DepositPay · Deposits & partial payments for Shopify

Privacy Policy

Last updated: 20 September 2026

DepositPay ("the App") provides deposit and partial-payment purchase options to Shopify merchants ("Merchants"). This policy describes how the App collects, uses and shares personal information when a Merchant installs the App or a customer places an order using one of the App's payment options.

Information we collect

When you install the App we receive, through Shopify's APIs, information needed to operate the service:

  • Store information: store name, myshopify domain, store owner email, currency, plan type.
  • Product information: product and variant IDs that a Merchant attaches to a deposit rule.
  • Order information for orders that use a DepositPay purchase option: order ID and number, totals, amounts paid and outstanding, payment schedule and payment mandate identifiers, fulfillment status.
  • Customer information for those orders: name and email address, used only to send balance reminders and payment notifications on the Merchant's behalf.

The App never receives or stores card numbers. Payment methods are vaulted by Shopify; the App only holds an opaque mandate reference that lets Shopify charge the remaining balance.

How we use information

  • To create and manage deposit purchase options on the Merchant's store.
  • To track outstanding balances and charge them when due, as configured by the Merchant.
  • To send transactional emails to customers (reminders, receipts, failed-payment notices) and alerts to the Merchant.
  • To provide support and to operate, secure and improve the service.

We do not sell personal information and we do not use it for advertising.

Sharing

We share information only with processors needed to run the App: our hosting provider, and our transactional email provider (Resend) for notifications. Each processor acts on our instructions and is bound by data-processing terms. We may disclose information if required by law.

Retention and deletion

Order records are kept while the App is installed so that balances can be collected and reported. When a Merchant uninstalls the App, Shopify sends us a shop redaction request and we delete all data for that store within 30 days. Customer data-request and redaction requests received from Shopify are honoured automatically.

Security

Data is transmitted over TLS and stored on access-controlled infrastructure. Access tokens are stored encrypted at rest by the hosting provider and are never exposed to browsers.

Your rights

Depending on where you live (including the EU/EEA, UK and California) you may have the right to access, correct, delete or restrict processing of your personal information. Customers should contact the Merchant they purchased from; Merchants may contact us at support@depositpay.app.

Changes

We may update this policy; the date above shows the latest version. Material changes will be announced inside the App.

Contact

DepositPay · support@depositpay.app

Privacy · Terms · Support