Cairn Loyalty & Rewards — Privacy Policy

Last updated 23 September 2026

Cairn is a loyalty and rewards app for Shopify stores. This policy explains what the app stores when a merchant installs it, why, for how long, and how to have it removed.

What Cairn stores

Why

Emails and consent

Program-status emails (points earned, reward issued, tier reached, birthday reward) are sent to members as part of the service. Reminder emails about expiring points are only sent to customers whose Shopify record shows email marketing consent. Merchants can turn any template off.

Retention and deletion

Where data is processed

No data is sold, shared with advertisers, or used to train models. No third-party scripts run on your storefront.

Security

Every request from Shopify is verified (webhook HMAC, app-proxy signature, session tokens). Personal data never appears in application logs. Secrets are stored as encrypted Cloudflare secrets. All data is encrypted in transit (TLS) and at rest, including Cloudflare's storage replicas and point-in-time recovery copies; Cairn keeps no other backups. Development and automated tests run only against synthetic data; production records are never copied into test environments. Operator access to production requires a single named account protected by a unique strong password and two-factor authentication, and every read of a member's name or email by the app, a merchant, or the operator is written to the store's access log.

Security incidents

If Cairn becomes aware of unauthorised access to, or loss of, personal data, it will: contain the issue (rotate the affected secrets, disable the affected route or store) within 24 hours of confirmation; notify every affected merchant by email within 72 hours with what happened, which data and customers were involved, and what has been done; notify Shopify through the Partner Dashboard; and publish a post-incident summary on the status page. Suspected incidents can be reported to security@keelcroft.com.

Data processing terms

By installing Cairn, the merchant instructs Cairn to process the personal data listed above solely to run the merchant's loyalty program. Cairn acts as a processor on the merchant's behalf: it processes only on these instructions, uses only the sub-processors named above (Cloudflare, Resend), applies the security measures described in this policy, assists with customer access and erasure requests through Shopify's compliance webhooks, deletes all data as described under Retention, and never sells or shares personal data or uses it for its own purposes. This section, together with the rest of this policy, is the data protection agreement between Cairn and each merchant.

Contact

Questions or deletion requests: privacy@keelcroft.com.