Skip to content
Fast Subscriptions
  • Product
    Subscription plans Pay-as-you-go, prepaid, fixed-term Build-A-Box Dynamic or fixed pricing bundles Customer portal Pause, skip, swap or cancel Payment recovery Smart retries and dunning
  • Solutions
    Food & Beverage Beauty & Personal Care Health & Wellness Pets Home Goods Meal Kits
  • Resource
    Help centre Migration guide Feature requests
  • Migration
    Import from Stripe Import from PayPal Express Import from Authorize.net
Try free Book a demo
  • Product
    • Subscription plans Pay-as-you-go, prepaid, fixed-term
    • Build-A-Box Dynamic or fixed pricing bundles
    • Customer portal Pause, skip, swap or cancel
    • Payment recovery Smart retries and dunning
  • Solutions
    • Food & Beverage
    • Beauty & Personal Care
    • Health & Wellness
    • Pets
    • Home Goods
    • Meal Kits
  • Resource
    • Help centre
    • Migration guide
    • Feature requests
  • Migration
    • Import from Stripe
    • Import from PayPal Express
    • Import from Authorize.net
Try free Book a demo

Legal

Privacy Policy

How Loyal handles merchant, subscriber and website data.

Last updated 14 August 2026Applies to loyalapp.com and the Loyal Shopify app

On this page

    On this page

      How to read this. Loyal handles two different kinds of information under two different sets of rules. Information about the merchant, their staff and our website is ours to look after, and this policy governs it. Information about a merchant's subscribers belongs to the merchant. We handle it only on their instructions, and the Data Processing Addendum governs that, not this policy. If you are a subscriber of a store, section 16 tells you who to contact.

      1. Who we are

      Loyal is a subscription management application for Shopify stores, operated by SlashCart Inc., a Delaware general corporation (file number 10224456) with a registered office at 131 Continental Drive, Suite 305, Newark, DE 19713, United States. In this policy, “Loyal”, “we”, “us” and “our” mean SlashCart Inc..

      Contact for all privacy matters: support@slashcart.com.

      2. Our two roles, and why the distinction matters

      We act in two separate capacities, and your rights depend on which one applies.

      • As a controller. For merchant account details, billing records, support conversations, marketing contacts and website analytics, we decide the purposes and means of processing. This policy governs that processing.
      • As a processor. For subscriber personal data inside a merchant's Shopify store, the merchant is the controller. They decide what is collected, why, and for how long. We process it only on their documented instructions, which are set out in the Terms of Service, the Data Processing Addendum and the merchant's own configuration of the app. We do not decide what happens to that data and we do not use it for our own purposes.

      Where we act as a processor, questions about the lawfulness of the processing, the notices given to subscribers, and the consent obtained for recurring billing are matters for the merchant, not for us.

      3. What this policy does not cover

      • The merchant's own storefront, website, marketing, checkout or privacy practices. Each merchant publishes its own policy and is responsible for it.
      • Shopify. The Shopify platform is operated by Shopify Inc. under its own privacy policy and its agreement with the merchant.
      • Third party services a merchant chooses to connect, including Klaviyo, Gorgias, Weglot and any tool reached through Shopify Flow. Once data reaches them, their terms govern it.
      • Any site we link to that we do not operate.

      4. Information we collect

      4.1 From merchants and their staff, as controller

      • Name, work email address, store name, myshopify domain, role, country, currency, locale and time zone
      • Records of the Loyal plan approved and charges raised through Shopify Billing
      • Support messages, attachments and any screen recordings a merchant chooses to send us
      • Product usage, including features enabled, screens opened, actions taken and errors encountered
      • Marketing engagement, such as whether an email we sent was opened or a link clicked

      4.2 From the merchant's Shopify store, as processor

      After the merchant installs Loyal and grants access, we read and write the following through the Shopify API. Every field below is used for a stated purpose in section 7 and for nothing else.

