Skip to main content

Privacy Policy

Last updated: August 2026

Information We Collect

When you install BatchCard on your Shopify store, we collect the following information:

  • Shopify OAuth data: Your store name, store owner email address, and access tokens required to operate the app within your Shopify admin.
  • Gift card batch data: Gift card values, codes, quantities, recipient email addresses (when using email delivery), batch names, tags, and notes that you create through BatchCard.
  • Unsubscribe records: When a gift card recipient unsubscribes from BatchCard email, we store their email address and whether the request applies to your store only or to all BatchCard email, so that we can honor it. An unsubscribe that applies to all BatchCard email is kept across stores and is not deleted when a store uninstalls.
  • Contact form submissions: Name, email address, store URL (if provided), topic selection, and message content submitted through our contact form.
  • Analytics data: Anonymized usage data collected through Google Analytics (GA4) with your consent. This includes page views, session duration, and general device information. No personally identifiable information is sent to Google Analytics.

How We Use Your Information

We use the information we collect to:

  • Provide the BatchCard service, including creating gift card batches, capturing codes, and delivering gift cards via email.
  • Process gift card operations on your behalf through the Shopify API.
  • Respond to support inquiries submitted through our contact form.
  • Improve the service based on anonymized usage patterns.

We do not sell your data to third parties. We do not use your data for advertising purposes.

Shopify Data

BatchCard connects to your Shopify store through OAuth, the standard authentication method for Shopify apps. During installation, you authorize BatchCard to access specific store data.

BatchCard requests only the permissions necessary to manage gift cards on your behalf. This includes the ability to create, read, and manage gift cards within your store.

BatchCard also reads and writes customer records in your store. Whenever a batch includes recipient email addresses, BatchCard looks up each address as a customer in your store and creates a customer record when no matching customer exists. This happens for every batch that carries recipient email addresses, including batches created with notifications turned off and batches delivered through Klaviyo, because BatchCard links each gift card to a customer record in your store. Customer records that BatchCard creates are set to email marketing consent of not subscribed, so creating the record never opts anyone into marketing.

We do not access your order history, financial information, or any other store data beyond what is required for gift card operations.

Access tokens are stored securely and are used only to communicate with the Shopify API on your behalf.

Data Storage and Security

Your data is stored on secure servers with encryption at rest. All data transmitted between your browser, our servers, and the Shopify API is encrypted in transit using HTTPS (TLS 1.2 or higher).

Gift card codes are stored in encrypted format. Access to production data is restricted to authorized personnel only.

We follow industry-standard security practices and regularly review our security measures.

Third-Party Services

BatchCard uses the following third-party services to operate:

  • Google Analytics (GA4): Collects anonymized website usage data with your consent. No personally identifiable information is shared with Google. You can opt out through our cookie settings.
  • Resend: Delivers BatchCard reminder emails and contact form submissions. Resend receives recipient email addresses and the email content necessary to deliver those messages on your behalf. Gift card delivery emails themselves are sent by Shopify, not by Resend.
  • Klaviyo (optional): If you connect your own Klaviyo account and select Klaviyo as the delivery channel, BatchCard sends one event per gift card to Klaviyo so that your Klaviyo flows can deliver it. That event includes the recipient email address, recipient name, gift card code, balance, personal message, batch name, your store name, and the expiration date when one is set. While Klaviyo is connected, reminder emails are sent through Klaviyo instead of Resend. Your Klaviyo API key is stored encrypted and is deleted when your store data is deleted. Klaviyo receives nothing unless you connect it.
  • Upstash: Provides rate limiting for our contact form to prevent abuse. Upstash receives anonymized IP address hashes and request counts. No personal data is stored by Upstash.

GDPR Compliance

If you are located in the European Union or European Economic Area, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate personal data.
  • Right to erasure: Request deletion of your personal data.
  • Right to data portability: Request your data in a structured, commonly used format.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to object: Object to our processing of your personal data.

To exercise any of these rights, contact us at support@batchcard.app. We will respond to your request within 30 days.

Cookie Policy

BatchCard uses cookies for essential site functionality and, with your consent, for analytics. Our cookie consent system allows you to control which cookies are active.

You can manage your cookie preferences at any time through our cookie settings page.

Data Retention

We retain your data for as long as your BatchCard account is active (i.e., the app is installed on your Shopify store).

When you uninstall BatchCard, your batch data and gift card codes are retained for 2 days in case you reinstall. Permanent deletion runs when Shopify sends the shop/redact webhook, approximately 48 hours after uninstall. At that point your batches, gift card records, gift card codes, recipient details, balance history, reminder history, queued jobs, and stored Klaviyo credentials are permanently deleted, as are any unsubscribe records that apply only to your store.

Two things are kept on purpose. The first is a minimal record that your store installed BatchCard, uninstalled it, and had its data deleted. That record contains no store content, no gift card data, and no recipient data. The second is any email address a recipient used to unsubscribe from all BatchCard email across every store, which we keep so that an unsubscribe is never undone by a later installation. You can request removal of an unsubscribe record at support@batchcard.app.

Merchants on the Starter plan and above can additionally enable recipient data retention, which automatically and permanently removes gift card recipients' personal data (email address, name, and personal message) from delivered gift cards after a merchant-chosen window of 1, 7, or 30 days. Removed values are replaced with masked derivatives that cannot be reversed. Gift card codes, values, and balances are unaffected. This feature is off by default and each removal run is recorded for audit purposes.

You can request immediate deletion of all your data at any time by contacting us at support@batchcard.app.

Changes to This Policy

We may update this privacy policy from time to time. When we make significant changes, we will notify you through the BatchCard app or via the email address associated with your Shopify store.

Minor clarifications or formatting changes may be made without notice. The “Last updated” date at the top of this page reflects the most recent revision.

Contact

For questions about this privacy policy or how we handle your data, contact us at support@batchcard.app.