Effective date: September 14, 2026 Last updated: September 14, 2026
This Privacy Policy describes how B2B Rewards Engine (the "App") processes information when the App is installed on or used with a Shopify store.
The App is operated by Sugoi Digital LLC, doing business as Sugoi Digital ("Developer," "we," "us," or "our").
1. Scope
This Privacy Policy applies to information processed through B2B Rewards Engine in connection with Shopify merchants, authorized merchant administrators, B2B customers, customer accounts, orders, rewards, and related Shopify resources.
The App provides B2B rewards functionality, including campaign administration, qualifying-order tracking, reward issuance, reward redemption, reward reconciliation, customer-account reward visibility, analytics, and reporting.
2. Information We Process
Merchant and administrator information
When a merchant installs or uses the App, we may process information supplied by Shopify that is necessary to authenticate and operate the App, including:
- Shopify shop domain and shop identifiers.
- Shopify user or administrator identifiers.
- Authentication and session information.
- Access and refresh tokens.
- Account role and authorization information.
- Administrator first name, last name, email address, locale, and related session information when supplied by Shopify's authentication system.
Merchant administrator information is used to authenticate authorized users and operate the App. It is separate from the protected Shopify customer data described below.
Shopify customer and order information
To provide B2B rewards functionality, the App processes a limited set of Shopify customer- and order-related data, which can include:
- Shopify customer IDs.
- Shopify order IDs.
- Shopify order names or order numbers.
- Order dates and status information.
- Qualifying order subtotals and adjusted subtotals.
- Redemption order subtotals and net reward revenue.
- Currency.
- Refund and cancellation information needed to reconcile rewards.
- B2B company IDs, company names, company-location IDs, and company-location names.
- Reward status, reward amounts, redemption minimums, and expiration dates.
- Shopify discount IDs and reward discount codes.
- Reward reissue and order-adjustment history.
- Customer and order identifiers included in Shopify privacy requests.
The App does not intentionally request or use Shopify customer name, customer postal address, customer email address, or customer phone number as part of its B2B rewards functionality.
Merchant-provided configuration
The App processes settings and configuration entered by authorized merchants, including campaign names, campaign dates, reward tiers, redemption requirements, selected B2B companies or locations, and other rewards-program settings.
Operational and security information
The App may generate limited operational information necessary to operate, secure, and troubleshoot the service.
Application logging is designed to avoid logging protected customer payloads and direct customer identifiers. Logs may include non-customer operational information such as shop domain, webhook topic, internal request identifiers, processing outcomes, timestamps, and generic error types.
3. How We Receive Information
We primarily receive information through:
- Shopify APIs.
- Shopify webhooks.
- Shopify Customer Account and Checkout extension contexts.
- Shopify authentication and session mechanisms.
- Configuration submitted by authorized merchant users.
We do not use B2B Rewards Engine to collect customer information for advertising profiles or behavioral advertising.
4. How We Use Information
We process information only as reasonably necessary to provide, secure, maintain, and support B2B Rewards Engine.
Purposes include:
- Determining whether an order qualifies for a rewards campaign.
- Creating and restricting reward discount codes to eligible Shopify customers.
- Displaying eligible rewards to authenticated B2B customers.
- Tracking reward issuance, redemption, expiration, voiding, refund adjustments, and reissues.
- Reconciling rewards following order cancellations or refunds.
- Producing merchant-facing rewards history, analytics, and reports.
- Authenticating merchant administrators and customer-account requests.
- Preventing unauthorized access to rewards.
- Responding to Shopify privacy requests.
- Maintaining service security and troubleshooting operational failures.
- Complying with applicable legal obligations.
We do not sell protected customer data.
We do not use protected customer data for unrelated advertising, data-broker activity, or independent customer profiling.
5. Data Minimization
The App is designed to process the minimum Shopify customer data necessary for B2B rewards functionality.
B2B Rewards Engine currently targets Shopify Level 1 protected customer data and is not designed to request the separately protected customer fields for:
- Name.