      • Products, variants, prices, inventory and metafields
      • Customer records, including name, email address, phone number, and shipping and billing addresses
      • Orders and draft orders connected to a subscription contract
      • Subscription contracts, selling plans, billing attempts, billing cycles and payment mandate identifiers held by Shopify
      • Discounts, markets, translations and shop settings that affect subscription pricing or presentation

      4.3 From subscribers using the customer portal

      Actions taken in the portal, such as a skip, swap, pause, reschedule, address change, plan change or cancellation, together with the identifiers and session data needed to authenticate the subscriber and to keep a record of who made each change and when.

      4.4 From migrations

      Where a merchant asks us to import subscribers from another provider, we process the export they or their previous provider supplies. This typically contains subscriber contact details, addresses, plan configuration, discount history, next billing dates and payment method references or network tokens issued by a gateway. We process it solely to perform the migration the merchant instructed.

      4.5 From website visitors

      IP address, approximate location derived from it, device and browser type, referring page, pages viewed, and anything typed into a trial or demo form. See the Cookie Policy.

      4.6 What we do not ask for

      We do not request, and merchants must not send us, special category data as defined by the GDPR, government identification numbers, financial account credentials, or full payment card numbers. If such data reaches us despite this, we will delete it and tell the merchant.

      5. Payment information

      We are not a payment processor. Recurring charges are executed by Shopify against a payment mandate that Shopify holds, or by the merchant's own gateway. Loyal instructs the charge and records the outcome, which includes the result code, the amount, the currency and the date. We do not receive or store full card numbers or security codes at any point.

      Where a migration involves gateway tokens or network tokens, these are opaque references rather than card numbers. We transmit them to the destination system to recreate the mandate and do not retain them once the mandate exists.

      Decision needed before publishing. If the subscriber portal displays a card brand and the last four digits, either state here that those two fields are stored, or confirm that they are read live from Shopify on each portal load and store nothing. Seal Subscriptions discloses that it stores last four digits, expiry and card type. An inaccurate claim here is the single most likely thing to fail a merchant security questionnaire.

      Merchants pay for Loyal through Shopify Billing. Shopify processes that payment. We receive a confirmation and never the merchant's card details.

      6. Shopify protected customer data

      Shopify classifies customer name, email address, phone number and address as protected customer data. We request the minimum access scopes needed to operate subscriptions, apply a documented purpose to each field, encrypt it in transit and at rest, restrict internal access to those who need it, and delete it on the schedule in section 11. We implement the three privacy webhooks Shopify requires and respond within the timeframes in section 15.

      7. Why we use information, and our legal basis

      Purpose Legal basis where the GDPR or UK GDPR applies
      Providing the app, creating and billing subscription contracts, running the portal, recovering failed payments, producing analytics for the merchant Performance of a contract with the merchant. For subscriber data, the merchant's own basis as controller.
      Performing a migration the merchant instructed Performance of a contract
      Service messages such as billing failures, breaking changes and security notices Performance of a contract, and legitimate interests in keeping merchants informed
      Support and fault investigation Performance of a contract
      Security, fraud prevention, abuse detection and enforcing our terms Legitimate interests in protecting our service, our merchants and their subscribers
      Product improvement using aggregated or de identified data Legitimate interests in improving the service. The data cannot be linked back to a person.
      Business to business marketing to merchants and to people who request information Legitimate interests, or consent where the law requires it. You may object or unsubscribe at any time.
      Establishing, exercising or defending legal claims Legitimate interests
      Tax, accounting, regulatory and lawful requests Legal obligation

      Where we rely on legitimate interests we have carried out a balancing assessment, and a summary is available on request.

      8. What we do not do

      • We do not sell personal information, and we do not share it for cross context behavioural advertising, as those terms are defined by the CPRA and comparable United States state laws.
      • We do not use subscriber personal data to train machine learning models.
      • We do not make decisions producing legal or similarly significant effects about any individual by automated means alone. Failed payment retry scheduling is a billing rule configured by the merchant, not a profiling decision about a person.
      • We do not enrich, append or resolve identity against third party data brokers.
      • We do not use subscriber data for our own marketing.

