What your own policies need to say
The app writes attributes to carts and orders on your store, so your privacy policy should mention it.
We publish our own privacy policy covering what we do. This article is about what yours should cover, because on your store you are the data controller.
What happens on your store
When someone plays the game, the app writes a small set of attributes into their cart: the campaign, a random session token, the gifts granted and their display names, and the offer’s expiry. These persist onto the resulting order and are visible in your Shopify admin.
None of them contain personal data. They are identifiers for a play, not a person.
What to add to your privacy policy
A sentence covering it is enough for most stores. Something like:
When you use our gift-reveal game, we store a random identifier for that session in your cart so the gifts can be applied to your order. This identifier does not contain personal information. The game is provided by Flip to Win, whose privacy policy is at fliptowin.app/privacy.
Adjust to match how the rest of your policy reads.
What you do not need
- No cookie banner change. The game page sets no cookies and uses no browser storage. Shopify strips cookies from app-proxy requests, so it could not set one if it tried.
- No consent gate. Nothing is collected that requires consent.
- No extra data-processing disclosure to Shopify. The app’s access to order data is already covered by Shopify’s protected customer data programme, approved at install.
If you need a data-processing agreement
Email us and we will provide one. Some EU merchants need a signed DPA for their records even where the processing is minimal.
Ad platform terms
Separate from privacy: your ad account’s own promotion rules apply to how you advertise the offer. See Ad platform notes.
Did this answer it?