PayShift ("PayShift", "we", "us", or "our"), provided by The Cognitio Lab ("Cognitio Lab"), is a Shopify application that lets merchants hide, rename, and reorder payment and shipping methods at checkout. This Privacy Policy explains what information we collect, how we use it, and the choices you have when you install and use PayShift (the "App").
By installing or using the App, you agree to the practices described in this Privacy Policy.
1. Who this policy applies to
- Merchants — Shopify store owners and staff who install and use the App.
- Store customers — shoppers who interact with a merchant's checkout where the App is active. We process limited customer-related data only to evaluate checkout rules; we do not market to or independently contact store customers.
2. Information we collect
a. Information from the merchant and the Shopify store
When you install the App, with your authorization through Shopify, we may access and store:
- Store/shop details: shop domain, store name, store ID, primary contact email, currency, country, and plan.
- Configuration data you create in the App: your payment and shipping rules, conditions, method names, and rule settings.
- Available payment methods, shipping/delivery options, products, collections, and customer segments/tags, used so you can build rules.
b. Information processed at checkout
To evaluate your rules, the App (via Shopify Functions) processes checkout and cart context such as: cart total and currency, products in the cart, shipping/destination country and region, and customer type or tags. This processing happens to determine which payment or shipping methods to show, hide, rename, or reorder. We do not store customer personal data such as names, addresses, emails, or payment details.
c. Information collected automatically
- Basic usage and diagnostic data (e.g. pages used in the App, feature usage, error logs) to operate and improve the App.
- Product analytics and diagnostics about how merchants use the PayShift admin app (see section 5.1 regarding PostHog), including optional session recordings from the Shopify admin App UI.
- Standard technical data such as IP address, browser type, and timestamps for security and troubleshooting.
We do not collect or store customers' full payment card details. Payment processing is handled entirely by Shopify and its payment providers.
3. How we use information
We use the information above to:
- Provide, operate, and maintain the App and its core features.
- Apply your configured rules at checkout.
- Provide customer support and respond to your requests.
- Monitor, secure, debug, and improve the App.
- Comply with legal obligations.
We do not sell your data or store customers' personal data, and we do not use the data for advertising.
4. Legal bases for processing (GDPR)
Where the EU/UK GDPR applies, we process data on the bases of: performance of a contract (providing the App), our legitimate interests (securing and improving the App), and compliance with legal obligations. Where required, we rely on consent.
5. How we share information
We do not sell personal information. We may share data only with:
- Shopify, as the platform the App runs on.
- Service providers / subprocessors that help us run the App (e.g. cloud hosting, database, error monitoring), under agreements that require them to protect the data. Current subprocessors: Railway (application hosting and PostgreSQL database).
- PostHog — our product analytics provider (see section 5.1).
- Legal / safety disclosures when required by law or to protect rights, safety, and security.
5.1 PostHog (product analytics)
We use PostHog to understand how merchants use PayShift and to diagnose problems. Event data is sent to PostHog's European Union (EU) cloud at https://eu.i.posthog.com (EU data residency).
What we send: shop domain (used as the analytics identifier), admin app usage events (for example page views, payment and shipping rule create/update/toggle/delete, settings changes, billing return, and uninstall), optional session recordings and error reports from the Shopify admin app.
What we do not send to PostHog: customer personal data from checkout, payment card details, or shopper identifiers. We do not load PostHog's browser SDK on the merchant's Online Store theme for shoppers.
Why: to measure product adoption, improve features, monitor reliability, and investigate errors. PostHog processes this data as our service provider. For PostHog's own practices, see PostHog's privacy policy.
6. Data retention
We retain merchant and configuration data for as long as the App is installed. When you uninstall the App or request deletion, we delete or anonymize associated data within 30 days, except where we must retain it to meet legal obligations. We respond to Shopify's mandatory data deletion requests (see Section 8).
7. Data security
We use reasonable technical and organizational measures to protect data, including encryption in transit, access controls, and restricted internal access. No method of transmission or storage is 100% secure, but we work to protect your information and review our practices regularly.
8. Shopify mandatory data requests (GDPR webhooks)
In line with Shopify's requirements, we support the following data-subject webhooks:
customers/data_request— we provide any stored data relating to a customer upon a store's request.customers/redact— we delete stored data relating to a specific customer.shop/redact— we delete a store's data after the App is uninstalled (typically within 48 hours to 90 days, per Shopify's timeline).
9. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. To exercise these rights, contact us at cognitiolab1@gmail.com. Store customers should contact the merchant (the data controller); we will assist the merchant in responding.
California (CCPA/CPRA): We do not sell or share personal information as defined by the CCPA. California residents may request access or deletion via the contact below.
10. International data transfers
Your data may be processed in countries other than your own. Where required, we use appropriate safeguards for such transfers. Product analytics events sent to PostHog are processed in the EU (see section 5.1).
11. Children's privacy
The App is intended for businesses and is not directed to children under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, notify merchants. Continued use of the App after changes means you accept the updated policy.
13. Contact us
If you have questions or requests regarding this Privacy Policy or your data, contact:
The Cognitio Lab
Email: cognitiolab1@gmail.com