Merchantwell
AppsCompanySupport
AOVLift ↗
AppsCompanyAOVLiftAddressSureSupport

Merchantwell legal

Privacy policyAddressSure privacyTerms of serviceData processing agreement

Questions?
support@merchantwell.com

AddressSure Privacy Policy

Last updated August 10, 2026

This policy explains how Merchantwell (“we,” “us,” or “our”) processes information when Shopify merchants install or use AddressSure Address Validator (the “Service”), and when buyers interact with AddressSure on Shopify’s Thank You or Order Status pages.

Buyer notice

The Shopify merchant from whom you purchased is the primary contact for questions or requests about your order and personal information. We process buyer information on that merchant’s behalf to validate and, when authorized, correct shipping addresses.

1. Information we process

Merchant and app information

We process the merchant’s Shopify store domain, Shopify authentication sessions and access scopes, AddressSure settings, extension activation observations, subscription status, usage units, and support communications.

Order and shipping-address information

AddressSure processes Shopify order identifiers and the shipping-address fields needed to validate and update an order: recipient name, company, phone number, street address, city, state or province, postal code, and country or region. We also process validation results, suggested corrections, merchant-configured shipping rules, and the customer or merchant action taken on a correction. AddressSure does not require a buyer’s email address for address validation.

Security and technical information

We use tenant-scoped hashes for customer and checkout references. Our infrastructure providers may process timestamps, IP addresses, device information, and sanitized diagnostic logs to operate and secure the Service. Raw addresses, access tokens, request bodies, and provider API keys are not written to application request logs.

2. Why we process information

  • Check shipping addresses after checkout and identify possible delivery problems.
  • Request and display a suggested correction when one is available.
  • Let an authorized customer or merchant update the Shopify order’s shipping address.
  • Show flagged and corrected orders in the merchant’s AddressSure dashboard.
  • Apply merchant-configured shipping rules, correction permissions, and correction windows.
  • Prevent duplicate provider requests and duplicate usage charges.
  • Secure, maintain, troubleshoot, and bill for the Service.

We do not sell personal information, use buyer data for third-party advertising, or use it to make decisions that produce legal or similarly significant effects.

3. Service providers and disclosures

We disclose information only as needed to operate the Service, including to:

  • Shopify, which provides the commerce platform, APIs, checkout, customer accounts, and app billing.
  • Google, whose Address Validation API processes shipping-address fields to return validation results and suggested corrections.
  • Render, which provides application hosting, networking, managed PostgreSQL storage, and encrypted backups.
  • Namecheap, which provides business email services when a merchant contacts support.
  • Professional advisers, authorities, or a successor when required by law or subject to appropriate protections.

4. Retention and deletion

Encrypted order-address snapshots expire after 30 days. Cached provider suggestions expire after 24 hours. Completed webhook receipts are removed after seven days, and encrypted queued webhook payloads expire after 30 days. Validation status, correction actions, and usage records are retained while needed to provide the Service, support merchants, prevent duplicate charges, and meet legal obligations. Shopify sessions are removed on uninstall. Store-associated data is permanently deleted after Shopify sends its mandatory shop-redaction request, subject to limited records we must retain for legal, tax, accounting, or fraud-prevention purposes.

5. Security

We use administrative, technical, and organizational safeguards appropriate to the information processed. Data is encrypted in transit using HTTPS/TLS. Address snapshots and provider suggestions receive application-level AES-256-GCM encryption, and Render encrypts PostgreSQL data and backups at rest. Access is limited to authorized systems and personnel.

6. Privacy choices and requests

Buyers should submit access, correction, deletion, or other privacy requests to the Shopify merchant with whom they interacted. We assist merchants with verified requests and respond to Shopify’s mandatory customer-data and deletion webhooks. Merchants may stop future processing by disabling AddressSure or uninstalling the app.

7. International processing

Information may be processed in the United States and other countries where Shopify or our service providers operate. Where required, we rely on contractual and other lawful transfer safeguards.

8. Changes to this policy

We may update this policy to reflect changes to AddressSure, law, or our practices. The date above shows when it was last updated. Material changes will be communicated as required by law.

9. Contact

For privacy questions, email support@merchantwell.com. Buyers should contact the merchant from whom they purchased first so the merchant can verify and route the request.

Merchantwell

Practical Shopify apps for better commerce.

support@merchantwell.com

Products

AOVLiftAddressSureBundlewell

Company

How we buildSupport

Legal

PrivacyTermsData processing
© 2026 Merchantwell. All rights reserved.Shopify is a trademark of Shopify Inc.