Merchantwell
AppsCompanySupport
AOVLift ↗
AppsCompanyAOVLiftAddressSureSupport

Merchantwell legal

Privacy policyAddressSure privacyTerms of serviceData processing agreement

Questions?
support@merchantwell.com

Privacy Policy

Last updated August 10, 2026

This Privacy Policy explains how Merchantwell (“Merchantwell,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when Shopify merchants use our websites and apps, including AOVLift Post Purchase Upsell and AddressSure Address Validator (collectively, the “Services”), and when buyers interact with experiences powered by the Services.

Buyer notice

The Shopify merchant from whom you made a purchase is the primary contact for requests about your order or personal information. Merchantwell processes buyer information on that merchant’s behalf. AddressSure-specific details are also available in the AddressSure Privacy Policy.

1. Information we process

Merchant and account information

We process the merchant’s Shopify store domain, Shopify authentication and session information, authorized staff-account information supplied by Shopify, app configuration, product and variant information where applicable, billing status, usage units, and communications sent to us.

AOVLift buyer and checkout information

To evaluate merchant-configured targeting rules and present post-purchase offers, AOVLift may process a Shopify customer identifier, customer tags, number of previous orders, purchased product and collection identifiers, order value, country, and checkout reference. Customer tags and previous-order count are evaluated temporarily for targeting and are not stored in AOVLift’s database. AOVLift does not request buyer names, email addresses, phone numbers, or postal addresses for this functionality.

Offer performance information

We record offer impressions, declines, acceptances, the funnel and offer shown, product or variant identifiers, product title, revenue attributed to an accepted offer, and an opaque checkout reference. These records enable merchant-facing analytics and are not used to build independent buyer profiles.

AddressSure order and shipping-address information

AddressSure processes Shopify order identifiers and shipping-address fields needed to validate and, when authorized, update an order: recipient name, company, phone number, street address, city, state or province, postal code, and country or region. It also processes validation results, suggested corrections, merchant-configured shipping rules, and the customer or merchant action taken on a correction.

Website and technical information

Our infrastructure providers may process standard request information such as timestamps, IP addresses, browser or device information, and sanitized diagnostic logs to deliver and secure the Services. We use cookies and similar technologies only as necessary for authentication, security, and operation. AddressSure does not write raw addresses, access tokens, request bodies, or provider API keys to application request logs.

2. How we use information

  • Provide, secure, maintain, and troubleshoot the Services.
  • Apply merchant-configured AOVLift funnel, product, country, order-value, tag, and customer-type rules.
  • Display eligible offers and safely process accept or decline actions through Shopify.
  • Check shipping addresses after checkout and display useful suggested corrections.
  • Let authorized customers or merchants update a Shopify order’s shipping address.
  • Provide merchants with app analytics, order review tools, and selected order tags.
  • Administer subscriptions and usage billing, respond to support, comply with law, and prevent fraud or abuse.

We do not sell personal information, use buyer data for third-party advertising, or use it to make decisions that produce legal or similarly significant effects.

3. How we disclose information

We disclose information only as needed to operate the Services, including to Shopify, which provides the commerce platform, APIs, checkout, customer accounts, and billing services; Google, whose Address Validation API processes AddressSure shipping-address fields to return validation results and suggested corrections; Render, which provides production application hosting and managed database services; Namecheap, which provides business email services; professional advisers or authorities when required by law; and a successor in a merger, financing, acquisition, or sale subject to appropriate protections.

Service providers may process information only to provide their contracted services to us.

4. Retention and deletion

AOVLift customer tags and previous-order count used for targeting are discarded after the targeting decision. For AddressSure, encrypted order-address snapshots expire after 30 days, cached provider suggestions after 24 hours, completed webhook receipts after seven days, and encrypted queued webhook payloads after 30 days. Merchant configuration, validation status, correction actions, analytics, and usage records are retained while needed to provide the Services, support merchants, prevent duplicate charges, and meet legal obligations. Shopify authentication sessions are removed when an app is uninstalled. Store-associated application data is permanently deleted when Shopify sends its mandatory shop-redaction request, except records we must retain for a limited period to comply with tax, accounting, fraud-prevention, or other legal obligations.

5. Security

We use administrative, technical, and organizational safeguards appropriate to the information we process. Information is encrypted in transit using HTTPS/TLS and encrypted at rest by our managed infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

6. Privacy choices and requests

Buyers should submit access, correction, deletion, or other privacy requests to the Shopify merchant with whom they interacted. We assist merchants with verified requests and respond to Shopify’s mandatory customer-data and deletion webhooks. Merchants may request deletion of Service data or stop future collection by uninstalling the app, subject to legal retention requirements.

7. International processing

Information may be processed in the United States and other countries where Shopify or our service providers operate. Where required, we rely on contractual and other lawful transfer safeguards.

8. Children

The Services are intended for Shopify merchants and are not directed to children. We do not knowingly collect personal information from children independently of a merchant’s use of Shopify.

9. Changes to this policy

We may update this policy to reflect changes to the Services, law, or our practices. The date above shows when it was last updated. Material changes will be communicated as required by law.

10. Contact

For privacy questions, email support@merchantwell.com. Buyers should contact the merchant from whom they purchased first so the merchant can verify and route the request appropriately.

Merchantwell

Practical Shopify apps for better commerce.

support@merchantwell.com

Products

AOVLiftAddressSureBundlewell

Company

How we buildSupport

Legal

PrivacyTermsData processing
© 2026 Merchantwell. All rights reserved.Shopify is a trademark of Shopify Inc.