Legal
Privacy Policy
This policy covers the edgecoms.com website, the Edge partner portal, and every app in the Edge suite. It was written app by app against what each one actually stores, rather than against what it is for.
Last updated: September 5, 2026
The short version
- We never sell your data, and we never use a merchant's shoppers to advertise anything of our own.
- Most of the apps store no shopper identifiers at all — they count anonymous events. The exceptions are named plainly in the table below.
- Trackproof is the one app that handles customer contact details. It encrypts them at rest and hashes them before they reach an advertising platform, and it only ever sends them to accounts the merchant connected themselves.
- Uninstalling deletes everything. Shopify sends us a redaction request about 48 hours later and the store's entire dataset is hard-deleted.
Who we are
Edgecoms (“we”, “us”) builds and operates the Edge suite of Shopify apps and the partner program at edgecoms.com. This policy explains what we do with personal data across all of them.
Privacy questions and data requests go to privacy@edgecoms.com.
Merchants, shoppers, and who answers for what
Two different relationships run through these apps, and the law treats them differently.
- Merchants and partners. When you install an app or join the partner program, we decide what to do with your data. We are the controller, and you can bring a request straight to us.
- Shoppers in a merchant's store. We only process shopper data on the merchant's instructions, to run the feature the merchant switched on. The merchant is the controller and we are the processor. If you are a shopper, your request goes to the store you bought from — they have tooling in the app to answer it, and we help them do so.
What we store about merchants
- Your shop domain, shop name, currency, timezone, Shopify plan and install state.
- The name and email address on the Shopify account that installed the app, from the session Shopify issues us.
- The configuration you create — bundles, timers, cart settings, selling plans, review flows, connected pixels.
- Aggregate revenue figures attributed to the app, which we use for your analytics and, where an app is priced on revenue, for billing.
- Support conversations you start in the in-app chat.
- Advertising platform credentials, where you connect them (Trackproof). These are encrypted at rest with AES-256-GCM and are never logged or shown back to the browser.
What each app stores about shoppers
The apps differ substantially here, so they are listed separately rather than covered by one paragraph. Each row says what the app writes to our database and what it explicitly does not.
| App | What it stores | What it does not collect |
|---|---|---|
| Edge Cart | Cart drawer events — opens, checkout clicks, upsell impressions and adds, discount code applications — each carrying a random session identifier and the cart total at the time of the event. | Names, email addresses, postal addresses, payment details, or any order contents beyond an anonymous checkout-click count. |
| Edge Bundles | Bundle views, add-to-carts, tier selections and purchases keyed to an anonymous per-tab session identifier; the Shopify customer identifier for signed-in shoppers so repeat-buyer analytics work; abandoned-bundle records where the merchant has switched recovery on; and a 90-day assignment cookie while an A/B test is running. | Customer names, phone numbers, postal addresses or payment details. Order line items and totals are read for revenue attribution; the customer fields on those orders are not. |
| Edge Timer | Timer impressions, each with an anonymous visitor identifier, IP address, browser user-agent, country, page URL and product identifier — the record behind the conversion reporting in the merchant's dashboard. | Names, email addresses, phone numbers, postal addresses or payment details. |
| Edge Reviews | Reviews a shopper chooses to submit, including the display name and any photos attached; the customer email address a review request is sent to; and an opt-out suppression list so somebody who unsubscribes is never emailed again. | Phone numbers, postal addresses or payment details. Review request emails are sent only for orders the merchant has configured a flow for. |
| Edge Currency | Currency widget views and switches, recording the currency moved from and to and the visitor's country, so the merchant can see which markets convert. | Any identifier for the visitor at all — no session id, no IP address, no cookies beyond the currency preference held in the shopper's own browser. |
| Edge Subscriptions | The subscription contracts the app runs on the merchant's behalf: customer email address and Shopify customer identifier, the charges raised against each contract, and a cancellation reason where the shopper gives one. | Payment card details. Subscriptions run on Shopify's native Subscription Contracts API, so card data stays with Shopify's payment processor and never reaches Edgecoms. |
| Trackproof | Storefront and order events — page views, product views, add-to-carts, checkout steps, purchases and refunds — together with the browser user-agent, IP address, page URL, referrer and Shopify browser identifier used for ad-platform match quality. Customer email, phone, name and billing or shipping location taken from orders are stored only as AES-256-GCM ciphertext, never in plain text, and are hashed with SHA-256 before being transmitted to any advertising platform. | Payment details. Raw email addresses and phone numbers are never transmitted to a third party and never logged. |
Across every app: we never collect payment card details. Payments stay with Shopify and its payment processors.
What the edgecoms.com website collects
- Advertising measurement. We run the Meta Pixel and Meta's Conversions API to measure how our own ads perform. Nothing loads and no request reaches Meta until you accept in the cookie banner. What is sent is the Meta cookie identifiers, your IP address and browser user-agent — not your email address. You can change your answer at any time from the link in the footer.
- Traffic analytics. Aggregate, cookieless page analytics from Vercel. These do not identify you.
- Forms you fill in. If you request a guide or playbook, we store the email address and optional store URL you typed, which button you submitted from, and when we sent the email. We use it to send you what you asked for and to follow up about the app it relates to.
