Privacy Policy

Last updated August 25, 2026

Who we are

Paytronix Gift Cards is a Shopify app built and operated by MalterTech LLC ("we", "us"). The app connects a Shopify store to that store's own Paytronix gift card program, so the store can sell digital gift cards on its storefront and let shoppers redeem a Paytronix balance at checkout.

This policy explains what the app collects, why, who it is shared with, how long it is kept, and how to reach us about it. It covers the app, its checkout and storefront extensions, its supporting API, and this website. It does not cover the practices of the Shopify store that installed the app, or of Paytronix, each of which has its own privacy policy.

We are not a party to the relationship between a store and its shoppers. Where the app handles a shopper's data, it does so on the instruction of the store that installed it.

The short version

  • We collect only what the app needs to sell, deliver, redeem, and reverse gift cards.
  • The only shopper personal data the app touches is an email address, and only so a purchased gift card can be delivered.
  • We set no cookies and use no tracking pixels or analytics, on this site, in the app, or on a merchant's storefront.
  • We do not sell personal data, share it for advertising, or use it to train machine learning models.
  • Gift card delivery records are deleted 30 days after the email is sent, and everything we hold for a store is deleted after it uninstalls the app.

Information we collect through Shopify's APIs

When a merchant installs the app, Shopify grants it a set of access scopes. The app currently requests read_discounts, write_gift_cards, write_gift_card_transactions, read_orders, write_orders, read_products, write_files, and read_files. Through those, and through the webhooks the app subscribes to, we collect:

Store information

  • The store's myshopify.com domain and numeric store ID, which identify the store on every record we hold.
  • The store name and the store owner's email address, read once at install to prefill the app's settings.
  • The store's Shopify subscription status for this app, so paid features can be enabled.

Order information

  • Order IDs, line items, order totals, and refund events, received from the orders/create and refunds/create webhooks. These tell the app that a gift card was purchased, that a redeemed balance was spent, or that an order was refunded and value has to be returned.
  • Gift card properties a shopper filled in at checkout, such as a recipient email address, sender name, message, and delivery date, when the shopper chose to send the gift card to someone else.

Customer email addresses

The app is registered with Shopify at Level 2 protected customer data and requests the email field only. When an order contains a gift card, the app reads the buyer's email address so the gift card can be delivered. It reads no customer name, phone number, billing address, or shipping address anywhere, and it stores no Shopify customer ID.

Gift card and file information

  • Shopify gift cards the app creates, adjusts, or deactivates in the course of a redemption, together with their balances.
  • Logo and gift card artwork a merchant uploads through the app, which is stored in that store's own Shopify Files.
  • Product information used to identify the merchant's gift card product, and discount information used to work out what a checkout still owes.

Information we collect directly from merchants

Merchants enter the following themselves, on the app's settings and gift card pages:

  • Business details: business name and a balance check URL, used to brand the gift card email.
  • Paytronix details: the store's Paytronix merchant ID and store code, and whether the app is pointed at the Paytronix test or production environment.
  • Mail server credentials: the SMTP host, port, encryption mode, username, password, and from address of the merchant's own mail server. The password is write only: it is stored on our server, never returned to the browser, and shown as a mask once set.
  • Email and error content: the copy, colors, and images used in gift card emails, and the wording shown to shoppers when a redemption fails.
  • Gift card inventory: a CSV of gift card numbers and registration codes, uploaded by the merchant.
  • Manual sale details: when a merchant sells a card by hand, the amount and, optionally, a recipient email address, sender name, and message.

We also generate automated logs of the app's own operation: errors, webhook processing, and background jobs. Anything written to those logs from a code path that touches order or customer data is put through a redactor first, which removes names, email addresses, phone numbers, and addresses before the line is stored.

Information we collect from merchants' customers

The app has two places where a shopper interacts with it directly:

  • At checkout. A shopper who wants to pay with a Paytronix gift card enters the card number and registration code. If the store sells gift cards and the shopper chooses to send one as a gift, they also enter the recipient's email address and, optionally, a sender name, a message, and a delivery date.
  • On the storefront. A shopper can check a gift card balance by entering the card number and registration code in the balance block. That lookup is passed to Paytronix and the balance is returned. We store nothing from it.

We do not track shoppers. The app drops no cookies and uses no tracking technologies on shoppers' devices. It does not use Shopify web pixels, and it does not log or infer how a shopper browses or navigates a store. It receives order data from Shopify only after an order is placed, and only for the purpose described above.

How we use the information

We use what we collect only to provide the app's services, specifically to:

  • sell a gift card through the merchant's Paytronix account when one is purchased;
  • deliver the gift card by email to the address the buyer or merchant supplied;
  • redeem a Paytronix balance at checkout, create the matching Shopify gift card, and return any unspent balance afterwards;
  • reverse a redemption when an order is abandoned, refunded, or reversed by the merchant;
  • show merchants their gift card inventory, sales, balances, and transaction history;
  • email merchants when gift card inventory is running low;
  • answer privacy requests Shopify forwards to us; and
  • diagnose faults, keep the app secure, and meet our legal obligations.

We use it for nothing else. The app has no marketing or advertising features. We do not use merchant or shopper data to build profiles, audience segments, or inferences, we do not sell or share personal data for advertising, and we do not use it to train machine learning models.

