Privacy Policy

Last updated: August 14, 2026

Who we are

Churn Death (“Churn Death”, “we”, “us”) is a subscription-management app for Shopify stores. Merchants install it to sell and manage recurring subscriptions; it schedules renewals through Shopify, sends subscription emails on the merchant’s behalf, and gives their customers a page to manage their own subscriptions.

This policy covers the Churn Death app at app.churndeath.com, the subscription options our widget adds to a merchant’s product pages, the subscriptions page we add to a store’s customer account area, and the emails the app sends. You can reach us any time at communication@churndeath.com.

Merchants and their customers

Two different groups of people appear in this policy, and our role differs for each.

  • Store customers (shoppers). When a shopper subscribes at a store, the merchant decides why and how that data is used — they are the data controller. Churn Death processes it on the merchant’s behalf, as their processor, to run their subscriptions. Shoppers should direct privacy requests to the store they subscribed with, or to Shopify; those requests reach us automatically (see Retention and deletion).
  • Merchants. For the account data a merchant gives us to run the app — store domain, store contact details, access credentials, settings — Churn Death is the controller.

What we collect through Shopify's APIs

When a merchant installs the app, Shopify grants it access to specific parts of the store. We copy only what running subscriptions requires:

  • Store customer details: name, email address and phone number, as held by the store.
  • Subscription details: the products, quantities and prices in each subscription, its currency, status, delivery schedule and shipping cost, and its next billing date.
  • Billing outcomes: when a renewal was attempted, whether it succeeded or failed, the error code when it failed, and a reference to the resulting Shopify order.
  • Order records used for merchant analytics: order date, totals, tax, currency, and whether the order included a subscription. These records deliberately contain no customer fields at all.
  • Merchant and store data: the store’s myshopify domain, store name, time zone and contact email address, the permissions granted to the app, and the access credentials Shopify issues for the store.
  • Store catalogue data: products, variants and subscription plans, which contain no personal data.

We never receive or store payment card details. Shopify stores payment methods and performs every charge. We hold no payment-method identifier either: we simply ask Shopify to charge a given subscription, and Shopify uses the method the shopper saved with the store.

What merchants give us directly

The settings and configuration a merchant enters in the app — such as subscription plans, retry rules for failed payments, and which subscriber emails to send — and any correspondence when a merchant emails us for support.

What we collect directly from store customers

Almost nothing beyond what Shopify passes us above. Specifically:

  • The subscription options we add to a merchant’s product pages run entirely in the shopper’s browser and make no calls to our servers. We do not see storefront browsing, and we set no cookies there.
  • The subscriptions page in a store’s customer account area sends only the requests needed to show and manage that shopper’s own subscriptions, authenticated by a token Shopify issues after the shopper signs in.
  • Our emails contain no tracking pixels — open and click tracking are switched off, so we do not record whether an email was opened or a link was clicked.
  • Cookies: the app uses strictly necessary authentication cookies only — for example a session cookie that keeps a signed-in merchant signed in, and a short-lived cookie during the Shopify sign-in handshake. Our own internal support tools use their own sign-in cookies, which are never set for a merchant or a shopper. There are no advertising cookies and no third-party analytics trackers anywhere in the app. For completeness: the app’s pages, including this one, load a typeface from Shopify’s content network, so Shopify sees that request.

How we use this data

  • To run subscriptions: work out when each subscription is due and ask Shopify to charge it, then record the result and reschedule the next one.
  • To send subscription emails on the merchant’s behalf: renewal reminders, subscription confirmations, and notices when a payment fails or an order cannot be fulfilled. Merchants can switch each type off.
  • To power the subscriber page where shoppers pause, skip, reschedule or cancel their own subscriptions.
  • To show merchants analytics about their subscription revenue — computed from the order records described above, which contain no customer fields.
  • To provide support and fix problems. Access to production data is restricted to the operator, and access through the app’s own administrative tools is recorded in an access log.
  • To meet legal obligations, including responding to the data-request and deletion notifications Shopify sends us.

We do not sell personal data, we do not use it for advertising, and we do not share it with anyone beyond the service providers listed below.

Service providers

We keep this list short on purpose. These are the only third parties that process data on our behalf:

Service providers that process data on our behalf, what they do, and where they process it
ProviderWhat they doWhere
ShopifyThe platform the store runs on. Data originates there, syncs to us, and Shopify performs all payments and orders.Per Shopify’s own policy
Fly.ioApplication hosting and our database.Frankfurt, European Union
ResendDelivers the emails the app sends.United States
GitHubBuilds and deploys the app, and triggers its scheduled jobs. No personal data is sent there.United States

Retention and deletion

  • We keep a store’s data for as long as the app is installed, because that is what running its subscriptions requires.
  • When a shopper asks to be erased (Shopify relays the request to us), we erase their personal details — name, email address, phone number, and the recipient address on emails we sent them. Records of transactions are kept with those personal details removed rather than deleted outright: charges, renewals and their outcomes are business and financial records. To be precise about what that does and does not achieve: those records stay linked to the store’s own customer reference, so the merchant and Shopify can still tell whose they are, while we no longer hold anything that identifies the person. We also record the fact that an erasure happened, so a later sync cannot re-import the data.
  • When a merchant uninstalls the app, the store’s access credentials are deleted immediately. About 48 hours later Shopify sends us a store-deletion notification, on which we erase the store’s customer personal data and the store contact address, and delete the order records used for analytics.
  • What remains after a store is offboarded: subscription and billing history with the personal details removed, plan and product configuration, and the app’s settings for that store are kept as business records. We do not currently apply a fixed deletion schedule to them; when we introduce one, we will state it here.
  • Data access requests relayed by Shopify are completed within 30 days: we send the merchant a summary of what we hold for that customer, so they can pass it on.
  • Operational records of the notifications Shopify sends us are pruned on a rolling ~30-day cycle, and server logs are short-lived.

Where data is stored and international transfers

The application and its database are hosted in the European Union (Frankfurt).

When the app sends an email, the recipient’s address and the content of that message are processed in the United States by our email provider.

No provider other than the ones listed above processes this data for us. Two honest qualifications: our hosting provider operates a global network, so a request may be routed through a location nearer to the visitor before it reaches our servers in Frankfurt; and the store’s data also lives with Shopify, whose own storage and processing locations are governed by Shopify’s privacy policy rather than ours.

Security

  • All traffic to and from the app is encrypted in transit (HTTPS).
  • Access credentials issued by Shopify are stored server-side and are never exposed to the browser.
  • Every notification we accept from Shopify is cryptographically verified before it is acted on.
  • Access to production data is restricted to the operator, and access through the app’s own administrative tools is recorded in an access log.

Your rights

Depending on where you live, you may have the right to access a copy of your personal data, to have it corrected or erased, to restrict or object to how it is used, and to receive it in a portable form.

  • If you are a store customer, exercise these rights through the store you subscribed with, or through Shopify. Shopify relays such requests to the apps a store uses, so they reach us automatically, and we complete them within 30 days. You are welcome to contact us directly as well, but we will normally need to work through the merchant, since the data is theirs.
  • If you are a merchant, contact us at communication@churndeath.com and we will respond within 30 days.

You also have the right to complain to your local data protection authority.

Changes to this policy

We will update this page as the app changes, and the “Last updated” date at the top will tell you when it last changed.

Contact

Questions about this policy, or about the data we hold, go to communication@churndeath.com. We answer over email.