Serial & Warranty Tracker (“the app”, “we”) is a Shopify app that records serial numbers on orders, lets a store's customers register their products for warranty, and lets them open warranty claims. It is built and operated by Thallis Ribeiro, an individual developer in Brazil. Questions about this policy go to xthallis@gmail.com.
Two kinds of data, two roles
Merchants. When you install the app on your Shopify store, we are responsible for the data the app keeps about your store.
Your customers. When your customers register a product or open a claim on your store, you, the merchant, decide why that data is collected and how it is used. We process it on your behalf to run the registration and claim pages. Under the GDPR you are the controller and we are the processor; under Brazil's LGPD you are the controlador and we are the operador.
What the app stores about merchants
- Your shop's domain, for example yourstore.myshopify.com.
- The session Shopify issues when you install the app: an access token, the permissions you granted and when the token expires. If Shopify includes details of the staff member who opened the app (user ID, name, email, locale), they are stored with the session.
- Your settings: default warranty length, the questions on your registration form, the reply time shown to customers, the serial help text, and whether serials that aren't on an order are accepted.
- The products you track: product ID, title and warranty length.
- For each order line you capture: the serial numbers, product ID and title, order ID, order name (like #1038), line item ID and order date. The serials are also written to the order's
warranty.serialsmetafield in your Shopify store. - A count of emails sent each day for your store, used to enforce daily sending limits.
The app reads orders and products through Shopify's API to show which orders need serials. It does not read customer names, emails or addresses from your orders. Your store's contact email is read from Shopify when an email has to go to you, and is not stored. Shopify handles billing; we never see your payment details.
What the app stores about your customers
Only what a customer types into the store's registration, claim and status pages:
- Registration: serial number, name, email address, purchase date, and answers to the store's own questions (up to 10). When the serial matches an order, the product title, order name and order date are attached and the warranty end date is calculated. If the date the customer typed differs from the order date, it is kept too.
- Claims: the description of the problem, the claim's status and dates, the store's reply to the customer, and the store's internal note, which the customer never sees.
- Status lookups: the serial and email entered are used to find the claim and are not stored again.
Registrations that arrive after a store on the free plan has used its 50 registrations for the month are stored the same way, and shown masked to the store until it upgrades. The app's storefront pages set no cookies of their own and run no analytics or ad trackers. Cookies set by the store itself are covered by the store's own privacy policy.
What the app does with it
Only what warranty registration and claims need: link serials to orders, calculate warranty end dates, show the store a unit's history, show customers their claim status, export registrations to CSV for the store, and send the emails below.
Emails
When email is turned on for the app, it sends these messages through Resend, an email delivery service:
- To customers: a confirmation when they register, a receipt when they open a claim, and an update when the store replies or changes the claim's status.
- To the store's email address: an alert for each new claim, with the customer's name and email.
To deliver them, Resend receives the recipient's address and the message itself: product title, serial number, claim reference, status and the store's reply. Customer replies go to the store's email, not to us. When email is off, nothing is sent and no data goes to Resend.
Who else handles the data
- Shopify, the platform the app runs on. Data moves between your store and the app through Shopify's API and app proxy.
- Our hosting provider, which runs the app's servers and the database where the data above is stored.
- Resend, which delivers the app's emails when email is on.
- Google Fonts, which serves the typefaces on this website (not on your admin or storefront pages).
Each handles data only to provide its service. These providers may process data outside your country, including in the United States. We disclose data to anyone else only when the law requires it.
We do not sell or rent personal data, share it for advertising, or use it to build profiles.
How long data is kept, and how it is deleted
- While the app is installed, data is kept so that warranty records last as long as the warranties do.
- When a store uninstalls the app, Shopify sends
app/uninstalledand the store's sessions, including the access token, are deleted right away. - Shopify then sends
shop/redact, about 48 hours after the uninstall. The app deletes everything it holds for that store: serial records, registrations, claims, tracked products, settings, email counters and sessions. - When Shopify sends
customers/redactfor a customer, the app deletes that customer's registrations and claims at that store, matched by email address. - When Shopify sends
customers/data_request, the store finds that customer's registrations in the app by email and can export them in the registrations CSV and filter by email. Registrations locked on the Free plan don't appear in that search or export; they are provided on request via xthallis@gmail.com. - Serials written to an order's
warranty.serialsmetafield live in the merchant's Shopify store. Uninstalling does not remove them; the merchant manages them in Shopify. - Our hosting provider keeps standard server logs (such as IP address, time and requested page) for a limited period to run and secure the service. Copies in the provider's backups, if any, expire on its own schedule.
Your rights under the GDPR and the LGPD
Depending on where you live, laws such as the EU and UK GDPR and Brazil's LGPD give you rights over your personal data: to know whether it is processed and get a copy, to correct it, to have it deleted, anonymized or blocked, to restrict or object to its processing, to receive it in a portable format, to know who it is shared with, and to complain to a data protection authority (in Brazil, the ANPD).
If you registered a product or opened a claim on a store
Contact that store first. It controls your registration data and can find it, export it or delete it. You can also email xthallis@gmail.com with the store's name and the email address you used. We will confirm the request comes from you, involve the store where the law requires it, and reply within the time the law sets.
If you are a merchant
Email xthallis@gmail.com from your store's contact address, or uninstall the app to have your store's data deleted as described above.
Security
Data travels over HTTPS and is kept in the app's database at our hosting provider. The status page asks for both the serial and the email, and gives the same answer whether either one is wrong, so nobody can probe which serials exist. Storefront forms are rate-limited and filter out bots, and each store's daily email volume is capped. No system is perfectly secure: if a breach affects your data, we will tell the affected merchants without undue delay and as the law requires.
This website
This website sets no cookies and runs no analytics. Its fonts load from Google Fonts, so your browser sends Google a request, including your IP address, when you open a page.
Launch list. If you leave your email in the “Get notified at launch” form, we store only that email address and the time you signed up, with our hosting provider. We use it once, to tell you the app is listed on the Shopify App Store. Ask at xthallis@gmail.com and we delete it.
If you email us instead, we keep your message to reply and, if you asked, to tell you when the app launches. Ask and we delete it.
Children
The app is made for businesses. It is not directed at children, and we do not knowingly collect children's data.
Changes to this policy
We post every change on this page and update the date at the top. If a change affects how merchant or customer data is handled, we will tell installed merchants before it takes effect.
Contact
Thallis Ribeiro, Brazil · xthallis@gmail.com