Effective Date: April 1, 2026
Orders-Limiter (“we,” “us”) — a Shopify app that helps merchants set and enforce quantity rules (minimum and maximum quantities, multiples, and subtotal caps), order-wide limits, and per-customer lifetime purchase caps on the storefront and at checkout (including via theme app extension and checkout/cart validation functions).
write_products (which includes read access). We read product data from the Admin API (for example identifiers, handles, and collection membership) to evaluate rules and to maintain internal mappings of which products, variants, and collections are associated with which rules for storefront and checkout enforcement. We use write access only when a feature needs to update product data in Shopify. We do not use catalog data to build profiles of individual buyers.read_themes, we access theme information as needed to support the theme app embed and related integration.orders/paid webhook) and store a running purchase total keyed to the Shopify customer ID and product variant. We store only the customer ID and aggregated quantities — we do not store names, emails, addresses, or payment details for this purpose. This data is used solely to determine whether a customer has reached a merchant-defined limit.customers/data_request, customers/redact, shop/redact).Data is stored in the database and infrastructure configured for this app (for example PostgreSQL). We retain session, shop, billing, rule, lifetime-cap, customer purchase-total, and usage records only as needed to run the service. When you uninstall, we remove OAuth sessions and delete the app-held rule and customer data for that shop. After uninstall, Shopify sends a shop/redact webhook; we then delete any remaining app-held data for that shop — including quantity, order, and subtotal rules, lifetime caps, customer purchase totals, usage records, shop and billing records, and any remaining sessions — to the extent we hold them.
We do not sell your data. We may use trusted subprocessors (for example hosting and email) that process data only to operate the app. Shopify processes data as the platform provider under Shopify’s terms and policies.
Depending on your region, you may have rights to access, correct, or delete personal data we hold about you as a merchant or staff user, or about your customers. When Shopify sends a customers/redact request, we delete that customer’s purchase totals and lifetime-cap records for your shop. Contact us at support@orders-limiter.erg.st, or use the support channel listed on the Shopify App Store listing. Uninstalling the app clears access tokens from our side and triggers Shopify’s shop data erasure flow for remaining merchant- and customer-associated records we store for that shop.