Skip to main content

Legal

Privacy Policy

Plain-language overview of what RentalSuite collects when you install the app on Shopify, and what happens to that data.

Last updated July 28, 2026Refund policyContact support

Who this applies to

This policy covers:

  • Merchants who install and use RentalSuite on Shopify
  • Data that flows through Shopify APIs, webhooks, app proxy routes, and our app database
  • Messages you send us for support or account help

Shopify handles its own platform data under Shopify's privacy policy. That is separate from this page.

Shopify permissions we use

RentalSuite asks for Shopify API scopes that match what the app actually does. Here is what the main groups are for:

read_products / write_products

Link catalog items to rental profiles and keep product data in sync.

write_inventory

Update sellable stock when rentals, buys, and holds change availability.

read_orders / write_orders

Create and manage rental-related orders, bookings, and fulfillments.

write_draft_orders

Support admin New Booking and quote-to-booking flows.

read_customers / write_customers

Attach renters to bookings, inquiries, waitlists, and customer profiles.

read_locations / write_locations

Manage pickup locations and delivery-related settings.

read_discounts / write_discounts

Apply rental promotion codes where configured in the app.

subscription contracts

Power Subscribe rentals and related purchase options.

write_app_proxy

Serve storefront rental endpoints under your shop’s app proxy.

metaobjects / files

Store app configuration and media the rental experience needs.

We do not request broad marketing scopes beyond what rental operations and notifications need.

What we collect

Shop & installation

  • Shop domain
  • OAuth session details (scopes, token expiry, Shopify user/account metadata)
  • Whether you finished in-app onboarding
  • Billing plan and product-cap usage

Products, inventory & bookings

  • Linked product profiles (modes, rates, availability, SKU)
  • Inventory, serial units, holds, and location settings
  • Bookings, inquiries, subscriptions, waitlists, and purchase leads
  • Promotion codes and review content you manage in-app

Storefront & checkout helpers

  • Availability and quote requests served through the app proxy
  • Optional cart / payment hold identifiers tied to a checkout session
Session identifiers used for holds or analytics are for operations and counting. not profiles of individual shoppers outside your store.

Email & notifications

  • Recipient addresses from Shopify or booking/inquiry records when templates send
  • Template content you customize and send status for operational emails

We do not sell email open or click tracking as a marketing product.

How we use it

We use this data to run the app, for example:

  • Log you in and secure app proxy requests
  • Power storefront rentals, bookings, inventory, and subscriptions
  • Show dashboard metrics for your shop
  • Send booking and inquiry emails you configure
  • Respond to Shopify privacy webhooks when required

We do not sell merchant or customer data.

Who we share it with

Data may go to:

  • Shopify (APIs and webhooks, required for the app to work)
  • Hosting, database, email, and monitoring providers that help us operate the service
  • Authorities if the law requires it

We do not rent or sell data to ad networks.

How long we keep it

We keep data while your shop uses RentalSuite and as long as we need it for security, billing disputes, or legal requirements.

Shopify compliance webhooks also trigger deletion:

  • customers/redact. removes customer-linked rental records for that shop where required
  • shop/redact. removes shop data across sessions, products, bookings, and related tables
  • app/uninstalled. clears session/onboarding data and unlinks app resources where applicable

Security

We use measures such as:

  • App Proxy signature checks on storefront requests
  • Validation on IDs and event payloads
  • HTTPS in production
  • Access controls and logging for operations

No system is 100% secure, but we treat security as ongoing work.

Your rights

Depending on where you are, you may have rights to access, correct, delete, or export personal data, or to object to certain processing.

Shopify App Store apps also honor Shopify's mandatory webhooks: customers/data_request, customers/redact, and shop/redact.

International transfers

Our infrastructure may process data in countries other than yours. When required, we use appropriate safeguards for cross-border transfers.

Changes to this page

We update this policy when the app or legal requirements change. The date at the top of the page is the latest revision.

Contact us

Privacy questions or requests: