Privacy

Block User stores the shop domain, the merchants’ block list, and the checkout message in a PostgreSQL database so the embedded admin can manage them. Each blocked buyer record can include an email address, a Shopify customer id, a display name, and an optional reason.

A copy of the emails, customer ids, and checkout message is saved to an app-owned metafield on the shop’s checkout validation. Shopify Functions read that metafield during checkout to decide whether to reject the cart. The function does not call this app’s server. A second app-installation metafield stores the message and the numeric customer ids, without emails, so the theme embed can stop a signed-in customer from adding to cart. That list is rendered on the storefront only as a yes or no for the current customer.

Shopify session tokens and offline access tokens are stored so the app can update that metafield after a merchant changes the list. When the app is uninstalled, or when Shopify sends a shop or customer redact request, the related rows are deleted.

The public landing page does not set tracking cookies. Shop domain values submitted on the install form are sent to Shopify to start OAuth.