Extra Product Options is a Shopify app that adds extra fields to a product page — gift wrap, engraving, an upload, a delivery date — and charges for the ones a shopper picks. This policy explains exactly what the app reads, what it keeps, and for how long.
The app reads no customer records and identifies nobody. It requests no customer scope, and no table in it holds a name, an email address, an order, or anything tying one shopper to another visit. The one thing it keeps that came from a shopper is a receipt for an uploaded file, described below, and no shopper is recorded against it.
Five access scopes, and what each one is for:
| Scope | What it is used for |
|---|---|
read_products |
Product and collection titles for the pickers a merchant chooses which products to price with, and turning a product tag into the list of products carrying it. |
write_products |
Writing the merchant’s pricing rule onto each of those products as an app-owned metafield. This is the only copy the checkout function can read, because Shopify Functions cannot make network requests. |
write_cart_transforms |
Registering the function that prices a cart line. |
write_files |
Asking Shopify for a pre-signed upload target when a shopper attaches a file, registering what they uploaded as a file on the store, and deleting the ones nobody ever bought. The file never passes through this app — the browser sends it straight to Shopify’s own storage host using a target this app asked for on its behalf. |
read_themes |
Reading the published theme’s config/settings_data.json to tell whether the app’s block has been switched on, so the setup checklist can say so. Theme content is not stored. |
The app does not request read_customers, read_orders or
any other customer scope. It cannot see who bought anything.
| Data | Why | Retained |
|---|---|---|
| Shopify session and access token | To call the Shopify API on the store’s behalf | Until uninstall |
| Price rules — the fields, formulas and targets a merchant creates, and the ids of the products each was published to | They are the merchant’s own work, and the app has to know which products to clear a rule from when it changes | Until deleted, or until the shop is redacted |
| Per shop: which plan it is on, the id of its registered cart transform, and the last time its storefront asked the app for a rule | Billing, knowing pricing is registered, and telling the merchant whether the options form is live on their theme | Until the shop is redacted |
| An upload receipt: the Shopify file id of an uploaded file, its address on Shopify’s CDN, its name and its size. No shopper is recorded against it. | A shopper who attaches artwork and then leaves would otherwise leave that file in the merchant’s Files for good, and nothing else in the system knows it is unwanted. The receipt is what lets the app delete it. | Deleted with the file about a week after it is uploaded, unless it reached a cart; receipts for files that did are kept while the file is, and all of them go when the shop is redacted |
That is the whole of it. There is no analytics table, no event log, and no copy of any order.
The measurements and choices a shopper enters — a width, a finish, a file they upload — are attached to their cart line and become part of the order, where Shopify stores them as ordinary order data. The merchant reads them there, on the order, as they would any other line item property.
This app does not store what they typed and never reads it back. While the shopper is on the product page, their browser asks the app which rule applies to that product; that request carries the shop and a product id, and nothing about the person. Uploaded files go to Shopify, not to this app.
There is no third-party service of any kind: no analytics, no advertising, no error reporting, no chat widget, no fonts or scripts loaded from anywhere else. Nothing is sold or shared with anyone.
shop/redact request, sent 48 hours after uninstall,
deletes everything the app holds for that shop: its rules, its settings and its
sessions.
customers/data_request and customers/redact
requests are answered, and there is nothing to return or erase, because no
customer data is held.
On the app’s own server, operated by add-ons.org. Access to it is limited to the people who run the app.
If what the app reads or stores changes, this page changes with it and the date above is updated.
Questions about this policy, or a request about data held for your shop: https://add-ons.org/contact/