordinary use and deleted or overwritten according to our service providers’ backup lifecycles.
When Shopify sends a verified customers/redact request, we delete order records, linked cart sessions, linked storefront event trails, relevant queued webhook records, and derived aggregates associated with the identified orders, unless retention is required by law.
When Shopify sends a verified shop/redact request, normally 48 hours after the merchant uninstalls the app, we delete retained application data associated with that shop, including sessions, configurations, storefront events, cart sessions, order analytics, aggregates, event sources, and associated billing records, unless retention is required by law. Data may be retained longer when necessary to comply with law, resolve disputes, enforce agreements, or protect the Service from fraud or abuse, in which case it will be limited to those purposes.
7. Privacy choices and rights
Depending on location and applicable law, individuals may have rights to request access to, correction of, deletion of, or portability of personal information, or to object to or restrict certain processing. Individuals may also have the right to withdraw consent and to appeal a denied privacy request. We will not discriminate against an individual for exercising an applicable privacy right.
Shoppers
If you shopped with a merchant that uses Hybrid Cart, please submit your request to that merchant first. The merchant controls the storefront and can identify the relevant order and send the appropriate request through Shopify. Shopify then sends Hybrid Cart the order identifiers needed to locate or delete linked pseudonymous analytics. Because Hybrid Cart intentionally does not retain customer names or contact details in its analytics, we generally cannot locate a shopper’s records using only a name or email address.
Shoppers can also manage analytics consent through the privacy controls offered by the merchant’s Shopify storefront. Disabling consent may prevent Hybrid Cart’s web pixel from receiving analytics events, but it does not affect information that must be processed to complete an order or provide requested cart functionality.
Merchants and merchant personnel
Merchants may contact us using the details below to request access, correction, or deletion, or to ask a privacy question. We may need to verify the requester’s identity and authority before acting. Merchants can also stop future collection by disabling applicable analytics functionality or uninstalling the Service, subject to any data that must be retained by law.
Authorized agents may submit requests where permitted by law. We may request proof of the agent’s authority and verification of the individual or business represented.
8. International data transfers
Hybrid Cart’s primary application and database infrastructure is hosted in the United States. We and our service providers may process information in the United States and other countries where we or they operate. When required, we use recognized safeguards for international transfers, such as contractual protections, and take steps designed to protect information in accordance with this policy and applicable law.
9. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include data minimization, transport encryption, server-side secret storage, authenticated merchant requests, verification of Shopify webhook signatures, tenant separation, access controls, and deletion workflows. No system or transmission method is completely secure, and we cannot guarantee absolute security.
10. Children
The Service is intended for Shopify merchants and is not directed to children. We do not knowingly collect personal information directly from children through Hybrid Cart. Merchants are responsible for ensuring that their storefronts, notices, consent practices, and use of the Service comply with laws that apply to children and teenagers.
11. Third-party services
The Service operates with Shopify and may interact with other applications or services selected by a merchant. Those third parties have their own privacy practices, and this policy does not govern them. Merchants and shoppers should review the privacy notices of Shopify and any relevant merchant-selected services.
12. Changes to this policy
We may update this Privacy Policy to reflect changes to the Service, our practices, providers, or applicable law. We will post the updated version with a new “Last updated” date. If a change is material, we will provide additional notice when required by law.
13. Contact us
Questions or requests concerning this Privacy Policy or our privacy practices may be sent to:
Negative Space LLCAttn: Privacy
13722 Little Harbor Ct
Jacksonville, FL 32225
United States
Email: [email protected]
Website: https://www.negativespace.dev
If you are a shopper, contacting the Shopify merchant first is usually the fastest way to exercise a privacy right connected to an order.
