Privacy policy
What we collect, why we collect it, who else sees it, and how to get it deleted.
Last updated 10 August 2026
This policy covers Fastrr Checkout — the Shopify app, the checkout your shoppers see, and this website. Two different groups of people are described below and they are treated differently, so it is worth knowing which one you are:
- Merchants — you installed the app on your Shopify store.
- Shoppers — you bought something through a checkout the app powers.
For shoppers, in short: the store you bought from is the owner of your data. We hold it on that store's behalf so the checkout can work, and we act on the store's instructions. Your first stop for a deletion request is the store; they can pass it to us and we will act on it.
What we collect
From shoppers
- Contact details — phone number, and email address if given.
- Delivery address — name, address lines, PIN code, city and state.
- Order contents — the products, quantities and amounts.
- Payment result — the method used, the gateway's payment reference and whether it succeeded. Never the card number, CVV or UPI PIN; those are entered inside the gateway's own payment sheet and never reach us.
- Technical data — IP address and browser user agent, recorded against the checkout session for fraud prevention and debugging.
From merchants
- Store details — your myshopify.com domain and the access token Shopify issues when you install.
- Configuration — your settings, branding and the payment gateway credentials you enter.
- Account details — the email address and name used to sign into the admin.
From this website
If you use the contact form, we get your name, email address, the store URL you supply and your message. These pages set no advertising or analytics cookies.
Why we collect it
- To complete the order — an address is needed to deliver, a phone number to arrange delivery, a payment reference to reconcile and refund.
- To recognise returning shoppers — so a saved address does not have to be typed again.
- To prevent fraud and abuse — OTP verification and rate limiting against the phone number and IP.
- To provide the merchant's own reporting — orders, revenue, abandoned carts and failure reasons.
- To meet legal obligations — a completed sale is a financial record with its own retention rules.
We do not sell personal data. We do not use shopper data to advertise anything, to anyone.
Who else sees it
Only the parties an order genuinely requires, and only the part each one needs:
- The merchant whose store the order was placed on — they are the owner of the customer relationship.
- Shopify — the order is written into the merchant's Shopify admin.
- The payment gateway (Razorpay, Cashfree or PayU) — the amount and the shopper's contact details needed to process and, if required, refund the payment.
- WhatsApp / Meta — the phone number, if the merchant has switched on OTP verification.
- Google — the partial address text typed, if the merchant has switched on address autocomplete. The lookup is proxied through our server, so Google does not receive the shopper's IP address.
How long we keep it
- Orders and payment records — retained while the merchant's account is active, and thereafter as long as tax and accounting law requires.
- Abandoned checkouts — pruned automatically once they are no longer useful for recovery.
- OTP codes — valid for minutes, then discarded.
- Contact form enquiries — kept while we deal with the enquiry and for a reasonable period afterwards.
Deletion and access requests
Shopify's privacy webhooks are implemented in full, so a request made through the merchant's Shopify admin reaches us automatically:
- Customer data request — we record the request together with the matching records so the merchant can answer it. Matching is done on phone number and email as well as the Shopify customer id, because the checkout is guest-first.
- Customer redaction — the person is erased and the purchase is kept in anonymised form. A sale is a financial record with its own retention obligation, so the totals stay reconcilable while nothing left behind identifies anyone.
- Shop redaction — every record belonging to that store is erased. What survives is the store's domain and a timestamp: the record that the erasure happened.
Shoppers should contact the store they bought from. Merchants can write to support@fastrrcheckout.com at any time.
Security
- Everything is served over HTTPS; the certificate renews automatically.
- Card details are captured by the payment gateway's own PCI-DSS compliant sheet and never touch our servers.
- Gateway credentials are stored encrypted and are never rendered back into a page.
- Each store's data is scoped to that store and resolved from a verified session, never from a URL parameter.
- Payment callbacks are rejected unless their signature verifies.
No system is perfectly secure. If you believe you have found a vulnerability, please write to us before disclosing it publicly.
Cookies
The checkout and the admin set a session cookie, which is what keeps you signed in and keeps a half-finished checkout attached to the right person, and a CSRF token cookie, which stops a third-party site submitting a form on your behalf. Both are strictly necessary. There are no advertising cookies and no third-party trackers on the checkout.
Changes to this policy
When this policy changes materially, the date at the top changes with it and merchants are notified. Continuing to use the app after that means the revised policy applies.
Contact
Privacy questions, access requests and complaints: support@fastrrcheckout.com.
Operator details. The registered legal entity, its address and the grievance officer named under the Information Technology (Reasonable Security Practices) Rules should be listed here before this policy is relied on commercially.