Encore

Privacy policy

Last updated: July 31, 2026

Encore never stores personal customer data. The recommendation engine needs to know that products were bought together — never who bought them. Everything Encore persists is a product identifier, an order identifier, or an aggregated counter.

What Encore stores

What Encore never stores

Customer names, email addresses, phone numbers, shipping or billing addresses, geolocation, customer ids, order totals (only a coarse band of the ratio between the offer's price and the order value), payment or fulfillment details, notes, or any free-text field that could contain personal data. Webhook payloads are processed in memory; only the fields listed above are extracted, and payloads are never persisted or logged.

Buyer-facing behavior

The post-purchase offer never uses personal data: the product is chosen from the store's aggregated co-purchase statistics, and any discount testing rotates per checkout, never per buyer identity — no profiling, no personalized pricing.

Deletion

Uninstalling Encore deletes every database row belonging to the store, including access credentials. Shopify's shop/redact compliance webhook re-runs the same purge as a safety net. Customer data requests and customer redaction requests are acknowledged immediately — there is no stored personal data to export or erase.

One narrow exception: a single record holding the store's public domain name and a count of how many free-plan upsells it has used is kept after uninstall, so the free plan's included quota is per store rather than resettable by reinstalling. It contains no customer, order or product data.

Security

Data is encrypted in transit (TLS between Shopify, the app and the database) and at rest (managed PostgreSQL volume encryption).

Contact

Questions: erdlightllc@gmail.com