Privacy policy

Last updated September 11, 2026. Sugar Rush Technologies. Contact: contact@sugarrush.tech.

This policy describes how Sugar Rush (“we”) handles personal data when a merchant uses our subscription platform, including the Shopify app.

Who this covers

Merchants who create a Sugar Rush shop, and the customers of those shops (subscribers). We process subscriber data on behalf of the merchant so they can sell and fulfill subscriptions.

What we collect

From merchants: name, email, password, shop name, and the payment or shipping accounts they connect (Shopify, Stripe, Shippo). We store API tokens in an encrypted vault. We do not see a merchant’s Shopify admin password.

From a merchant’s customers, only what is needed to run subscriptions:

We do not use this data for advertising, resale, or selling personal data. We do not make automated decisions that have legal or similarly significant effects.

Why we use it

To provide the product: connect the merchant’s catalog, take subscription orders (Shop Pay or Stripe), show a customer portal, send transactional email, and queue fulfillment (ship, local delivery, pickup).

Where it is stored

Application data lives in our hosted Postgres database (Supabase). Credentials are encrypted at rest (AES-256-GCM). Traffic uses HTTPS. Database backups are encrypted by the host. Test shops are separate from live merchant shops.

Who can see it

The merchant sees only their own shop. Platform operators are limited to the people who run Sugar Rush (today, one operator) and use strong passwords. We do not operate a dedicated staff access log for every view of customer records. Hosts (Supabase, Cloudflare, Resend, Stripe, Shopify, Shippo) process data as needed to provide their service.

How long we keep it

We keep subscriber and shop data while the shop is connected and the merchant account is open. When a merchant deletes their Sugar Rush account, we delete the shops they solely own and the related customer, subscription, and shipment rows. After a merchant uninstalls the Shopify app, Shopify sends a shop redaction request; we then remove Shopify tokens and subscriber personal data for that store. Customer deletion requests from Shopify are applied by anonymizing or deleting that customer’s stored fields. We complete those actions within 30 days of the request.

Shopify compliance

Public Shopify apps must handle customer data-request, customer redaction, and shop redaction webhooks. We acknowledge those requests and carry out the matching deletion or export duty described above. Merchants who need a copy of a customer’s stored data can email us; we will provide what we hold for that shop.

Your choices

Merchants can disconnect Shopify, Stripe, or Shippo from the dashboard, or delete their Sugar Rush account. Subscribers manage or cancel through the merchant’s portal or by contacting the merchant. For access or deletion of personal data, email contact@sugarrush.tech.

Security incidents

We maintain a written incident-response policy. If personal data leaves our control, we notify affected merchants as soon as we can, and the same calendar day for a confirmed leak.

Children

The service is for merchants and their adult customers. We do not knowingly collect data from children.

Changes

We will update this page when our practices change and revise the date above.