      9. Who we share information with

      We share personal information only in the following circumstances.

      • Subprocessors. Service providers that help us run Loyal, each bound by written contract, limited to what they need and prohibited from using it for their own purposes. The current list is at Subprocessors.
      • Shopify, because the app runs on and depends on the Shopify platform.
      • Integrations the merchant connects. Data leaves at the merchant's instruction and is then governed by their agreement with that provider.
      • Professional advisers such as lawyers, auditors, accountants and insurers, under confidentiality.
      • Authorities, where legally required. We assess each request, disclose only what is required, and notify the affected merchant unless the law prohibits it.
      • Successors, in a merger, acquisition, financing, reorganisation or sale of assets. Affected merchants will be told before their data moves to a new controller.

      10. International transfers

      We are established in the United States and our team and infrastructure operate across more than one country. If you are in the United Kingdom, the European Economic Area or Switzerland, your information may be transferred outside your jurisdiction.

      Where it is, we rely on an adequacy decision where one exists, and otherwise on the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit and at rest. A copy of the clauses is available on request from support@slashcart.com.

      11. How long we keep information

      Information Retention
      Store and subscriber data while installed For as long as the merchant keeps Loyal installed
      Store and subscriber data after uninstall Deleted within 14 days, or within 48 hours of Shopify sending a shop redaction request, whichever is sooner
      Subscriber data following a Shopify customer redaction request Deleted or irreversibly de identified within 30 days
      Migration source files Deleted within 30 days of the merchant confirming the migration
      Merchant account and contact details Until the account closes, then 12 months
      Billing, tax and accounting records 7 years, as required by law
      Support conversations 24 months
      Security, access and audit logs 12 months
      Encrypted backups Rolling 35 days, after which deleted records age out of the backup set

      Deletion from live systems happens on the schedule above. Data already written to an encrypted backup is not individually removed from that backup, because doing so would compromise its integrity. It remains encrypted, is not restored into live systems except in a disaster recovery event, and is destroyed when the backup expires.

      We may retain information for longer where a law requires it, where it is needed to establish, exercise or defend a legal claim, or where it is needed to investigate a security incident or a suspected breach of our terms. Where we do, we continue to protect it and use it for no other purpose.

      Decision needed before publishing. The 14 day figure is a commitment. Confirm with engineering that the deletion job actually runs on that cycle. Competitors state 3 and 7 days, so tighten this if you can, but never publish a number the system does not meet. Appstle's policy promises immediate deletion on uninstall and then describes backup archives two paragraphs later, which is the contradiction to avoid.

      12. Security

      We implement technical and organisational measures appropriate to the risk. Data is encrypted in transit using TLS 1.2 or above and encrypted at rest. Access to production systems is limited to the people who need it, protected by multi factor authentication, and removed when someone stops working with us. Production is kept separate from test environments, and we do not use real subscriber data in testing. We keep dependencies patched and we keep access and error logs. Further detail is on the Security page.

      No method of transmission or storage is completely secure. We do not warrant or guarantee that our safeguards cannot be defeated, and we cannot promise absolute security. Where a personal data breach affects a merchant's data, we will notify them without undue delay in line with section 8 of the Data Processing Addendum, and will notify regulators and individuals where the law requires it.

      13. Merchant responsibilities

      Merchants are controllers of their subscriber data and are responsible for the following. This is a statement of how the law allocates these duties, not an attempt to shift ours.

      • Having and documenting a lawful basis for enrolling subscribers in recurring billing, and obtaining consent where consent is the basis
      • Publishing an accurate privacy notice that discloses the use of a subscriptions app and the processing described here
      • Disclosing price, billing frequency, renewal timing and cancellation method before checkout, and honouring cancellations
      • Having the right to export and transfer subscriber data and payment mandates from a previous provider, and verifying an imported result before resuming billing
      • Responding to their subscribers' data rights requests, using the export, correction and deletion tools we provide
      • Configuring retention, notifications and integrations appropriately for their own jurisdiction
      • Not sending us special category data, card numbers or credentials

      We provide tooling. We do not provide legal advice and we do not make a merchant's subscription programme compliant on their behalf.

