SiloCipher

Privacy Policy

Last updated: August 15, 2026

Overview

SiloCipher ("we", "us", or "our") provides Shopify merchants with tools for GDPR, CCPA/CPRA, and DSAR compliance. The SiloCipher app includes an embedded admin for banner and privacy settings, a theme app embed (consent banner and privacy badge), Google Consent Mode v2 signaling, aggregated consent analytics, Shopify Billing for Free and Pro plans, and optional DSAR erasure cascades to merchant-connected platforms (such as Klaviyo or Gorgias).

This Privacy Policy explains how we collect, use, and protect information when merchants install and use SiloCipher at https://app.silocipher.com. For storefront visitors, SiloCipher processes data on behalf of the merchant (the merchant is the controller; SiloCipher acts as a processor / service provider).

Information we collect

How we use information

Storefront consent & cookies

When the SiloCipher Embed theme extension is enabled, the storefront may:

That storefront processing is performed on behalf of the merchant for their visitors. Merchants remain responsible for their own privacy policy, cookie disclosures, and lawful basis toward shoppers.

Data sharing

We do not sell personal information. We share data only with: (1) infrastructure providers that host the app and database (for example cloud hosting and Supabase), under contractual safeguards; (2) Shopify, as required to run an embedded app and Billing; (3) third-party platforms merchants explicitly connect for DSAR cascade (such as Klaviyo or Gorgias); and (4) authorities when required by law.

Retention & deletion

When a merchant uninstalls SiloCipher, we deactivate merchant settings, clear stored third-party API credentials, remove Shopify sessions for that shop, and record an uninstall audit entry as needed for compliance. Merchants may contact us to request deletion of remaining app data subject to legal retention requirements. Shopify may retain its own copies of webhook or billing records according to Shopify's policies.

Security

We use industry-standard measures including encrypted transport (HTTPS / TLS), access-controlled databases, and HMAC validation for Shopify webhooks. Optional integration API keys are stored server-side for the merchant's shop and are not exposed to the storefront. No method of transmission or storage is completely secure.

Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data, and to opt out of the sale or sharing of personal information under CCPA/CPRA. Merchants and their customers should also use Shopify's privacy tools and the SiloCipher DSAR workflows where applicable.

Contact

For privacy questions about SiloCipher, email support@silocipher.com or contact us through the support channel on the SiloCipher Shopify App Store listing.

This page is provided for transparency and Shopify App Store compliance.