SiloCipher
Privacy Policy
Last updated: August 15, 2026
Overview
SiloCipher ("we", "us", or "our") provides Shopify merchants with tools for GDPR, CCPA/CPRA, and DSAR compliance. The SiloCipher app includes an embedded admin for banner and privacy settings, a theme app embed (consent banner and privacy badge), Google Consent Mode v2 signaling, aggregated consent analytics, Shopify Billing for Free and Pro plans, and optional DSAR erasure cascades to merchant-connected platforms (such as Klaviyo or Gorgias).
This Privacy Policy explains how we collect, use, and protect information when merchants install and use SiloCipher at https://app.silocipher.com. For storefront visitors, SiloCipher processes data on behalf of the merchant (the merchant is the controller; SiloCipher acts as a processor / service provider).
Information we collect
- Shop and merchant settings: shop domain, installation status, and configuration saved in the SiloCipher admin (banner layout and regional rules, copy and styling, privacy badge settings, Google Consent Mode preferences, optional App API base URL, and optional Klaviyo / Gorgias API credentials for DSAR cascades).
- Session and authentication data: Shopify OAuth session tokens required to operate the embedded app securely.
- Subscription status: whether the shop has an active SiloCipher Pro subscription, checked through Shopify's Billing API. We do not receive or store payment card numbers; Shopify processes charges.
- Shop metafields we write: plan indicator (free/pro) and App API base URL on the shop, so the theme embed can load the correct configuration. These metafields are stored in the merchant's Shopify shop.
- DSAR / compliance webhook payloads: data Shopify sends for
customers/data_request,customers/redact, andshop/redact. Customer emails and other personal fields in stored payloads are redacted. For audit lookup we retain a SHA-256 hash of the customer email where applicable. Plaintext email is used only in memory to call merchant-configured cascade APIs and is not persisted. - DSAR audit logs: shop, webhook topic, processing status, timestamps, cascade outcomes (for example Klaviyo / Gorgias), and the email hash described above — for merchant compliance reporting in the admin.
- Aggregated consent analytics: when the storefront embed is active, the banner may send a lightweight beacon with shop domain, event type (accepted, declined, preferences, or impression), country code, and date. We store daily aggregates per shop and country — not visitor names, emails, IP addresses, or device IDs.
How we use information
- Provide, secure, and improve the SiloCipher application
- Serve storefront banner configuration and apply Free / Pro feature gating
- Process DSAR and privacy-law compliance webhooks from Shopify
- Cascade erasure or data-request handling to merchant-configured third parties (for example Klaviyo or Gorgias) when API credentials are supplied
- Display audit evidence, consent analytics, and plan status to merchants in the embedded admin
- Sync plan and App API URL metafields so the theme embed stays aligned with billing and settings
- Respond to support and security incidents
Storefront consent & cookies
When the SiloCipher Embed theme extension is enabled, the storefront may:
- Set a first-party cookie (
silocipher_user_consent) to remember a visitor's Accept or Decline choice - Write preferences through Shopify's Customer Privacy API
- Update Google Consent Mode v2 signals via
dataLayerwhen the merchant has Consent Mode sync enabled - Load banner settings from SiloCipher's public storefront config API (using the shop domain), and optionally send the aggregated consent analytics beacon described above
That storefront processing is performed on behalf of the merchant for their visitors. Merchants remain responsible for their own privacy policy, cookie disclosures, and lawful basis toward shoppers.
Data sharing
We do not sell personal information. We share data only with: (1) infrastructure providers that host the app and database (for example cloud hosting and Supabase), under contractual safeguards; (2) Shopify, as required to run an embedded app and Billing; (3) third-party platforms merchants explicitly connect for DSAR cascade (such as Klaviyo or Gorgias); and (4) authorities when required by law.
Retention & deletion
When a merchant uninstalls SiloCipher, we deactivate merchant settings, clear stored third-party API credentials, remove Shopify sessions for that shop, and record an uninstall audit entry as needed for compliance. Merchants may contact us to request deletion of remaining app data subject to legal retention requirements. Shopify may retain its own copies of webhook or billing records according to Shopify's policies.
Security
We use industry-standard measures including encrypted transport (HTTPS / TLS), access-controlled databases, and HMAC validation for Shopify webhooks. Optional integration API keys are stored server-side for the merchant's shop and are not exposed to the storefront. No method of transmission or storage is completely secure.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data, and to opt out of the sale or sharing of personal information under CCPA/CPRA. Merchants and their customers should also use Shopify's privacy tools and the SiloCipher DSAR workflows where applicable.
Contact
For privacy questions about SiloCipher, email support@silocipher.com or contact us through the support channel on the SiloCipher Shopify App Store listing.
This page is provided for transparency and Shopify App Store compliance.