How Magnetar Apps collects, uses and protects information when you use our apps and website.
This Privacy Policy explains how Magnetar Apps, operated by Magnetar Apps Pty Ltd (ACN 699 371 536) ("Magnetar", "we", "us"), collects, uses, discloses and protects personal information when you use our applications, including Super Tags and Super Checkout: Brand Styler (each an "App"), and our website. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where they apply, other data protection laws such as the GDPR and CCPA.
This policy applies to merchants who install our Apps and visitors to our website. Where we process data about your store's own customers on your behalf, you are the controller of that data and we act as your processor; that processing is also governed by our agreement with you and by Shopify's requirements.
Your contact details (such as name and email), the contents of support requests, and any information you enter when configuring an App.
To provide the Apps, we access data from your Shopify store through Shopify's APIs. This is limited to what each App needs - for example, Super Tags reads product, order and customer records to evaluate your tagging rules, and Super Checkout: Brand Styler reads and writes your checkout and customer-account branding configuration.
Tagging orders and customers requires access to Shopify Protected Customer Data. Depending on the rules you write, Super Tags reads the following fields:
We read these fields for one purpose only: to compare them against the conditions you typed into your own tagging rule and decide which tags to apply. We do not use them to build profiles, to train models, for advertising, or for any purpose of our own, and we never sell them.
When you use our Apps or website we may collect usage and diagnostic data such as log events, device and browser information, and cookie identifiers, to keep the service secure, reliable and improving.
Super Tags evaluates your rules in memory, against data fetched live from the Shopify Admin API, and then discards that data. We do not store your customers' names, email addresses, phone numbers or addresses in our database.
What we do store, in a managed PostgreSQL database:
The tags recorded in a run log are the same tags written to the record in Shopify, which you can already see there. If you build a rule that generates a tag from a field value, that tag could itself contain a customer's email address or phone number. Records of that kind are erased on request, as described under Data retention and deletion below.
We use information to: provide, operate and support the Apps; process rules and settings you configure; authenticate and secure access; communicate with you about your account, support and service updates; comply with legal obligations; and improve and develop our products. We do not sell your personal information.
Where the GDPR applies, we process personal information on the bases of performing our contract with you, our legitimate interests in operating and improving the service, your consent (where requested), and compliance with legal obligations.
We share information only as needed to run our service. These are the only third parties that process data on our behalf, each bound by its own data processing terms and confidentiality obligations:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Shopify | The platform our Apps run on and read from | Your store data, which does not leave Shopify except as described in this policy | Per Shopify's terms |
| Render | Application hosting and the managed PostgreSQL database | Everything listed in section 3 | United States |
| Resend | Delivers support emails | Only what you submit through the in-app support form: your email address, your message, and any file you attach | United States |
| Anthropic | Drafts a tagging rule from a description you type (Super Tags' optional "Draft with AI" feature) | Only what you type: your description, and the current contents of the rule you are editing (conditions, tag names, Liquid code) | United States |
Resend is used solely to deliver the support form. It is not part of the tagging pipeline and never receives customer data from your store. Please avoid pasting customer personal data into a support message or screenshot; anything you do include is emailed to us and kept in our support inbox.
AI rule drafting. Super Tags can draft a tagging rule from a description you type in plain English. When you use this feature, we send Anthropic (the provider of the Claude model) the description you typed and the current contents of the rule you are editing, so a follow-up request refines the rule instead of starting over. That is all: the App does not send your product, order or customer records to Anthropic, and no store data is read for this feature. If you type store or customer details into your description or rule, those typed words are included in what is sent. Requests are made under Anthropic's commercial API terms, under which submitted content is not used to train AI models, and we have not opted into any Anthropic data-sharing or training program. The feature only runs when you press the draft button; if you never use it, nothing is sent to Anthropic. Every draft lands in the editor for you to review and is never saved or applied automatically.
We do not use third-party analytics or error-monitoring services inside our Apps. We also disclose information where required by law or to protect our rights and the safety of others, and we may transfer information as part of a merger, acquisition or sale of assets.
We keep personal information only as long as needed to provide the Apps and for legitimate legal, accounting or security purposes. We act on Shopify's mandatory compliance requests as follows:
customers/redact): we delete every run-log record referring to that customer, including any tag strings recorded against them. We hold nothing else about them.customers/data_request): we have no personal data to return. The only customer-linked data we hold is the Shopify customer id and the tags the App applied, and those tags are already visible to you on the customer record in Shopify.shop/redact, sent by Shopify 48 hours after you uninstall): we delete the shop record and everything attached to it, including your rules, settings, run logs and sessions. Nothing is retained.Support emails are kept for as long as needed to resolve your request and maintain a support history, and are deleted on request.
We use reasonable technical and organisational measures to protect information against loss, misuse and unauthorised access. Data is encrypted in transit using TLS, and our database is a managed instance with encryption at rest. Access to production systems and API credentials is limited to the people who need it and is protected by multi-factor authentication. We do not export store data to any other system. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Our infrastructure and support-email providers store and process information in the United States, which may be a different country from the one you are located in. Where we transfer personal information across borders, we take reasonable steps to ensure it remains protected consistent with this policy and applicable law.
Where our Apps process personal information about your customers, we do so on your behalf and only to provide the App to you. You are responsible for having an appropriate privacy notice and lawful basis for that processing, and for responding to your customers' privacy requests. Requests we receive from your customers directly will be referred to you.
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email us at support@magnetarapps.com. We will respond within the time required by applicable law. Uninstalling an App triggers deletion of its data automatically.
Our website and embedded App admin use cookies and similar technologies to keep you signed in, remember preferences, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.
Our Apps and website are intended for businesses and are not directed at children. We do not knowingly collect personal information from children.
We may update this policy from time to time. We will post the updated version here and change the "Last updated" date above. Material changes may be notified to you directly.
For privacy questions or complaints, contact us at support@magnetarapps.com. If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.