Privacy policy
Last updated 24 August 2026.
Hammerdown is a Shopify app that runs timed auctions on a merchant's store. This policy describes what the app stores, why it stores it, and how long it keeps it. It covers both the merchants who install the app and the shoppers who bid through it.
What we store about a merchant
When a merchant installs the app we store their store domain, the access token Shopify issues for the store, the plan the store is subscribed to, and the app's own settings for that store. Access tokens are encrypted at rest with AES-256-GCM and are used only to call Shopify's Admin API on the store's behalf.
We also store the auctions a merchant creates, the bids placed on them, and the resulting event history, which is what the app's reporting and exports are built from.
What we store about a shopper
When a shopper bids, we store the Shopify customer identifier for their account alongside the bid amount and the time. The same identifier is recorded on an auction's current high bidder and winner, on invitations to a private auction, and on the record of a notification email we sent.
We do not store shopper names or email addresses. When the merchant's admin needs to show a bidder's name, or the app needs to email a bidder, that detail is read from Shopify's Admin API at the moment it is needed and is not written to our database. This means a shopper's contact details stay under the merchant's control in Shopify.
Why we store it
To run auctions and settle them: to accept and rank bids, to stop a product under auction from being bought at its catalog price by anyone but the winner, to invoice the winner at the price they won, and to send the notifications a merchant has enabled. We do not sell this data, and we do not use it for advertising or profiling.
Cookies
This website and the install flow set one session cookie, which holds the anti-forgery token that protects the Shopify authorization step. The app's embedded admin authenticates each request individually and sets no cookie at all. There are no advertising cookies, analytics cookies, or third-party trackers on any of our pages.
Who else processes the data
We use a small number of service providers, each of which processes data only to provide their service to us:
- Shopify, the platform the app runs on and the source of store and customer records.
- Fly.io, application hosting, in the United States.
- Supabase, the PostgreSQL database, in the United States.
- Resend, delivery of the app's transactional email.
- Sentry, error tracking. When something in the app fails, Sentry receives the error, the code path that raised it, and the address the request came from. Request bodies are never sent, so a shopper's details cannot reach it.
How long we keep it
A store's data is kept for as long as the app is installed, because the auction history is what the merchant's own reporting reads. Roughly 48 hours after a merchant uninstalls, Shopify asks us to erase the store, and we delete the shop record together with its auctions, bids, invitations, event history, notification records, and API keys.
When Shopify asks us to erase an individual shopper, we replace that shopper's identifier everywhere it appears for that store with a random pseudonym. The auction history stays internally consistent, so a merchant's past results still add up, while the person behind those bids can no longer be identified or linked across auctions. The pseudonym is random rather than derived from the identifier, so it cannot be reversed. A request is scoped to one store: the same shopper at a different store is untouched.
Your rights
If you are a shopper, the merchant whose store you bid on is the controller of your data, and a request to access or erase it is best made to them: Shopify passes it to us and we act on it as described above. You are welcome to contact us directly as well, and we will work with the merchant to answer you.
If you are a merchant, you can export your auction and bid data from the app at any time, and uninstalling begins the erasure described above.
Changes
If this policy changes in a way that affects what we store or who processes it, we will update the date at the top of this page and, for a material change, notify installed merchants by email.
Contact
Hammerdown is operated by Daniel Cardone, a sole proprietor in Massachusetts, United States, who is the controller of the data described above. Questions about this policy, or about data held for your store, can go to support@hammerdown.app.