      14. Your rights

      14.1 European Economic Area, United Kingdom and Switzerland

      You may request access to your personal data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests, including direct marketing. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out. You may complain to your supervisory authority, to the Information Commissioner's Office in the United Kingdom, or to the Federal Data Protection and Information Commissioner in Switzerland. We would prefer you raise it with us first so we can resolve it.

      14.2 California

      You may request the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients. You may request correction or deletion, and you may limit the use of sensitive personal information, though we do not collect it for any purpose requiring that limit. You may opt out of sale or sharing, though as stated in section 8 we do neither. We will not discriminate against you for exercising a right. Requests may be made up to twice in a 12 month period.

      14.3 Other United States states

      Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana among others, have rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and profiling with legal or similarly significant effects. We do not carry out any of those three activities. Where a state provides an appeal, and we decline a request, our response will explain how to appeal.

      14.4 Canada

      Under PIPEDA and provincial equivalents you may request access to your personal information and challenge its accuracy. Complaints may be made to the Office of the Privacy Commissioner of Canada.

      15. How to make a request

      Email support@slashcart.com with the nature of your request and enough information for us to locate your records, usually the email address and store domain involved.

      We will verify your identity before acting, using information already in our records. Where we cannot verify you to a reasonable degree of certainty, we will ask for more, and if we still cannot, we will decline and explain why. An authorised agent may act for you with written permission and proof of their authority.

      We respond within the period the applicable law allows, normally 30 days or 45 days, and will tell you if we need an extension the law permits. Requests are free unless they are manifestly unfounded, repetitive or excessive, in which case we may charge a reasonable fee or decline, and will explain our reasoning.

      For requests received through Shopify's privacy webhooks, we return a customer data export to the merchant within 10 days, complete a customer redaction within 30 days, and complete a shop redaction within 48 hours.

      16. If you are a subscriber of a store

      The store you subscribed to is the controller of your personal data, not us. Send your request to that store. If you send it to us, we will acknowledge it, forward it to the merchant, and assist them in responding, but we are not permitted to alter or delete their records on our own initiative except where our contract or the law requires it.

      17. Children

      Loyal is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.

      18. Do Not Track

      There is no accepted industry or legal standard for how online services should respond to Do Not Track browser signals, so we do not currently respond to them. We do honour Global Privacy Control signals on loyalapp.com where the law recognises them as a valid opt out.

      19. Changes to this policy

      We revise this policy when the product, our vendors or the law change. The current version date appears at the top of the page. Where a change materially affects merchants, we will give at least 30 days notice by email or in the app before it takes effect, and continued use after that period constitutes acceptance. Prior versions are available on request.

      20. Complaints

      If you are unhappy with how we have handled your personal information or a request, email support@slashcart.com with “Privacy complaint” in the subject line. We acknowledge within 5 business days and aim to resolve within 30 days. If you remain unsatisfied you may escalate to your supervisory authority or regulator as described in section 14.

      21. Where the information comes from

      We do not buy personal information and we do not collect it from data brokers. Everything in section 4 reaches us from one of these places.

      • Directly from the merchant, when they install Loyal, configure it, contact support or fill in a form on our website
      • From the merchant's Shopify store through the Shopify API, after the merchant grants access
      • From subscribers themselves, when they use the customer portal
      • From a previous subscription provider, in a migration export the merchant asks us to import
      • Automatically from a visitor's browser on loyalapp.com
      • From our own systems, as usage records, logs and error reports

      22. California categories

      This section sets out our collection in the categories the CCPA uses. As stated in section 8, we do not sell personal information and we do not share it for cross context behavioural advertising. We do not collect sensitive personal information for any purpose that would trigger the right to limit its use.

