NORTH JS TECH
Skip to content
North Js Tech

Privacy Policy

Effective date:

Privacy Policy — Rich Cart Drawer And Upsell

Effective date: July 23, 2026

App: Rich Cart Drawer And Upsell ("the App")

Operator: NorthJS Tech ("we", "us", "our")

Website: https://cartdrawer.northjstech.com

Contact: support@northjstech.com

Rich Cart Drawer And Upsell is a Shopify app that provides a customizable cart drawer, upsells, and related cart features for Shopify stores. This Privacy Policy explains what information the App collects, how it is used, and the choices available to you.

This policy covers two groups of people:

Merchants — Shopify store owners and staff who install and configure the App.

Shoppers — visitors and customers of a merchant's storefront where the App's cart drawer is displayed.

If you are a shopper, the merchant whose store you visit is the controller of your personal data; we process shopper data on the merchant's behalf as described below. Please also review the privacy policy of the store you are shopping on.

1. Information we collect from merchants

When a merchant installs the App, we receive and store:

Store information: the store's myshopify.com domain and related shop identifiers.

Authentication data: Shopify OAuth access tokens and granted permission scopes, required for the App to function.

Staff account details: for the staff member who installs or uses the App, Shopify may provide a user ID, first and last name, email address, locale, and account status (owner/collaborator). This comes from Shopify's standard app session and is used only for authentication.

App configuration: the drawer designs, settings, templates, and feature configuration the merchant creates in the App's editor, including version history.

Shopify permissions (API scopes) we use

Products (write): Render and manage upsell/recommendation products and quick-add.

Inventory (read): Show low-stock and scarcity indicators from real stock levels.

Themes (read): Detect theme setup for compatibility and installation guidance.

Discounts (read/write): Create and apply discount features configured in the App.

Cart transforms (read/write): Power cart-level features such as free-gift logic.

Validations (read/write): Register checkout validation rules configured in the App.

Markets, locales, locations, publications: Localize content, show pickup locations, and publish App resources.

Files (write): Store files uploaded through merchant-configured cart custom fields.

Orders (read, via webhook): Receive order-paid totals for the merchant's analytics dashboard.

We do not request access to the merchant's customer database.

2. Information processed about shoppers

The App is designed to minimize shopper data collection. It does not build shopper profiles, does not track shoppers across sites, and does not use advertising identifiers.

Anonymous usage analytics. The storefront widget sends predefined events for the merchant dashboard. No shopper identity, IP address, or device identifier is stored.

Shared carts. Stores shared cart line items, custom properties, optional cart note, and Shopify customer ID (if logged in). Shared carts expire automatically (7 days by default, 30 days maximum).

Inventory reservations. Temporarily stores Shopify cart token, reserved variant IDs, and quantities. Reservations expire automatically.

File uploads. Files (up to 20 MB) are stored in the merchant's Shopify Files storage. We do not retain a separate copy.

Cart contents remain in Shopify and are accessed through Shopify APIs.

3. Cookies and browser storage

The App does not set cookies and does not use fingerprinting or advertising trackers.

Browser storage used for functionality:

rcd:saved — Save-for-later (localStorage)

rcd:recent — Recently viewed (localStorage)

rcd:cartq — Offline cart queue (localStorage)

rcd:timer — Countdown timer (sessionStorage)

rcd:reservation — Reservation countdown (sessionStorage)

This data remains on the shopper's device.

4. Third-party services

Shopify: Store, cart, and order data flow through Shopify APIs and are governed by Shopify's Privacy Policy.

Google Fonts: If enabled by the merchant, fonts load from Google servers and Google receives the shopper's IP address as part of the request.

The App does not use third-party analytics, advertising, session recording, or error tracking services and never sells or rents personal data.

5. Data retention and deletion

On uninstall: Store records, tokens, configurations, and related data are deleted.

Shared carts and reservations expire automatically.

Analytics events are stored as anonymous aggregates.

Merchants may request deletion by emailing support@northjstech.com. Requests are fulfilled within 30 days.

6. Shopify privacy webhooks (GDPR/CCPA)

customers/data_request

customers/redact

shop/redact

The App supports Shopify's mandatory privacy webhooks.

7. Your rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or port your personal data.

Shoppers should contact the merchant. Merchants may contact support@northjstech.com.

Legal bases: contract performance, legitimate interests, and legal compliance.

8. Security

Data is transmitted using HTTPS/TLS, stored in access-controlled databases, and Shopify tokens are stored securely server-side.

9. International transfers

Where required, international transfers are protected using appropriate safeguards, including standard contractual clauses.

10. Children

The App is intended for Shopify merchants and is not directed to children under 16.

11. Changes to this policy

We may update this policy from time to time. The effective date reflects the latest revision.

12. Contact

NorthJS Tech

Email: support@northjstech.com

Website: https://northjstech.com

Last updated:

Let's talk