Privacy policy
Last updated: July 22, 2026
This policy covers North Fox Apps ("we", "us") and our Shopify applications, including FairConsent. We build privacy tooling, so we hold ourselves to the standard our products exist to enforce: collect as little as possible.
What we collect from merchants
When you install one of our apps on your Shopify store, we receive and store:
- Your store’s
myshopify.comdomain and an API access token, which are required for the app to function. - The app’s own settings (for FairConsent: region mode, country list, plan tier). These are stored in your own store’s metafields on Shopify, not on our servers.
- Billing status (which plan you subscribe to), managed entirely by Shopify’s billing system.
We do not collect your name, email address, or any personal information beyond what Shopify provides for app operation.
What we collect from your store’s visitors
Nothing is stored by us. FairConsent’s banner runs entirely in the visitor’s browser. Consent choices are recorded via Shopify’s Customer Privacy API and in the visitor’s own browser storage — they never reach North Fox Apps servers.
When a merchant enables geo-targeting, the visitor’s IP address is used transiently in memory to resolve a country code. The IP address is not logged, not stored, and not shared. The resolved country (e.g. "DE") is cached in the visitor’s own browser for the session.
Cookies and similar technologies
Our apps set no cookies of their own on storefronts. FairConsent writes the visitor’s consent choice to their browser’s local storage under the key fairconsent:v1 so their decision is remembered. Consent state recorded through Shopify’s Customer Privacy API is governed by Shopify’s own cookie policy.
Data sharing
We do not sell, rent, or share any data with third parties. We use no third-party analytics, advertising, or tracking services in our apps or on this website.
Data retention and deletion
- Uninstalling an app removes its storefront code automatically and revokes its API access.
- We honor Shopify’s mandatory privacy webhooks: on shop data erasure requests we delete all stored data for that shop (which consists of the API session record).
- App settings live in your store’s metafields and remain under your control at all times.
GDPR & CCPA
For merchants and their customers in the EEA, UK, and Switzerland: our lawful basis for processing the minimal data above is the performance of the app service you install. For California residents: we do not sell personal information as defined by the CCPA/CPRA.
Contact
Privacy questions: northfoxapps@gmail.com.