- Address.
- Email.
- Phone.
If App functionality changes so that additional protected fields are required, we will review and update our data practices and obtain any required Shopify approval before relying on those fields in production.
6. Data Retention
We apply different retention periods based on the purpose of the data.
Privacy-request snapshots
When Shopify sends a customer data request, the App may temporarily store a snapshot containing responsive App data so the merchant can review and fulfill the request.
Pending privacy-request snapshots are retained for no more than approximately 30 days and are cleared earlier when the request is fulfilled or when a matching customer-redaction request requires removal.
A minimal non-sensitive request record may remain after the protected snapshot is cleared so the App can record that the privacy workflow occurred.
Reward and operational history
Reward records are retained while the merchant continues to use the App for as long as they are reasonably necessary to operate the rewards program and provide:
- Reward administration.
- Redemption and refund reconciliation.
- Historical reporting.
- Merchant analytics.
- Reward reissue and adjustment history.
- Program auditing.
Expiration of a reward does not by itself delete the historical reward record because the record continues to support merchant reporting and reconciliation functions.
When Shopify sends an applicable customer-redaction request, matching customer and order identifiers are removed or redacted from retained reward data in accordance with the request.
Shop uninstall and shop deletion
When the App receives Shopify's uninstall or shop-redaction event, the App deletes the merchant's App data from its active application database, including rewards, campaigns, settings, privacy-request records, and App authentication sessions, subject to any retention required by applicable law.
7. Shopify Privacy Requests
B2B Rewards Engine implements Shopify privacy workflows for:
- Customer data requests.
- Customer redaction requests.
- Shop redaction requests.
Requests are authenticated before processing.
For customer redaction, the App removes or redacts matching customer and order identifiers from applicable App records while preserving non-identifying financial or operational history where appropriate.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information processed by the App.
Current safeguards include:
- TLS-encrypted application traffic.
- TLS-required production database connections.
- Server-side enforcement that rejects non-SSL database connections.
- Encryption at rest provided by managed database infrastructure.
- Verification of Shopify webhook signatures.
- Authentication and authorization checks for merchant and customer-account requests.
- Shop-scoped database access in App workflows.
- Limited operational logging designed to exclude protected customer payloads.
- Automated clearing of expired privacy-request snapshots.
- Deletion of App data following shop cleanup events.
- Secret values stored outside source code.
No method of electronic transmission or storage can be guaranteed to be completely secure.
9. Service Providers and Subprocessors
We use service providers to operate B2B Rewards Engine.
Current infrastructure providers include:
- Railway, for application hosting and execution.
- Supabase, for managed PostgreSQL database infrastructure.
These providers may process information on our behalf only as needed to provide their services to us.
10. International Processing
The App's current production infrastructure is hosted in the United States.
Information may be processed in the United States or other jurisdictions in which approved service providers operate.
Where required by applicable law, appropriate safeguards for international transfers will be used.
11. Merchant and Customer Privacy Rights
Privacy rights vary by jurisdiction and may include rights to access, correct, delete, restrict, or obtain information about the processing of personal data.
Shopify merchants are generally the primary point of contact for their customers regarding store data.
When Shopify sends a supported privacy request to the App on behalf of a merchant or customer, B2B Rewards Engine processes the request through its Shopify privacy workflow.
Merchants can also contact us regarding App-specific privacy questions.
12. Children's Data
B2B Rewards Engine is a business-to-business rewards application and is not designed or intended for use by children.
We do not knowingly use the App to collect personal information from children for independent purposes.
13. Changes to This Privacy Policy
We may update this Privacy Policy when our services, data practices, subprocessors, or legal obligations change.
We will update the "Last updated" date when material changes are made and provide any additional notice required by applicable law.
14. Contact
Developer: Sugoi Digital LLC, doing business as Sugoi Digital Privacy contact: hello@sugoidigital.co Mailing address: 27010 Coco Flower Ln, Katy, Texas 77493, United States Country: United States