RateTable — Privacy Policy
Last updated: 8 August 2026
RateTable is a Shopify app that lets a merchant define weight-based shipping rates in a table and writes them into their store’s own native Shopify shipping profiles. This policy explains exactly what the app stores and why.
What we do not collect
RateTable does not request, receive, or store your customers’ personal information. It does not access customer names, addresses, email addresses, order contents, or payment details. The app requests no customer-data scopes, and checkout never contacts our servers — the rates buyers see are native Shopify configuration.
What we store
- Your store domain (for example
example.myshopify.com) and the Shopify access token issued when you install the app. The token is used only to read your shipping settings and write your rate profile. - Your rate configuration — the zones, countries, weight brackets, prices, and shipping option name you enter in the app.
- An activity log of the app’s own operations: when rates were compiled, whether verification succeeded, and any errors. This records app events, not customer or order activity.
- An optional alert email address, only if you choose to enter one so the app can notify you when your rates are changed outside the app.
Shopify scopes and why they are needed
read_shipping,write_shipping— read and write the shipping profile the app manages for you.read_products— attach your products to that profile, so rates apply at checkout.read_locations— shipping profiles require a fulfillment location.read_markets— warn you when a country in one of your rate zones is not an active market, which would otherwise silently block those buyers.
Who else processes this data
- Fly.io — hosting. The application and its database run on Fly.io infrastructure in the United States.
- Google (Gmail SMTP) — used only to deliver operational alert emails to you or to us. No merchant or customer data is included beyond the store domain and the event description.
We do not sell, rent, or share your data with anyone else, and we do not use it for advertising.
Retention and deletion
When you uninstall RateTable, your session and access token are deleted automatically. Your rate configuration and activity log are removed as part of the same process. You can also request deletion at any time by emailing ratetable.support@gmail.com.
RateTable implements Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact). Because the app holds no customer personal data, customer requests return no customer records; shop redaction removes the store’s stored configuration.
Your rights
Depending on where you are based, you may have the right to access, correct, export, or delete the data described above. Contact ratetable.support@gmail.com and we will respond within 24 hours on weekdays.
Security
All traffic to the app is served over HTTPS. Access tokens are stored server-side, are short-lived, and are refreshed by Shopify’s expiring-token flow. The app is accessible only from within your Shopify admin.
Changes
If this policy changes materially, the date above will be updated and, where the change affects how your data is handled, we will notify installed merchants by email.