Magnetar APPS
Apps
Super Tags
Overview
Tutorials
All tutorials Getting started Building rules Liquid reference Activity log Plans and usage Settings and sync
Super Checkout: Brand Styler
Overview
Guides
All guides Getting started Branding basics Checkout & account pages Using the live preview Publishing & reverting Plans and usage FAQ
Pricing Support Get started
Apps Super Tags Tutorials Super Checkout: Brand Styler Guides Pricing Support Get started
Legal

Privacy Policy

How Magnetar Apps collects, uses and protects information when you use our apps and website.

Last updated: 14 July 2026
Plain-language summary

We collect only the store data our apps need to work - via Shopify's APIs - plus basic account and usage information. Super Tags reads customer names, emails, phone numbers and addresses only to evaluate the tagging rules you write, in memory, and does not store them in our database. We never sell your data, and we share it only with Shopify, our hosting provider, our support-email provider and - only if you use Super Tags' optional AI drafting, and only the text you type - Anthropic. If you uninstall an app we delete its data on Shopify's redaction schedule. Questions go to support@magnetarapps.com. The full policy below is what legally applies.

This Privacy Policy explains how Magnetar Apps, operated by Magnetar Apps Pty Ltd (ACN 699 371 536) ("Magnetar", "we", "us"), collects, uses, discloses and protects personal information when you use our applications, including Super Tags and Super Checkout: Brand Styler (each an "App"), and our website. We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where they apply, other data protection laws such as the GDPR and CCPA.

1. Who this policy covers

This policy applies to merchants who install our Apps and visitors to our website. Where we process data about your store's own customers on your behalf, you are the controller of that data and we act as your processor; that processing is also governed by our agreement with you and by Shopify's requirements.

2. Information we collect

Information you provide

Your contact details (such as name and email), the contents of support requests, and any information you enter when configuring an App.

Store data accessed through Shopify

To provide the Apps, we access data from your Shopify store through Shopify's APIs. This is limited to what each App needs - for example, Super Tags reads product, order and customer records to evaluate your tagging rules, and Super Checkout: Brand Styler reads and writes your checkout and customer-account branding configuration.

Protected Customer Data

Tagging orders and customers requires access to Shopify Protected Customer Data. Depending on the rules you write, Super Tags reads the following fields:

  • Name (first name, last name, display name) - so you can tag named VIP, press, wholesale or internal accounts, or flag names on your own fraud list.
  • Email address, including its verification and marketing-consent state - so you can tag by email domain, for example tagging your own staff, business buyers, or disposable-domain signups.
  • Phone number - so you can tag by country prefix and build accurate SMS segments, or exclude customers with no number from SMS flows.
  • Address (street, city, province, postcode, country, company) - so you can tag by destination for shipping, duties, tax and fulfilment routing, or tag business orders by company name.

We read these fields for one purpose only: to compare them against the conditions you typed into your own tagging rule and decide which tags to apply. We do not use them to build profiles, to train models, for advertising, or for any purpose of our own, and we never sell them.

Information collected automatically

When you use our Apps or website we may collect usage and diagnostic data such as log events, device and browser information, and cookie identifiers, to keep the service secure, reliable and improving.

3. What we store, and what we do not

Super Tags evaluates your rules in memory, against data fetched live from the Shopify Admin API, and then discards that data. We do not store your customers' names, email addresses, phone numbers or addresses in our database.

What we do store, in a managed PostgreSQL database:

  • Your shop domain, plan, billing cycle, timezone and usage counters, to run the App and apply plan limits.
  • The tagging rules and settings you configure. These are your own content and are the App's core function.
  • A log of each processing run: the Shopify id of every item changed, the tags added or removed, counts, timings and error messages. Changed customers are identified by their Shopify id, never by name or email.
  • Shopify session records, which include an access token and the name and email of the staff member who authenticated. These are required by Shopify's authentication flow.

The tags recorded in a run log are the same tags written to the record in Shopify, which you can already see there. If you build a rule that generates a tag from a field value, that tag could itself contain a customer's email address or phone number. Records of that kind are erased on request, as described under Data retention and deletion below.

4. How we use information

We use information to: provide, operate and support the Apps; process rules and settings you configure; authenticate and secure access; communicate with you about your account, support and service updates; comply with legal obligations; and improve and develop our products. We do not sell your personal information.

