Who this policy covers
This policy applies to merchants and their staff who install or use PromoMath from the Shopify App Store, and to visitors of the PromoMath pages on this website. PromoMath is a business tool for store owners. It is not directed at children, and it does not collect information from your customers.
What PromoMath reads from Shopify
When you install PromoMath you grant it two read-only permissions: read products and read inventory. Shopify stores Cost per item on the inventory record for a variant, which is why the inventory permission is needed. Using that access, PromoMath reads the following through the Shopify Admin API each time you run an analysis:
- Product and variant titles, and SKUs
- Prices and compare-at prices
- Cost per item, and the currency it is saved in
- Which collections a product belongs to, so you can analyze one collection
- Product status, so draft and archived products and gift cards can be skipped
- Your store's default currency and name, to label the results
This data is read live for the analysis you asked for and is used to calculate margins during that session. PromoMath does not copy your catalog, prices, or costs into its own database and does not keep them after the analysis is shown.
PromoMath does not read or receive customer records, orders, payment details, or customer personal data of any kind. It cannot change prices, create discounts, or edit products; its permissions are read-only.
What PromoMath stores
- Your Shopify session. When you install the app, Shopify issues an access token so the app can read your store on your behalf. PromoMath stores that token together with your store domain and the permissions granted in a Postgres database. Without it the app cannot call Shopify. Depending on how Shopify issues the session, the record may also carry the name, email address, and locale of the staff member who opened the app, as provided by Shopify.
- A small settings record. Your last minimum margin, whether you have dismissed the first-run guide, how many analyses you have run, and whether the app has asked you for a review. This is saved as an app-owned metafield inside your own Shopify store, not in a database run by JPM Inc.
Billing
Subscriptions and the free trial are handled by Shopify App Pricing. Shopify bills you and holds your payment details. PromoMath only asks Shopify whether your store has an active subscription so it can decide whether to show the app or the plan page. JPM Inc never sees your card or bank information.
Analytics
The PromoMath app itself contains no analytics scripts, tracking pixels, or advertising tools.
The PromoMath listing on the Shopify App Store is hosted by Shopify. We have connected a Google Analytics property to that listing through Shopify's listing tools, so visits to the listing page may be measured by Google Analytics. Shopify's privacy policy governs that page.
This website, jamesmckinney.xyz, uses Google Analytics to count page visits, including visits to these PromoMath pages. That measurement is separate from the app and never includes your store data.
Service providers
PromoMath runs on a small set of providers, each of which processes data only so the app can work:
- Shopify provides the platform, the Admin API, app billing, and the App Store listing.
- Vercel hosts the application and runs the code that performs each analysis.
- Supabase hosts the Postgres database that holds the session record described above.
- Google Analytics measures visits to the App Store listing and to this website, as described under Analytics.
No other third party receives data from PromoMath. JPM Inc does not sell store data and does not share it for advertising.
How long data is kept
- Session record. When you uninstall PromoMath, Shopify sends an uninstall notice and the app deletes the session record for your store. Shopify sends a second shop-data erasure request 48 hours after uninstall, and the app runs the deletion again at that point as a safeguard.
- Settings metafield. It lives in your store, and Shopify removes app-owned metafields when the app is uninstalled.
- Analysis data. Not retained. It is read for the analysis you requested and not stored afterwards.
- Customer data requests. Shopify may forward a customer data access or erasure request. Because PromoMath holds no customer data, there is nothing to return or erase, and we confirm that within 30 days.
Security
Access to your store is limited to the two read-only permissions above. Requests between Shopify, the app, and the database travel over encrypted connections, and the app verifies that requests from Shopify are genuine before acting on them. The database is not publicly reachable and is accessed only by the app. No system is perfectly secure, and we will tell affected merchants if we learn of a breach involving their data.
Your rights and choices
You can uninstall PromoMath at any time from your Shopify admin, which removes its access and triggers deletion of its stored session. You can also ask what is held about your store, or ask for it to be deleted, by emailing james@jamesmckinney.xyz. We answer within 30 days. Depending on where you are, you may have additional rights under local privacy law, and we will honor them.
Changes to this policy
If this policy changes, the date at the top of the page changes with it. Material changes will be noted inside the app.
Contact
JPM Inc, Michigan, United States
james@jamesmckinney.xyz