Who we share information with

We do not sell personal data and we do not disclose it except to the service providers below, each of which processes it only to run the app, and except where we are legally required to.

Recipient What it receives Why
Paytronix Gift card numbers, registration codes, amounts, and the merchant's own Paytronix merchant ID and store code. No shopper name, email, or address. The gift card program itself. This is the merchant's existing Paytronix account, reached with the merchant's own identifiers.
Shopify Gift cards created or adjusted for an order, and order tags and metafields recording gift card activity. Applying gift card value to the shopper's order and making the activity visible in the merchant's admin.
Amazon Web Services All app traffic and logs. Hosting the app's API and background jobs, in the US East region.
MongoDB Atlas The records described in this policy. Database hosting, in the United States.
Cloudflare QR code images of gift card numbers. No personal data. Object storage, so the gift card email can show a scannable code.
Better Stack Application logs, with personal data removed before they are written. Log aggregation and alerting.

Gift card emails do not go through our mail service. They are sent over the merchant's own mail server, using the SMTP settings the merchant supplied. The recipient's address therefore passes to the merchant's mail provider, which the merchant chose and controls.

How long we keep information

  • Gift card delivery records (recipient email address, sender name, and gift message) are deleted 30 days after the email is delivered, by a job that runs daily. A gift card scheduled for a future date is kept until it is actually delivered, and the 30 days start then.
  • Redemption and gift card inventory records are kept for as long as the app is installed, so refunds, reversals, and balance disputes can be settled. These records hold gift card numbers, registration codes, amounts, dates, and Shopify order IDs. They hold no shopper name, email address, phone number, or postal address.
  • Store settings and credentials are kept for as long as the app is installed.
  • On uninstall, the app's Shopify access token for that store is deleted immediately. Shopify sends a store redaction request 48 hours later, and we then delete everything stored for that store: settings, credentials, gift card inventory, redemption records, and any queued emails.
  • QR code images generated for gift card emails are retained in object storage. They encode the gift card number only and contain no personal data.
  • Application logs are retained on a rolling basis by our hosting and logging providers, with personal data removed before they are written.

Privacy requests and individual rights

Depending on where they live, individuals may have the right to access, correct, delete, or restrict the processing of their personal data, and to object to it. We have a process for receiving and answering these requests, and we do not charge for them or discriminate against anyone who makes one.

If you are a shopper

Contact the store you bought from. The store passes the request to Shopify, and Shopify forwards it to us. We hold no account of your own, so the store is the only party that can identify you to us.

If you are a merchant

Email us at support@maltertech.com. You can also delete everything we hold for your store at any time by uninstalling the app, which triggers the deletion described above.

How we answer Shopify's privacy requests

The app implements all three of Shopify's mandatory privacy webhooks:

  • Customer data request. We compile every record we hold for that shopper and email it to the store owner, within Shopify's 30 day window. If we hold nothing, we say so.
  • Customer redaction. We delete that shopper's queued and sent gift card emails, and remove the gift card number and registration code from their redemption records. The transaction record itself, meaning the amount, the date, and the Shopify order ID, is kept for financial reconciliation, and no longer identifies a card or a person.
  • Store redaction. We delete everything stored for the store.

Where your data is stored

MalterTech LLC is established in the United States and has no establishment in Europe. All data described in this policy is stored and processed in the United States, on Amazon Web Services in the US East region and on MongoDB Atlas.

If you are a merchant in the European Economic Area or the United Kingdom, using the app involves transferring data to the United States. Contact us at support@maltertech.com to put standard contractual clauses or another appropriate transfer mechanism in place.

How we protect information

  • All traffic to and from the app is over HTTPS.
  • The app has no login and no password of its own. Every request from the app's admin pages carries a short lived session token issued by Shopify, which our server verifies before it will load or change anything for that store.
  • Access to the Shopify Admin API uses Shopify's token exchange. The resulting token is held on our server and is never sent to the browser.
  • Merchant secrets, including the SMTP password, are write only: they are never returned to the browser and are shown as a mask once set.
  • Every Shopify webhook is verified against its signature before the payload is trusted.
  • Records are scoped to the store they belong to on every read and write, so one store's data cannot be reached from another's.

No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect what we hold and to keep only what we need.

Cookies and tracking

This website sets no cookies, runs no analytics, and hosts no advertising. It loads a web font from Google Fonts, which means your browser makes a request to Google's servers to fetch it.

The app sets no cookies of its own. Its admin pages, which run inside the Shopify admin, load Shopify App Bridge and a small number of open source libraries from public content delivery networks. Shopify sets its own cookies in the admin and on merchant storefronts, governed by Shopify's privacy policy, not this one.

Children

The app is a business tool sold to merchants and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, email support@maltertech.com and we will delete it.

Changes to this policy

We update this policy when the app's data practices change. The date at the top of the page always reflects the current version. Material changes are announced to merchants by email or in the app before they take effect.

Contact us

Questions about this policy, about what we hold, or about a privacy request go to support@maltertech.com, and we answer within 30 days.

We have not appointed a Data Protection Officer. Privacy enquiries are handled directly by MalterTech LLC at the address above.