- Abuse prevention. Form submissions are rate-limited by IP address in memory. That IP address is not written to our database.
What we store about partners
If you join the Edge partner program we store your name, email address and login credentials, the stores attributed to you, the commissions generated on them, and the payout method and reference you give us so we can pay you. A partner can only ever see their own merchants, earnings and commissions; that isolation is enforced in the database layer, not just in the interface.
Consent
Inside a merchant's storefront, tracking is gated on Shopify's Customer Privacy API. Where a store collects consent — for example under GDPR in the EU and UK — no events are sent and no cookies are written until the shopper has consented.
For Trackproof specifically: where an advertising platform does not honour browser-level consent signals automatically, we do not send events at all for a visitor who has declined marketing consent, and we forward Google Consent Mode v2 signals in the payload where the destination supports them.
Who else touches this data
| Sub-processor | Why | What it receives |
|---|---|---|
| Shopify | The platform the apps run on, the source of storefront and order events, and the biller for every subscription. | Shopify is the origin of this data rather than a recipient of it. Its own privacy terms govern the store. |
| Railway | Application hosting and the PostgreSQL databases behind the Edge apps. Servers are in the United States. | All app data described above, encrypted at rest. |
| Vercel | Hosting for edgecoms.com and cookieless aggregate traffic analytics for the marketing site. | Website request data. The analytics are aggregate and set no cookies; they do not identify a visitor. |
| Resend | Transactional email — merchant digests, review requests, subscription notices, and data-request exports. | The recipient's email address and the contents of the message being sent. |
| Sentry | Error monitoring and crash reporting. | Stack traces and request metadata. Customer personal data is not sent to Sentry. |
| Discord | In-app support messages are relayed to a private support workspace so the team can answer them. | The contents of a support conversation and the email address of whoever started it. |
| Meta, TikTok and Google | Destinations for Trackproof only, and only the accounts a merchant has connected themselves. | Conversion events, with customer identifiers hashed (SHA-256) before they are sent. Coarse location fields — city, region, postal code, country — are sent unhashed where the receiving platform requires that for matching. |
| LLM providers (Anthropic, OpenAI, Google or OpenRouter) | Power the AI copywriting and recommendation features inside Edge Bundles, depending on configuration. | Product titles, the merchant's brand-voice notes, and aggregate co-purchase counts. No shopper identifiers and no order records. |
We do not sell personal data, and we do not share it for cross-context behavioural advertising of our own products.
How long we keep it, and how it gets deleted
We implement Shopify's mandatory privacy webhooks in every app:
customers/data_request— Everything held about that shopper is compiled and returned to the merchant, who relays it. For Trackproof this is limited to event metadata and hashed identifiers.customers/redact— Every row tied to that shopper is deleted, matched on both the Shopify customer identifier and the email address.shop/redact— Sent by Shopify roughly 48 hours after an uninstall. The store's entire dataset — configuration, events, credentials and sessions — is hard-deleted.
Some data expires sooner than that, whether or not you uninstall:
- Edge Cart analytics events are purged automatically after 90 days.
- Trackproof event records are kept only as long as they are needed to deliver a conversion and power the verification dashboard, on a retention window the merchant sets to 30, 90 or 180 days.
- Marketing leads submitted on edgecoms.com are kept until the person asks for deletion.
- Everything else is retained while the app is installed and deleted on redaction or uninstall.
Security
- All traffic is encrypted in transit with TLS, and databases are encrypted at rest.
- Advertising platform credentials and stored customer contact details are encrypted with AES-256-GCM. They are decrypted in memory only at the moment they are needed.
- Customer email addresses and phone numbers are hashed with SHA-256 before they leave our systems for any advertising platform.
- Webhook and storefront ingestion requests are verified by HMAC signature and rate-limited. An endpoint that cannot verify a signature refuses the request rather than accepting it unsigned.
- Access to production systems is restricted to the operating team.
Your rights
Depending on where you live — including under the GDPR in the EU and UK, and the CCPA and CPRA in California — you may have the right to access the personal data we hold about you, correct it, have it deleted, object to or restrict how we use it, receive a portable copy, and not be discriminated against for exercising any of that. We do not sell personal data, so there is nothing to opt out of on that front.
If you are a shopper in a store that uses an Edge app, send your request to that store. They are the controller of your data and can action it through Shopify, which reaches us automatically. If you cannot reach them, write to us and we will help.
If you are a merchant or a partner, write to privacy@edgecoms.com and we will respond within 30 days. If you are in the EU or UK, you also have the right to complain to your local data protection authority.
International transfers
Our servers are in the United States. If you are outside the US, using the apps means your data is transferred there and to the sub-processors listed above. Where that transfer is out of the EU or UK, it is made under the European Commission's Standard Contractual Clauses and the UK Addendum.
Children
The Edge apps are business tools sold to merchants. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe we have, write to us and we will delete it.
Changes to this policy
We update this policy when what the apps do changes. The “last updated” date at the top always reflects the current version, and for a material change we will notify merchants in-app or by email before it takes effect.
Contact us
Privacy questions and data requests: privacy@edgecoms.com.
Anything else: support@edgecoms.com.