H
HijriBoost Shopify App · Apps Alchemy
Privacy Policy

Last updated: September 2026

HijriBoost is a Shopify application developed and operated by Apps Alchemy. This privacy policy explains what data we collect, how we use it, and how we protect your information when you use HijriBoost to plan Hijri calendar campaigns, publish storefront countdown banners, create event discounts, and collect widget leads in your Shopify admin.

Section 01
Information We Collect
HijriBoost collects data necessary to provide calendar campaigns, storefront widgets, discounts, and lead capture.

Merchant and store data

  • Your Shopify store domain and OAuth access token for authentication and API access
  • Staff session details provided by Shopify when you use the embedded app (for example name, email, and locale where Shopify supplies them)
  • Onboarding and administrative preferences such as primary market, reminder language, notification email, and onboarding state
  • Campaign configuration: event identifiers, names, discount type and value, discount codes, Shopify discount identifiers, start and end dates, and status
  • Custom event records you create, including English and Arabic names, image URLs, and date ranges
  • Shop metafield data used to display the live countdown banner on your storefront, as configured in the app
  • Reminder delivery logs (event, lead days, channel, and send time) used to avoid duplicate merchant reminder emails

Storefront widget lead data

  • Email address and optional first name submitted through the countdown widget
  • The related event identifier and the time of submission

We do not use HijriBoost to collect mailing addresses or payment card data. Payment processing for Shopify checkout and for app billing is handled entirely by Shopify and your payment providers.
Section 02
How We Use Your Data
We use the data we collect solely to operate HijriBoost:
  • Authenticate your store and keep a secure embedded-app session
  • Create, update, and remove event campaigns and automatic discounts in your store
  • Sync countdown metafields and theme-app-extension content so your storefront can display the live banner
  • Store and display widget leads in your admin, and export them when you request a CSV
  • Send merchant reminder emails about upcoming events to the notification address you configure
  • Fulfil Shopify’s mandatory privacy webhooks (customer data requests, customer redaction, and shop redaction)

We do not sell, rent, share, or trade merchant or customer personal data with third parties for advertising, marketing, or unrelated commercial purposes.
Section 03
Email and communications
HijriBoost does not send promotional email to your customers. Widget leads are stored for you, the merchant, so you can follow up according to your own policies. Subscription and receipt emails for app billing are handled by Shopify according to Shopify’s policies.

Merchant reminders

If you provide a notification email during onboarding, we may send operational reminders about upcoming calendar events to that address. These messages are not marketing to your storefront customers.

Support

If you contact us by email, we use your message and address only to respond to your request. We do not add you to marketing lists solely because you wrote to support.
Section 04
Data storage and security
Application data is stored in PostgreSQL databases on secure cloud infrastructure. We implement industry-standard measures including:
  • Encrypted connections (HTTPS/TLS) between clients and our servers
  • Secure OAuth and API access through Shopify
  • Environment-based management of secrets and credentials
  • Database access limited to the application services that require it

We do not store customer payment information; billing for the app is handled through Shopify.
Section 05
Data retention and deletion
We retain merchant configuration, campaigns, custom events, reminder logs, and widget leads for as long as HijriBoost remains installed and your store remains active in our system. When you uninstall the app, or when Shopify sends the mandatory shop data erasure webhook (typically 48 hours after uninstall), we delete app-held data for that store, including widget leads, merchant settings, related campaign records, and sessions. When Shopify sends a customer redaction request, we delete widget-lead records for that customer that we can match by email. You may request assistance with deletion or data questions by contacting us at
Section 06
GDPR and Shopify compliance webhooks
HijriBoost is designed to meet Shopify’s mandatory privacy requirements. We subscribe to Shopify’s compliance webhooks, including:
  • customers/data_request — we collect any widget-lead records we store for the requested customer (email, optional first name, event, and submission time) and email them to the merchant notification address so the store owner can respond
  • customers/redact — we delete widget-lead records associated with the customer email Shopify provides
  • shop/redact — we delete data associated with the store after uninstall or erasure as required, including widget leads, merchant settings, and sessions

Where the GDPR applies, merchants remain the data controller for their customers’ personal data; HijriBoost processes data on your instructions to provide the app.
Section 07
Third-party services
HijriBoost relies on:
  • Shopify APIs — to authenticate, read themes, write discounts, products, metafields, and metaobjects (within granted scopes), and operate the app proxy used by the storefront widget
  • Cloud hosting — to run the application and databases
  • Transactional email — to send merchant reminder emails and customer-data-request notices to the address you configure

Subprocessors and infrastructure providers process data only as needed to host and operate the service.
Section 08
Cookies and tracking
The embedded HijriBoost admin experience runs inside Shopify; session and security cookies follow Shopify’s practices as described in Shopify’s documentation. This standalone policy page does not set marketing cookies or third-party tracking scripts.
Section 09
Your rights and controls
As a merchant, you can:
  • Edit or delete campaigns, custom events, discounts, and countdown settings from the app at any time
  • View and export widget leads collected through your storefront widget
  • Uninstall HijriBoost to stop future data processing associated with the app
  • Contact us for privacy questions or assistance with data subject requests that involve our records
Section 10
Changes to this policy
We may update this privacy policy to reflect changes in our practices, technology, or legal requirements. We will revise the “Last updated” date on this page when we do. Continued use of the app after updates constitutes acceptance of the revised policy where permitted by law. We may notify you of material changes through the app or by email when appropriate.
Section 11
Contact
If you have questions about this privacy policy or HijriBoost data practices, contact:

Apps Alchemy


We aim to respond to privacy-related inquiries promptly.