MarginPin
Contact support

YOUR STORE. YOUR DATA.

Privacy policy

Last updated

MarginPin is operated by Codefern LLC (“we”, “us” or “our”). This policy explains how we handle information when you use our Shopify app to manage product prices and costs, visit this page, or contact us.

For support and privacy requests, email jason@codefern.com.

1. Information we process

Store and installation details
Your Shopify store identifier, domain, name, currency, time zone, permissions and installation status.
Product prices, costs and changes
Product and variant identifiers, titles, vendor names, SKUs, product status, selling prices and recorded item costs. We also store rules you save and records of previews and updates, including relevant product values, processing results and timestamps.
Merchant and staff accounts
Shopify authentication sessions can contain user identifiers, names, email addresses, language, account or collaborator attributes, permission scopes, expiry information, and access and refresh tokens.
Spreadsheets you upload
We process the product identifiers and proposed values in your Excel file to prepare changes. The original workbook is parsed in memory and is not saved as a file. Its filename, matched product details and proposed values can remain in preview and operation records. Please leave out buyer details and other information unrelated to product pricing.
Subscription details
We verify your plan and subscription status with Shopify. Shopify handles subscription approval and billing; MarginPin does not receive payment card numbers.
Service records and support messages
We record platform event identifiers, store domains, topics, timestamps and processing status. Technical logs can contain request metadata, network information such as IP addresses, and errors used to operate and secure the service. When you email us, we receive your address and the contents and attachments you choose to send.

MarginPin does not request access to buyer or order records, retrieve customer lists, or install tracking on your storefront. Merchant and staff account information is separate from buyer information. We do not save the original buyer details included in Shopify privacy notifications.

Shopify authentication and app navigation may use necessary cookies or browser storage. We do not use advertising cookies or add analytics trackers to this privacy page.

2. How we use information

We use information to:

  • Connect your store, authenticate access and apply your Shopify permissions.
  • Show cost coverage, prepare pricing previews and carry out changes you confirm.
  • Maintain saved rules, operation history and supported price restoration features.
  • Verify subscriptions, apply plan limits and prevent duplicate processing.
  • Troubleshoot errors, protect the service, respond to support and privacy requests, and meet applicable legal obligations.

We do not sell personal information or share it for targeted advertising. Saving a pricing rule does not apply it; product changes require confirmation in the app.

3. Providers and data location

We use service providers to run MarginPin, process support correspondence and store backups. They process information for these service purposes:

  • Shopify provides authentication, authorized store data, subscription services and platform notifications. Shopify also provides resources used to display the app and applies its own privacy policies to its services.
  • BandwagonHost hosts our application and primary database on a server in the United States.
  • Cloudflare R2 stores encrypted database backups with a Western North America location preference. This preference is not a guarantee of storage within a specific country.
  • Our email service provider processes messages sent to jason@codefern.com so we can respond to you.

Information may be processed outside your country, including in the United States, where data protection laws may differ. Email us with questions about our providers or data handling. We may also disclose information when required by applicable law or a valid legal request, or as necessary to protect legal rights and the security of the service.

4. Retention and backups

While the app is installed. We keep store information, saved rules and operation records needed for the app, including history, price restoration and usage accounting. Active-store operation history has no fixed automatic deletion period. You can contact us to request deletion as described below.

After uninstalling. When we receive a valid uninstall notification, we remove the store's authentication sessions and stop further pending work. On receipt of Shopify's store-deletion notification, we delete the still-uninstalled store's app records, including its saved rules, operation history, stored product values and related jobs. An earlier installation's notification must not erase a new installation.

Platform event receipts. We automatically remove completed or ignored event receipts more than 30 days after receipt. Events still awaiting processing are retained until they can be handled; processing failures can delay cleanup.

Technical logs and correspondence. Application logs rotate under storage limits rather than a fixed number of days. We retain technical and support records while needed to investigate errors, resolve requests, handle necessary follow-up or meet legal obligations. We review relevant records when handling a deletion request and remove or anonymize information no longer needed. We may keep a limited record of the request and its outcome to demonstrate how it was handled, explain any necessary retention and avoid restoring deleted data.

Encrypted backups. We schedule database backups daily. Backups are encrypted before upload to Cloudflare R2. After successful backups, snapshots outside a rolling seven-day window measured from the newest snapshot are removed, along with unreferenced backup data. Failures can delay cleanup while existing recovery points are preserved. Data deleted from the live database can remain in an older backup until that backup expires; we do not edit individual store records inside existing backups. Before restored data is used, we reapply applicable deletion requests completed after the backup.

5. Access, correction and deletion

Send a privacy request

Email jason@codefern.com with your store's .myshopify.com domain and what you want to access, correct or delete. For an individual account or support message, include only the details needed to locate it. Do not send passwords, access tokens or payment card details.

  1. We verify the request. We confirm your identity and authority for the information requested. We may ask for proportionate additional information to avoid disclosing or deleting another person's data.
  2. We act on the relevant records. We locate the app data and any related support records, then provide, correct, delete or anonymize the information as appropriate. To close and fully erase a store's app account, uninstall MarginPin so it stops receiving new store data. A request about individual information does not require deletion of the entire store account.
  3. We confirm the outcome. We aim to handle requests within 30 days of receipt and follow any shorter applicable legal deadline. If verification, a permitted extension or a legal retention obligation affects the request, we explain what remains, why and the next steps. Shopify privacy notifications are handled within its required timeframe.

If you are a buyer at a Shopify store

Contact that store first about its customer or order records. MarginPin does not retrieve those records. We accept Shopify's customer data-access and deletion notifications, but there are no buyer records collected through our Shopify API access to export or delete. If you sent us personal information directly in a support email, or believe it was included in an uploaded product field or file, contact us so we can investigate and handle that information. We do not treat these cases as automatically empty requests.

What deleting MarginPin data changes

Deletion removes the relevant records held by MarginPin. It does not delete products, customers or orders held by Shopify or the merchant, and does not undo prices or costs already written to Shopify. Deleted rules and history, including associated restoration information, are no longer available. Shopify handles its own subscription and billing records separately.

Depending on the law that applies to you, you may also have rights to obtain a copy of your information, restrict or object to processing, withdraw consent where processing relies on it, or complain to a data protection authority. You can contact us at the same email address to exercise applicable rights. We do not discriminate against you for making a privacy request.

6. Security and policy updates

We use HTTPS, restrict access to the database and backups, and check Shopify authentication and permissions for protected app actions. No storage or transmission method can guarantee absolute security.

We will post changes to this policy here and update the date above. Where required, we will provide additional notice of material changes. For questions, contact Codefern LLC at jason@codefern.com.