NEWDiscoverShipGoal– turn cart progress into bigger baskets
Legal

Privacy Policy

How Disco Merchant handles information for its website and Shopify apps.

Last updated: September 24, 2026

Disco Merchant is Panikka Studio's Shopify apps brand. This Privacy Policy explains how we collect, use, and protect information when you visit our website, contact us, or use our Shopify apps, including BlockCart, PayWith, and future Disco Merchant apps.

If a specific app listing, data processing addendum, or written agreement says something different for a particular app or merchant, that app-specific term controls.

Our role

When a merchant installs one of our apps, the merchant controls their store's customer data. We process that data on the merchant's behalf and only to provide the app's functionality. Shoppers who want to access, correct, or delete their personal information should contact the merchant they bought from. Shopify forwards those requests to us, and we act on them as described below.

Information we collect

We collect only the information we need to operate, support, and improve our apps and website. This may include:

  • Merchant account details such as store name, Shopify store domain, the name and email of the staff member using the app, billing status, and app installation status.
  • App configuration data such as validation rules, payment rules, checkout settings, preferences, and support context you provide.
  • Operational data such as logs, diagnostics, error reports, browser/device details, and usage events needed to keep the service reliable.
  • Messages you send to us by email, forms, or support channels.

Customer and checkout data

Our apps may process limited customer, cart, checkout, product, order, or shipping data when that information is needed to apply the rules a merchant configures. We use this data only to provide the app's functionality, troubleshoot issues, and maintain security. We do not sell customer personal information.

PayWith

PayWith lets merchants show, hide, reorder, and rename payment methods at checkout. To evaluate a merchant's rules, PayWith reads the following data from the checkout:

  • The buyer's email address.
  • Billing and shipping address details: country, province or state, city, and postal code. Street address lines are used only to detect PO box addresses.
  • Customer account details: whether the buyer is logged in, customer tags, number of orders, and total amount spent.
  • B2B details: the purchasing company, company location, and whether a PO number is present.
  • Cart details: products, variants, collections, quantities, totals, discounts, cart attributes, and the selected delivery option.

This data is evaluated inside Shopify's checkout infrastructure each time checkout loads. It is not sent to our servers and we do not store it. The only customer data PayWith stores is what a merchant types into their own rules, such as a customer email address or postal code used as a rule condition.

How we use information

  • To provide, maintain, secure, and improve Disco Merchant apps and the website.
  • To respond to support requests, product questions, and early-access inquiries.
  • To process billing and subscription status through Shopify or other approved providers.
  • To monitor app health, prevent abuse, debug errors, and understand which features are useful.
  • To send service updates or important notices related to an app you use.

Our apps do not use personal data to make automated decisions that have legal or similarly significant effects on shoppers.

Sharing information

We share information only when needed to run the service, comply with the law, or protect Disco Merchant, merchants, and shoppers. We do not rent or sell personal information to advertisers. The service providers we use include:

  • Shopify, which hosts merchant stores and runs our checkout logic.
  • Cloudflare, which hosts our apps and databases.
  • Crisp, which provides in-app support chat and receives the store name and the staff member's email when they use chat.
  • Email and analytics providers used to operate the website and respond to messages.

These providers may process information in countries other than the one where you or your customers are located.

Retention

We keep information only for as long as needed to provide the service:

  • When a merchant uninstalls an app, Shopify sends us a store data deletion request 48 hours later. We then delete that store's configuration, rules, and session data.
  • When Shopify sends us a customer data deletion request, we remove that customer's personal information from the merchant's stored rules.
  • Support messages and operational logs are kept only as long as needed to resolve issues, maintain security, and meet legal obligations.

Security

We use technical and organizational safeguards to protect information, including encryption in transit and at rest, encrypted backups, restricted staff access, and separate test and production environments. No online service is perfectly secure, so merchants should also protect their Shopify accounts, staff permissions, and credentials.

Your choices

Merchants can uninstall our Shopify apps through Shopify. You may also contact us to request access, correction, deletion, or export of information where those rights apply. Some data may need to be retained for legal, security, billing, or operational reasons.

Changes to this policy

We may update this Privacy Policy as our apps, legal requirements, or operations change. The updated policy will be posted on this page with a new last updated date.

Contact

Questions about privacy can be sent to business@panikka.studio.