Skip to content
SproutCart

Heardabout privacy policy

Heardabout stores the answers shoppers give to the survey on the thank-you page, the order each answer came with, and the total of every order the store receives so that answers can be weighed by revenue. It stores no names, email addresses or postal addresses. Everything lives in the app's own database.

Effective · Questions: hello@sproutcart.co

Who is responsible

Heardabout is a Shopify app built and operated by SproutCart, an independent Shopify developer. A merchant installs it on their store; the merchant's own privacy policy also applies to their customers. For anything on this page, write to hello@sproutcart.co.

Heardabout is in development and is not yet offered for install on the Shopify App Store. This page describes what the app's code does today.

What the app stores

  • Survey answers: the option a shopper picked, a 0–10 score, and free text of up to 500 characters. From: Shoppers who answer the survey on the order confirmation page. Why: To show the merchant which answers came with which orders, and the revenue behind each answer.
  • The order ID and confirmation number each answer came with. From: The checkout, at the moment the shopper submits. Why: To join an answer to its order, and to accept only one answer per order.
  • The Shopify customer ID of the shopper who answered — only when they were logged in to a customer account. From: The session token Shopify gives the thank-you page. Why: So that a customer redaction request can find and delete that customer's answers.
  • The ID, total and currency of every order the store receives. From: Shopify, through the orders/create webhook. Why: An answer counts only once its order is confirmed, and the response rate needs the number of orders.
  • The store's domain, its offline access token, its name, its surveys and its settings (admin language and two preferences). From: Shopify, at install, and the merchant in the app's admin. Why: To run the app for that store.

What it does not store

  • No customer names, email addresses, phone numbers or postal addresses.
  • No order line items and no payment details — only the order's ID, total and currency.
  • No IP addresses, and no analytics or tracking code in the survey block.
  • Nothing the app stores is sent to an AI service.

Where it is stored

In the app's own database, on the server that runs the app. The production hosting provider has not been chosen yet, because the app is not yet offered for install; it will be named here before it is.

Services that see the data

  • Shopify — The platform the app runs on. Every piece of data above starts there. What it sees: Everything listed above.
  • Inngest — Runs the app's background jobs, such as recording a new order. What it sees: For each new order, only its ID, total and currency and the store's domain. Inngest keeps its own event history under its own retention, outside the app's database.
  • An email delivery service (SMTP) — Sends the merchant one welcome email at install, and the reply to a customer data request, sent to the store's own email address. What it sees: The store's contact email address and name; for a data request, everything listed above that is stored for that customer.

The app does not sell, rent or trade any of this data, and does not use it for advertising. It is not shared with anyone beyond the services above.

When it is deleted

  • The merchant uninstalls the app: The access token, the store's name and its billing record are deleted immediately. Surveys, answers and order totals are kept for now, so a reinstall within 48 hours keeps them.
  • Shopify sends shop/redact, 48 hours after uninstall: Every survey, every answer and every stored order total for the store is deleted. The store's settings row (the admin language and two preferences) goes with it.
  • Shopify sends customers/redact for a customer: Every answer given while logged in as that customer, every answer on an order Shopify lists in the request (which covers guest checkouts), and the stored totals of those orders are deleted.
  • Otherwise: Nothing expires on a timer. Answers are kept until one of the events above.

Customer data requests

When Shopify sends a customers/data_request, the app collects the customer's answers (by logged-in customer ID and by the orders Shopify lists) and those orders' totals and emails it to the store's own email address in Shopify, for the merchant to pass on to the customer. If it cannot reach the store (the app was uninstalled), it sends nothing.

Changes to this policy

When what the app stores or who sees it changes, this page changes with it and the effective date above moves.

Contact

hello@sproutcart.co. For help using the app, see the Heardabout support page.