Privacy policy
Last updated September 11, 2026. Sugar Rush Technologies. Contact: contact@sugarrush.tech.
This policy describes how Sugar Rush (“we”) handles personal data when a merchant uses our subscription platform, including the Shopify app.
Who this covers
Merchants who create a Sugar Rush shop, and the customers of those shops (subscribers). We process subscriber data on behalf of the merchant so they can sell and fulfill subscriptions.
What we collect
From merchants: name, email, password, shop name, and the payment or shipping accounts they connect (Shopify, Stripe, Shippo). We store API tokens in an encrypted vault. We do not see a merchant’s Shopify admin password.
From a merchant’s customers, only what is needed to run subscriptions:
- Name — so the merchant can identify the subscriber
- Email — portal sign-in and order notices
- Shipping address — ship and local-delivery fulfillment
- Phone, when provided on the address — delivery contact
- Order and subscription contents, cadence, and fulfillment status
We do not use this data for advertising, resale, or selling personal data. We do not make automated decisions that have legal or similarly significant effects.
Why we use it
To provide the product: connect the merchant’s catalog, take subscription orders (Shop Pay or Stripe), show a customer portal, send transactional email, and queue fulfillment (ship, local delivery, pickup).
Where it is stored
Application data lives in our hosted Postgres database (Supabase). Credentials are encrypted at rest (AES-256-GCM). Traffic uses HTTPS. Database backups are encrypted by the host. Test shops are separate from live merchant shops.
Who can see it
The merchant sees only their own shop. Platform operators are limited to the people who run Sugar Rush (today, one operator) and use strong passwords. We do not operate a dedicated staff access log for every view of customer records. Hosts (Supabase, Cloudflare, Resend, Stripe, Shopify, Shippo) process data as needed to provide their service.
How long we keep it
We keep subscriber and shop data while the shop is connected and the merchant account is open. When a merchant deletes their Sugar Rush account, we delete the shops they solely own and the related customer, subscription, and shipment rows. After a merchant uninstalls the Shopify app, Shopify sends a shop redaction request; we then remove Shopify tokens and subscriber personal data for that store. Customer deletion requests from Shopify are applied by anonymizing or deleting that customer’s stored fields. We complete those actions within 30 days of the request.
Shopify compliance
Public Shopify apps must handle customer data-request, customer redaction, and shop redaction webhooks. We acknowledge those requests and carry out the matching deletion or export duty described above. Merchants who need a copy of a customer’s stored data can email us; we will provide what we hold for that shop.
Your choices
Merchants can disconnect Shopify, Stripe, or Shippo from the dashboard, or delete their Sugar Rush account. Subscribers manage or cancel through the merchant’s portal or by contacting the merchant. For access or deletion of personal data, email contact@sugarrush.tech.
Security incidents
We maintain a written incident-response policy. If personal data leaves our control, we notify affected merchants as soon as we can, and the same calendar day for a confirmed leak.
Children
The service is for merchants and their adult customers. We do not knowingly collect data from children.
Changes
We will update this page when our practices change and revise the date above.