Privacy policy

Last updated September 30, 2026

Mint Limits is a Shopify app made by Mint Labs ("we", "us"). It lets a merchant set minimum and maximum order quantities, pack sizes and order value limits, which Shopify checks at checkout. This policy explains what the app handles, why, and when it's deleted.

The short version

  • We store the merchant's rules and app settings. We don't store anything about the merchant's customers: no names, emails, addresses, orders or carts.
  • The limits are checked by a Shopify Function inside Shopify's checkout. It reads the cart and, for tag rules, whether a signed-in customer has a tag — and can't send that anywhere; nothing reaches our servers.
  • We never sell or share data, use it for advertising, or combine it across stores. No cookies, no tracking.

Information about merchants

InformationWhy
Store domain and a Shopify access tokenTo create and update the store's checkout rule, save the rules for the theme blocks, and let the product/collection pickers and the simulator read product titles, prices and collection membership.
Rules and messages: what each rule applies to (product, variant and collection IDs with their titles), the limits, customer tags typed by the merchant, custom message texts, store currencyTo run the limits the way the merchant set them up.
Plan and subscription statusRead from Shopify to decide which features apply. Payments are handled entirely by Shopify.
When the storefront blocks last loaded, and whether the last update to Shopify succeededTo show setup status and problems on the app home.

Information about the merchant's customers

InformationHow it's usedKept
Cart contents, the customer's language and, for rules limited to tagged customers, whether the signed-in customer has one of those tagsRead by the app's Shopify Function inside Shopify's checkout to check the limits and show the message. Functions can't send data anywhere; nothing reaches us.Not stored
The cart (on the storefront)The storefront script reads the shopper's own cart from the store (Shopify's cart API) in their browser to show limits and cart messages. It isn't sent to us.Not stored
Browser storage on the shopper's deviceLocal storage keeps the date the script last told us "the block is live" (so it does that at most once a day, with no shopper data); session storage keeps which rule collections products belong to, so cart messages work across pages. No cookies.On the device

Because the app holds no customer data, Shopify's customer privacy requests (customers/data_request, customers/redact) have nothing to return or delete; we acknowledge them. When a store is deleted (shop/redact, sent 48 hours after a merchant uninstalls) we permanently delete everything we hold for the store.

Where data is processed and how it's protected

The app runs on Cloudflare (hosting and database) and connects to Shopify's APIs. Data is encrypted in transit (TLS) and at rest. Access is limited to Mint Labs staff who need it to provide support. We use no other sub-processors, analytics or trackers. See our security policy.

Retention

Rules and settings are kept while the app is installed and deleted 48 hours after uninstall (so a quick reinstall doesn't lose them). Access tokens are deleted as soon as the app is uninstalled. Rate-limit counters for the storefront status ping are deleted within a day.

Your rights

Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly and can delete their rules in the app at any time. We respond within 30 days.

Changes

If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.

Contact

Mint Labs — support@stickermint.com