Information we collect
We collect information needed to create merchant accounts, process crypto payments, operate Shopify integrations, provide support, prevent abuse, and meet legal and compliance obligations.
- Merchant account information, such as business name, support email, wallet addresses, billing status, team access, and security settings.
- Shopify store information, such as shop domain, app installation status, granted scopes, store settings, and webhook delivery metadata.
- Shopify order and payment information needed to create and reconcile payment sessions, including order identifiers, order amounts, currency, payment status, refund status, and customer email when Shopify provides it.
- Crypto payment information, such as payment amount, token, network, transaction signature, settlement wallet, receipt status, and cNFT receipt metadata.
- Technical information, such as IP address, user agent, request logs, error logs, rate-limit events, and authentication events.
How we use Shopify data
We use Shopify data only to provide and support the Aelith Pay integration for the merchant that installed or authorized the app.
- Create a Shopify payment session when a buyer chooses Aelith Pay at checkout.
- Redirect buyers to the hosted crypto checkout and return them to Shopify after payment or cancellation.
- Update payment, capture, refund, and void status through Shopify payment APIs.
- Help merchants reconcile Shopify orders with on-chain transaction records.
- Respond to Shopify app uninstall, customer data request, customer redact, and shop redact webhooks.
How we share information
We do not sell merchant or customer data. We share information only when needed to provide the service, comply with law, protect the platform, or complete an action requested by the merchant or customer.
- With Shopify, to complete app installation, payment-session updates, webhook handling, and app compliance requests.
- With blockchain networks, where transaction details are public by design once a payment or refund is submitted on-chain.
- With infrastructure providers used for hosting, databases, logs, storage, email delivery, monitoring, and rate limiting.
- With compliance, legal, or security reviewers when required to investigate fraud, abuse, sanctions risk, or legal requests.
Data retention and deletion
We keep information for as long as needed to operate payments, maintain audit records, resolve disputes, support merchants, and meet legal obligations. When Shopify sends a customer redact or shop redact webhook, Aelith Pay removes or de-identifies covered Shopify data from the active service where required.
Security
We use encryption, access controls, webhook signature verification, mTLS-aware payment ingress checks, audit logging, and monitoring to protect merchant and payment data. No method of transmission or storage is completely secure, so merchants should also protect their account credentials, wallets, and Shopify admin access.
Merchant and customer rights
Merchants may request access, correction, export, or deletion of account information, subject to legal, security, and transaction-record retention requirements. Shopify customer privacy requests should be submitted through Shopify when they relate to a Shopify order or customer record.
Contact
For privacy or data requests, contact Aelith Pay at support@aelith.ai. Include the Shopify shop domain, merchant account email, and enough detail for us to identify the affected records.