5. Legal bases

Where the GDPR applies, we process personal information on the bases of performing our contract with you, our legitimate interests in operating and improving the service, your consent (where requested), and compliance with legal obligations.

6. Who we share information with

We share information only as needed to run our service. These are the only third parties that process data on our behalf, each bound by its own data processing terms and confidentiality obligations:

ProviderPurposeData involvedLocation
Shopify The platform our Apps run on and read from Your store data, which does not leave Shopify except as described in this policy Per Shopify's terms
Render Application hosting and the managed PostgreSQL database Everything listed in section 3 United States
Resend Delivers support emails Only what you submit through the in-app support form: your email address, your message, and any file you attach United States
Anthropic Drafts a tagging rule from a description you type (Super Tags' optional "Draft with AI" feature) Only what you type: your description, and the current contents of the rule you are editing (conditions, tag names, Liquid code) United States

Resend is used solely to deliver the support form. It is not part of the tagging pipeline and never receives customer data from your store. Please avoid pasting customer personal data into a support message or screenshot; anything you do include is emailed to us and kept in our support inbox.

AI rule drafting. Super Tags can draft a tagging rule from a description you type in plain English. When you use this feature, we send Anthropic (the provider of the Claude model) the description you typed and the current contents of the rule you are editing, so a follow-up request refines the rule instead of starting over. That is all: the App does not send your product, order or customer records to Anthropic, and no store data is read for this feature. If you type store or customer details into your description or rule, those typed words are included in what is sent. Requests are made under Anthropic's commercial API terms, under which submitted content is not used to train AI models, and we have not opted into any Anthropic data-sharing or training program. The feature only runs when you press the draft button; if you never use it, nothing is sent to Anthropic. Every draft lands in the editor for you to review and is never saved or applied automatically.

We do not use third-party analytics or error-monitoring services inside our Apps. We also disclose information where required by law or to protect our rights and the safety of others, and we may transfer information as part of a merger, acquisition or sale of assets.

7. Data retention and deletion

We keep personal information only as long as needed to provide the Apps and for legitimate legal, accounting or security purposes. We act on Shopify's mandatory compliance requests as follows:

  • Customer erasure (customers/redact): we delete every run-log record referring to that customer, including any tag strings recorded against them. We hold nothing else about them.
  • Customer data request (customers/data_request): we have no personal data to return. The only customer-linked data we hold is the Shopify customer id and the tags the App applied, and those tags are already visible to you on the customer record in Shopify.
  • Uninstall (shop/redact, sent by Shopify 48 hours after you uninstall): we delete the shop record and everything attached to it, including your rules, settings, run logs and sessions. Nothing is retained.

Support emails are kept for as long as needed to resolve your request and maintain a support history, and are deleted on request.

8. Security

We use reasonable technical and organisational measures to protect information against loss, misuse and unauthorised access. Data is encrypted in transit using TLS, and our database is a managed instance with encryption at rest. Access to production systems and API credentials is limited to the people who need it and is protected by multi-factor authentication. We do not export store data to any other system. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

9. International transfers

Our infrastructure and support-email providers store and process information in the United States, which may be a different country from the one you are located in. Where we transfer personal information across borders, we take reasonable steps to ensure it remains protected consistent with this policy and applicable law.

10. Your store's customers

Where our Apps process personal information about your customers, we do so on your behalf and only to provide the App to you. You are responsible for having an appropriate privacy notice and lawful basis for that processing, and for responding to your customers' privacy requests. Requests we receive from your customers directly will be referred to you.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email us at support@magnetarapps.com. We will respond within the time required by applicable law. Uninstalling an App triggers deletion of its data automatically.

12. Cookies

Our website and embedded App admin use cookies and similar technologies to keep you signed in, remember preferences, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect functionality.

13. Children

Our Apps and website are intended for businesses and are not directed at children. We do not knowingly collect personal information from children.

14. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date above. Material changes may be notified to you directly.

15. Contact and complaints

For privacy questions or complaints, contact us at support@magnetarapps.com. If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Magnetar APPS
Shopify apps with magnetic pull. Built in Sydney & Melbourne, Australia.
Apps
Super Tags Super Checkout: Brand Styler
Company
Pricing Support FAQ Changelog
© 2026 Magnetar Apps Privacy Terms