Cairn Loyalty & Rewards — Privacy Policy
Last updated 23 September 2026
Cairn is a loyalty and rewards app for Shopify stores. This policy explains what the app stores when a merchant installs it, why, for how long, and how to have it removed.
What Cairn stores
- Per member: Shopify customer ID, first name, email address, email marketing consent state, and — only if the customer enters it — birthday month and day.
- Per order: Shopify order ID and name, the order subtotal and the amount that qualified for points, the line items' SKU, vendor and gift-card flag, discount codes used, and any referral code attached to the cart. No shipping or billing addresses, no phone numbers, no payment details.
- Program data: the points ledger (every earn, redemption, reversal and expiry with a reason), redemptions and any discount codes issued, referrals, imports, email delivery events, and a log of every time a member's name or email was accessed.
- Merchant data: the store domain, store name, currency, time zone, the store owner's email address, the program settings, and the Shopify API session for the store.
Why
- Names and email addresses are used solely to send program emails (points earned, rewards, tier changes, reminders) and to personalise the storefront panel.
- Order totals are used to calculate points and to show the merchant member versus non-member revenue.
- The access log exists so merchants can see who accessed personal data and when.
Emails and consent
Program-status emails (points earned, reward issued, tier reached, birthday reward) are sent to members as part of the service. Reminder emails about expiring points are only sent to customers whose Shopify record shows email marketing consent. Merchants can turn any template off.
Retention and deletion
- Data is kept while the app is installed.
- Access-log records are deleted after 90 days.
- When a customer is erased through Shopify (
customers/redact), their ledger, profile and access records are deleted. - When the app is uninstalled, the program is frozen and the merchant receives a CSV export link valid for 48 hours. When Shopify sends the
shop/redactrequest 48 hours after uninstall, every record for the store is deleted. - Data-subject requests (
customers/data_request) are answered from the same records; merchants can also export a member's data from the Customers page.
Where data is processed
- Cloudflare (Workers and Durable Objects) hosts the app and stores all data. Each store's data lives in its own isolated storage object.
- Resend delivers program emails. Resend receives the recipient address and the email content.
- Shopify provides the customer, order and store-credit APIs the app calls.
No data is sold, shared with advertisers, or used to train models. No third-party scripts run on your storefront.
Security
Every request from Shopify is verified (webhook HMAC, app-proxy signature, session tokens). Personal data never appears in application logs. Secrets are stored as encrypted Cloudflare secrets. All data is encrypted in transit (TLS) and at rest, including Cloudflare's storage replicas and point-in-time recovery copies; Cairn keeps no other backups. Development and automated tests run only against synthetic data; production records are never copied into test environments. Operator access to production requires a single named account protected by a unique strong password and two-factor authentication, and every read of a member's name or email by the app, a merchant, or the operator is written to the store's access log.
Security incidents
If Cairn becomes aware of unauthorised access to, or loss of, personal data, it will: contain the issue (rotate the affected secrets, disable the affected route or store) within 24 hours of confirmation; notify every affected merchant by email within 72 hours with what happened, which data and customers were involved, and what has been done; notify Shopify through the Partner Dashboard; and publish a post-incident summary on the status page. Suspected incidents can be reported to security@keelcroft.com.
Data processing terms
By installing Cairn, the merchant instructs Cairn to process the personal data listed above solely to run the merchant's loyalty program. Cairn acts as a processor on the merchant's behalf: it processes only on these instructions, uses only the sub-processors named above (Cloudflare, Resend), applies the security measures described in this policy, assists with customer access and erasure requests through Shopify's compliance webhooks, deletes all data as described under Retention, and never sells or shares personal data or uses it for its own purposes. This section, together with the rest of this policy, is the data protection agreement between Cairn and each merchant.
Contact
Questions or deletion requests: privacy@keelcroft.com.