ChargeItPrivacy Policy

Legal

Privacy Policy

Last updated: August 27, 2026

This Privacy Policy describes how CognitioLab ("we", "us", or "our") collects, uses, stores, and shares information in connection with the ChargeIt Shopify application (the "App"). By installing or using the App, you agree to this Privacy Policy.

1. Who we are

ChargeIt is developed and operated by CognitioLab. The App helps Shopify merchants configure payment-method fees and discounts at checkout based on a customer's declared payment choice.

For privacy questions or requests, contact us at cognitiolab1@gmail.com.

2. Scope

This policy covers information processed through:

  • The ChargeIt embedded admin interface
  • Shopify OAuth authentication and session management
  • Shopify Admin API access used to sync checkout configuration
  • Checkout and storefront extensions that apply merchant rules
  • Webhooks Shopify sends to the App (including uninstall and mandatory privacy compliance topics)

This policy does not replace Shopify's own privacy practices. Merchants remain responsible for their storefront privacy notices and for how they use fees or discounts in their markets.

3. Information we collect

3.1 Merchant and shop information

When you install or use the App, we may process:

  • Shop identifiers — shop domain (for example, example.myshopify.com), shop country, plan name, Shopify Plus status, and primary currency
  • Authentication data — OAuth access tokens and session records required to keep the App connected to your store
  • Staff account details provided by Shopify — when available through online sessions, fields such as staff user ID, name, email, locale, and account-owner flags
  • App configuration — fee and discount rules, payment-method targets, conditions, labels, currency overrides, announcement-bar settings, payment-choice appearance settings, and legality acknowledgements
  • Operational sync data — timestamps, sync status, error messages, and identifiers for app-created Shopify resources (for example fee catalog product, Cart Transform, Discount, and Payment Customization IDs)

3.2 Customer and order information

ChargeIt is designed to operate primarily on merchant configuration and on checkout context already available inside Shopify. In the current product:

  • Declared payment choice is stored as a cart/checkout attribute on Shopify (prefixed _chargeit_), not as a long-lived customer profile in our database
  • Rule conditions may reference cart data such as subtotal, products, collections, shipping country, customer tags, or guest vs logged-in status — evaluated inside Shopify Functions / checkout, not by copying full customer records into our servers
  • We do not intentionally collect or store customer names, emails, phone numbers, payment card details, or full order histories in our App database for reporting or marketing
  • The App may request additional Admin scopes only when a feature needs them. Order-history reporting is not part of the current product, so we do not request order-read scopes until that feature ships

3.3 Information we do not collect

  • Payment card numbers or full payment credentials
  • Customer passwords
  • Browsing data from unrelated websites
  • Advertising identifiers for sale or cross-app tracking

4. How we use information

We use the information described above to:

  • Authenticate merchants and maintain secure App sessions
  • Provide fee, discount, payment-choice, announcement-bar, and related checkout features
  • Sync compiled rules to Shopify Metaobjects, metafields, and Shopify Functions
  • Show plan/region capability warnings (for example US/Canada card-hide limits)
  • Respond to support requests you send us
  • Comply with Shopify platform requirements, including mandatory privacy webhooks and legal obligations
  • Improve reliability, security, and App performance
  • Measure product usage and diagnose errors in the Shopify admin App (see section 6.1 regarding PostHog)

We do not sell personal information. We do not use merchant or customer data for unrelated advertising networks.

5. Legal bases (where applicable)

Where privacy laws such as the GDPR or UK GDPR apply, we process data on one or more of these bases:

  • Contract — to provide the App you installed
  • Legitimate interests — to secure the App, prevent abuse, and improve core functionality in ways that do not override fundamental rights
  • Legal obligation — when we must respond to lawful requests or retain records required by law
  • Consent — where a specific feature or communication requires it

6. How we share information

We may share information with:

  • Shopify — as required to operate an embedded Shopify app, sync checkout configuration, and receive webhooks
  • Infrastructure providers — hosting, database, and related services that process data only to run the App under our instructions
  • PostHog — our product analytics provider (see section 6.1)
  • Professional advisors or authorities — when reasonably necessary to comply with law, enforce our rights, or protect merchants and users

We do not share App data with third parties for their own marketing purposes.

6.1 PostHog (product analytics)

We use PostHog to understand how merchants use ChargeIt and to diagnose problems. Event data is sent to PostHog's European Union (EU) cloud at https://eu.i.posthog.com (EU data residency). Events are tagged with app_name=chargeIt so they can be filtered when multiple CognitioLab apps share one PostHog project.

What we send: shop domain (used as the analytics identifier), admin App usage events (for example page views, rule create/update/toggle, settings changes, sync actions, and uninstall), and optional session recordings and error reports from the Shopify admin App.

What we do not send to PostHog: customer emails, phone numbers, payment card details, cart contents, or other storefront visitor personal data. We do not load PostHog's browser SDK on the merchant's Online Store theme, checkout UI extensions, or Shopify Functions for shoppers.

Why: to measure product adoption, improve features, monitor reliability, and investigate errors. PostHog processes this data as our service provider. For PostHog's own practices, see PostHog's privacy policy.

7. Data storage and security

App data is stored in secured cloud infrastructure with access controls appropriate to a Shopify app (encrypted transport via HTTPS, authenticated Admin API calls, and shop-scoped data isolation in our database).

No method of transmission or storage is 100% secure. We take commercially reasonable steps to protect information, but we cannot guarantee absolute security.

Depending on your hosting region and our infrastructure, data may be processed in countries other than where your store is located. Product analytics events sent to PostHog are processed in the EU (see section 6.1). Where required, we rely on appropriate transfer safeguards.

8. Data retention and deletion

  • While installed — we retain shop configuration and session data needed to operate the App
  • On uninstall — when Shopify sends the app/uninstalled webhook, we delete local ChargeIt shop data (rules, settings, sync history, related logs) and session records for that shop
  • Shop redaction — when Shopify sends the shop/redact webhook (typically 48 hours after uninstall), we again ensure shop data is erased from our systems
  • Customer data / redact requests — because we do not store customer personal profiles in MVP, customers/data_request and customers/redact requests are acknowledged and checked; there is normally no customer PII to export or delete from our database. If future features store such data, we will fulfill those requests within the timelines Shopify requires

Shopify may separately remove app-owned checkout configuration from the store on uninstall. Merchants may need to manually remove leftover catalog items (such as a fee product) if Shopify does not auto-delete them.

9. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. Merchants can:

  • Review and update App settings inside ChargeIt
  • Uninstall the App to stop active processing
  • Contact us at cognitiolab1@gmail.com to request access or deletion of merchant account data we hold

Store customers should contact the merchant (store owner) for requests about storefront orders and customer accounts. We will cooperate with merchants and Shopify on mandatory privacy webhooks.

10. Children's privacy

The App is intended for Shopify merchants and business users. It is not directed to children under 16, and we do not knowingly collect personal information from children.

11. Third-party services

The App runs on the Shopify platform. Use of Shopify is subject to Shopify's terms and privacy policy. We also use PostHog for product analytics as described in section 6.1. Links or integrations outside CognitioLab are governed by those third parties' policies.

12. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Continued use of the App after an update means you accept the revised policy. Material changes may also be communicated through the App or Partner listing where appropriate.

13. Contact

CognitioLab
App: ChargeIt
Email: cognitiolab1@gmail.com

If you have questions about this Privacy Policy or how ChargeIt handles data, please email us. We aim to respond promptly.

This Privacy Policy is provided for transparency and Shopify App Store compliance. It is not legal advice. If you need counsel for your specific jurisdiction or business, consult a qualified attorney.