Privacy
v1 · updated 16 September 2026
Rulestage runs inside your Shopify admin and holds the rules you write, the versions you publish and a record of the decisions it explains. It reads the minimum customer data your own rules need, and it stores a hashed customer id instead of the id itself.
Seller: WaveApp LLC
Checkout: Shopify
Contact: support@rulestage.com
Product domain: rulestage.com
Contact: support@rulestage.com (Cloudflare Email Routing to the WaveApp LLC mailbox, the same arrangement as every other WaveApp product; Rulestage sends no email of its own).
1. What never happens
- Rulestage stores no customer name, email address, phone number or postal address. It never asks Shopify for those fields.
- No third-party service receives a customer's data from Rulestage. There is no advertising, no profiling, no enrichment and no data sale.
- The marketing website never touches a store's Shopify data.
- The checkout function runs with no network access, so a decision at checkout sends nothing out of Shopify.
- No raw shopper identifier is written to a decision record.
2. Data we touch
2.1 Your rules and your settings
Data: rule drafts, published rule versions, scenarios, settings, and the activation state of the app for your shop.
Used to: run the simulator, analyse conflicts, publish a version to Shopify's checkout validation, and show your history.
Basis: performing our contract with you.
Kept: until you delete the data from Settings, or until Shopify sends shop/redact after you uninstall.
2.2 Customer data your rules need
Data: from the orders/create webhook we read the customer id and each line's product id and quantity. We write per-product quantity totals to an app-owned metafield on that customer record inside Shopify. The order payload is discarded; only the webhook id is kept, so the same webhook is not processed twice.
Used to: evaluate the per-customer limits you wrote, and nothing else.
Who holds it: the totals live on the customer record inside your own Shopify store, not on our server.
Basis: performing our contract with you, as your processor for this data.
Kept: on that customer record until Shopify sends customers/redact, which removes it.
2.3 Decision records
Data: the decision, the winning rule and version, a normalized reason, the provenance of the run, and a SHA-256 hash of the customer id.
Used to: let you reproduce a block in the simulator against the version that was live, and diagnose a support question.
Kept: for the retention window in your Settings, 90 days by default. Older rows are purged. Export gives you one JSON file per shop.
2.4 What your shoppers see
A blocked cart shows the message you wrote, with the numeric threshold, limit, quantity or country it names. That message is the only shopper-facing surface. Rulestage sends no email, no SMS and no notification.
2.5 The website
Data: rulestage.com sends PostHog a sanitized page address, the referrer, and the name of a marketing button from a fixed list.
Used to: count visits and find which page led to an install.
Who: PostHog processes it in the United States.
Kept: under the PostHog project's retention settings; Rulestage keeps no separate copy.
Autocapture, heatmaps, surveys and session recording are switched off, and we set no cookie of our own.
2.6 Email to us
Data: what you write to support@rulestage.com, your address, and any diagnostics bundle you attach. A bundle carries the decision, the version, your settings and the engine version, with hashed customer ids.
Used to: answer you and fix the problem.
Kept: 12 months after the thread closes.
3. Processors
- Shopify — the platform Rulestage runs inside. Your store data, your customers' records and the billing for this app stay with Shopify under its own terms.
- Hosting and security providers — they run the server and database behind the app, and the network in front of both sites.
- PostHog — website analytics for rulestage.com only (United States).
Nobody else receives data from Rulestage.
4. Where the data sits and how it is protected
Every request between Rulestage, Shopify and your browser uses TLS.
The database runs on our server in the United States, reachable only from the app on that server. The app encrypts sensitive fields before writing them to the database (AES-256-GCM): your shop's access tokens, staff names and emails from Shopify sessions, saved test carts and the stored decision records. The key is kept outside the database. Customer identifiers in decision records are also stored as one-way hashes, so no raw customer id sits in the database. Backups are made every night, encrypted on the server before they leave it, and stored in a private Cloudflare R2 bucket; the key stays on the server.
5. Your rights
You can export your shop's data as JSON and delete it from Settings at any time. Uninstalling the app tells Shopify to send shop/redact, and that deletes every row for your shop.
If you are in the EU, the UK or another place with data-protection rights, you can ask us to show, correct, delete, restrict, export or stop using data about you. You can also complain to your local supervisory authority. Write to support@rulestage.com; we answer within one month.
For a shopper's data, Shopify is the source. customers/data_request and customers/redact are implemented, so a request you forward through Shopify reaches us.
6. Children
Rulestage is a tool for Shopify merchants and is not directed at children. We do not knowingly request personal information from children.
7. Changes
This notice describes what the app does today. If a change affects the data we touch, we say so in the app before it takes effect.
8. Contact
support@rulestage.com — WaveApp LLC, 30 N Gould St Ste N, Sheridan, WY 82801, USA