NovaPay provides tools for creating payment, delivery, discount, and checkout-validation rules. We use information only to provide, secure, support, and improve those services. We do not sell personal information or use it for third-party behavioural advertising.
1. Information we collect
Information received from Shopify
When a merchant installs the App, Shopify provides information needed to authenticate the store and operate the App. Depending on the merchant’s approved permissions and features used, this may include:
- the Shopify store domain and installation or access credentials;
- merchant or authorized-user details such as name, email address, locale, and account role;
- product, variant, collection, product-tag, shipping-method, discount, payment-customization, delivery-customization, validation, checkout, customer, and order information that is necessary to configure or run a rule;
- app subscription status and the permissions granted to the App; and
- app lifecycle events, including installation, permission changes, and uninstallation.
Checkout information processed by rules
When an enabled rule runs, Shopify may make relevant checkout data available to the App’s Shopify Functions. Based on the rule a merchant configured, this can include cart totals, line items, product or variant identifiers, titles, SKUs, quantities, product and customer tag matches, customer email, order count, discount codes, payment and delivery options, line-item properties, country or market, and delivery or billing details such as name, phone number, company, street address, city, province, country, and postal code. This data is evaluated within Shopify’s checkout environment to return the requested rule result. NovaPay does not use checkout data to build advertising profiles.
Information provided directly to NovaPay
- rule names, conditions, settings, and other configurations a merchant saves;
- primary and secondary contact emails and product-email preferences saved in Shopify metafields;
- name, email, store domain, message, and any other details submitted through support or feature-request forms; and
- technical information normally created when the App is used, such as request timestamps, browser or device information, IP address, diagnostics, and security logs.
2. How we use information
We use information to:
- authenticate users and provide the App’s features;
- create, apply, synchronize, and troubleshoot checkout rules and Shopify customizations;
- manage subscriptions, plan limits, settings, and merchant preferences;
- respond to support requests and communicate about service or security matters;
- send product communications when a merchant has chosen to receive them;
- monitor reliability, prevent fraud or abuse, and protect the App, merchants, and Shopify users;
- improve the App and understand feature performance; and
- comply with legal obligations and enforce our rights.
Where applicable law requires a legal basis, we process information to perform our contract with the merchant, pursue the legitimate interests described above, comply with law, or act with consent where requested.
3. How we share information
We may share information only as reasonably necessary with:
- Shopify, whose platform, APIs, billing, and Functions infrastructure are used to provide the App;
- service providers that support hosting, databases, email delivery, security, monitoring, and technical operations, subject to appropriate contractual obligations;
- professional advisers or authorities when required to comply with law, respond to lawful process, or protect rights, safety, and security; and
- a successor organization in connection with a merger, acquisition, financing, reorganization, or sale of all or part of the business, subject to this policy or notice of material changes.
We do not sell or rent personal information, and we do not share personal information for cross-context behavioural advertising.
4. Data retention and deletion
We retain merchant account and rule information for as long as the App is installed or as needed to provide the Service. Shopify-hosted configurations and metafields remain subject to Shopify’s retention controls. When the App is uninstalled, we revoke or remove access and delete or anonymize App-controlled merchant data within a reasonable period, unless a longer period is required for legal, security, fraud-prevention, dispute, or accounting purposes.
Support correspondence and operational logs may be kept for a limited period needed to resolve requests, maintain security, and meet legal obligations. Merchants may request deletion using the contact information below. Shopify may separately retain information under its own policies.
5. International data transfers
NovaPay and its service providers may process information in countries other than the country where the merchant or customer is located, including the United States. Where required, we use recognized safeguards for international transfers, such as contractual protections, and take steps designed to protect information consistently with this policy.
6. Your privacy rights
Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing of personal information, receive a portable copy, or withdraw consent. Individuals may also have the right to complain to a local data-protection authority. We will not discriminate against anyone for exercising a privacy right.
If you are a customer of a Shopify merchant, the merchant is generally the best first contact because NovaPay processes checkout information on the merchant’s instructions. Merchants may contact us directly. We may need to verify a request and may ask the relevant merchant to help identify or fulfill it.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls and secure service connections. No system is completely secure, and we cannot guarantee absolute security. Merchants should protect their Shopify credentials and notify us promptly of suspected unauthorized use.
8. Children’s privacy
The App is intended for Shopify merchants and authorized business users, not for children. We do not knowingly collect personal information directly from children through the App. If you believe a child has provided information to us directly, please contact us so we can review and delete it where appropriate.
9. Shopify and third-party services
Shopify processes information under its own agreements and privacy policy. Merchants are responsible for their own store privacy notices and for ensuring their use of NovaPay complies with applicable law. For more information, see Shopify’s Privacy Policy.
10. Changes to this policy
We may update this policy to reflect changes to the App, our practices, or legal requirements. We will post the revised policy here and update the effective date. When required, we will provide additional notice to merchants.
11. Contact us
NovaPay Checkout Rules is operated by Umais Yasir, Shopify Partner ID 4376752. For privacy questions, complaints, or privacy-rights requests, email info@umaisyasir.com. For product assistance, merchants can also use the support channel available from inside the NovaPay App.
Please include your Shopify store domain and enough information for us to understand and verify the request. Do not send passwords, access tokens, or payment-card details.
Last updated: September 1, 2026