Skip to content

Privacy policy — Restrict Multi Discount Codes Shopify app

Last updated: August 11, 2026

This Privacy Policy describes how Restrict Multi Discount Codes (“the App”, “we”, “us”) handles information when merchants install and use the App.

Restrict Multi Discount Codes is primarily an extension-only Shopify app. Checkout UI extensions run in the buyer’s checkout session on Shopify’s infrastructure. A lightweight Cloudflare Worker supports app installation (OAuth) and Shopify privacy compliance webhooks. We do not collect or store customer personal data for marketing or advertising.

The checkout extensions:

  • Read the number of discount codes or gift cards already applied to the cart (via Shopify checkout APIs).
  • Read merchant-configured limits from checkout editor block settings (max_discount_codes, max_gift_cards).
  • Display banners and, when limits are exceeded, block checkout progress with validation messages.

This processing happens within Shopify checkout. We do not receive discount codes, gift card numbers, or customer identities on our servers.

For installation and compliance, the Worker may store:

  • Shop domain (for example example.myshopify.com)
  • A temporary OAuth nonce used to verify install requests

This data is stored in Cloudflare D1 and is used only to operate and secure the app. It is removed when no longer needed or upon shop redaction/uninstall per Shopify’s compliance topics.

The App does not:

  • Store customer names, emails, addresses, or payment details
  • Sell or share personal information for advertising
  • Track individual buyers across sites (checkout extensions do not set third-party cookies)

This documentation site at https://restrict-multi-discount-codes.k2.digital/docs/ is informational. It uses Google Tag Manager and Google Analytics 4 (configured in GTM) to understand aggregate page views and improve documentation. See your browser’s controls and Google’s policies for analytics data.

The App registers Shopify privacy webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store customer personal data, there is typically nothing to export or delete for individual customers. Shop redaction removes shop-level install data from our database.

The App requests only the permissions declared at install time. Checkout extensions use Shopify checkout APIs available to UI extensions with block_progress enabled.

You control maximum limits in the checkout editor, whether to install or uninstall the App, and whether to add one or both extension blocks.

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the latest revision.

For privacy questions, email tech@k2.digital or see Support.