      Category What it covers, and who receives it
      Identifiers Names, email addresses, phone numbers, postal addresses, store domains, IP addresses. Disclosed to our subprocessors, to Shopify, and to integrations the merchant connects.
      Commercial information Products subscribed to, order and billing history, plan configuration, discounts. Disclosed to our subprocessors, to Shopify, and to integrations the merchant connects.
      Financial information Charge outcomes, amounts, currencies and dates, and opaque payment mandate references. No card numbers or security codes, as set out in section 5. Not disclosed for any purpose beyond executing the charge.
      Internet or network activity Pages viewed, features used, actions taken, referring pages, device and browser type. Disclosed to our hosting and analytics subprocessors.
      Geolocation Approximate location derived from an IP address, and the country on an address. Disclosed to our subprocessors.
      Professional information A merchant contact's role and company. Disclosed to our support and marketing subprocessors.
      Inferences None. We do not build profiles about individuals.

      The purposes for each category are in section 7. The recipients are described in full in section 9. Requests under this section are made as described in section 15.

      23. AI and automated features

      We do not train machine learning models on merchant or subscriber personal data, and we do not send that data to a third party model provider for training. Where a Loyal feature uses a model, the input is limited to what the feature needs, the output is a suggestion for a person to accept or reject, and the merchant can turn the feature off.

      The parts of Loyal that decide things on a schedule, such as when to retry a failed payment or when to pause a subscription, are rules the merchant configures. They are not profiling, and they do not make a decision about a person by automated means alone. If we add a feature that changes any of this, we will update this section and give notice under section 19.

      24. Keeping your account secure

      Access to Loyal runs through your Shopify admin, so the security of your Shopify account is the security of your subscriber data. Use multi factor authentication, give each person their own login rather than a shared one, and remove staff and agencies as soon as they stop working with you. Review who has access periodically.

      Tell us immediately at support@slashcart.com if you think an account has been compromised. We are not responsible for activity carried out through credentials that were shared, reused or left active, and we cannot detect misuse by someone your store has authorised.

      25. Export and switching away

      You can export your subscription data from Loyal at any time while the app is installed, in a machine readable format, and use it to move to another provider or to your own systems. We will give reasonable assistance during a transition and keep the service running normally until you uninstall.

      Export before you uninstall. After uninstall, deletion runs on the schedule in section 11 and we cannot recover the data. Payment mandates held by Shopify or your gateway are not ours to transfer, and what can move depends on what that provider allows. This mirrors section 21 of the Terms of Service.

      26. Links to other sites

      Our website and documentation link to sites we do not operate, including Shopify, our integration partners and our subprocessors. We do not control those sites and we are not responsible for their content or for how they handle your information. Read their own policies before you use them.

      27. Contact

      SlashCart Inc.
      131 Continental Drive, Suite 305
      Newark, DE 19713
      United States

      All enquiries, including privacy, security and legal: support@slashcart.com

      This policy should be read together with our Terms of Service, Data Processing Addendum, Cookie Policy and Subprocessors page, which together form the agreement governing use of Loyal.

      ↑ Back to top
      Fast Subscriptions
      Subscriptions, memberships and subscription boxes for Shopify brands. Merchant success team available 24×7×365.

      PRODUCTS

      • Subscription plans
      • Build-A-Box
      • Payment recovery
      • Analytics

      Solutions

      • Food & Beverage
      • Beauty & Personal Care
      • Health & Wellness
      • Pets
      • Home Goods
      • Meal Kits
      • Digital Products

      Company

      • About
      • Help centre
      • Migration guide
      • Contact
      © 2026 RetailForce. All rights reserved.
      • Privacy
      • Terms
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions
      Fast Subscriptions

      Your cart is empty

      Have an account? Log in to check out faster.

      Continue shopping

      Search

      No products found.