Box Blocker Bob™ Privacy Policy

Effective September 29, 2026

This policy describes how Box Blocker Bob™ (the "App"), a Shopify app operated by Vintage Villages, 302 Carlaw Ave. Unit 123b, Toronto, Ontario, M4M 3L1, Canada ("we", "us"), collects, uses and retains information when a merchant installs and uses the App on a Shopify store.

Information we collect

When a merchant installs the App, Shopify provides us with the store's domain and an access token that allows the App to act on the store within the permissions the merchant grants. The App requests only permission to read and write checkout validations.

The App stores the settings the merchant chooses (for example, which address types to refuse, the messages shown at checkout, and minimum order amounts by region) and any block or allow rules the merchant enters. A block or allow rule may contain information the merchant types in, such as a street address, a name with a postal code, an email address, an email domain, a telephone number, a customer account, a postal code, a region or a country. The App stores this information only because the merchant chose to enter it.

The App does not collect information about shoppers. Addresses entered at checkout are evaluated by a Shopify Function running within Shopify's checkout; they are not transmitted to or stored by the App. Personal entries in a block or allow list are provided to the Function as one-way fingerprints rather than in readable form.

How we use information

We use the information described above solely to provide the App's functions to the merchant: to apply the merchant's rules at checkout, to display and edit those rules in the App, and to answer the merchant's support requests. We do not sell information, use it for advertising, or share it with third parties, except with our hosting provider (Fly.io, Inc.), which stores the App's data on our behalf, and with Shopify as required to operate the App.

Retention and deletion

Settings and rules are kept while the App is installed. A merchant may edit or delete any rule at any time within the App. When a store uninstalls the App and Shopify sends its shop data erasure request, we delete all of that store's settings, rules and access tokens.

Where Shopify forwards a customer's request to delete their information, we delete every block or allow rule in that store that is keyed on the customer's email address, telephone number or customer account, and we update the store's checkout rules accordingly. Rules keyed on a street address or on a name with a postal code are not linked to the customer in the request and remain under the merchant's control; the merchant may remove them at any time. Where Shopify forwards a customer's request for access, we identify any rules keyed on that customer.

Security

Information is transmitted over encrypted connections and stored, encrypted at rest, on servers located in Canada. Backups are encrypted and are deleted automatically after five days. Access to the App's servers and accounts is limited to the operator of the App and is protected by two-step authentication.

The App keeps an access log recording when a store's block or allow list is viewed or changed, by which store staff account, and when Shopify's privacy requests are processed. The log records the type and number of entries concerned, not their contents, and entries are deleted after one year or when the store's data is erased.

Data processing terms for merchants

By installing the App, the merchant engages us to process, on the merchant's behalf, the information described in this policy, and these terms form part of the agreement between the merchant and us. The merchant determines what information is entered into the App and remains responsible for having a lawful basis to use it. We process that information only to provide the App's functions as described above and on the merchant's documented instructions, which are the settings and rules the merchant enters.

We keep the information confidential, maintain the security measures described above, and engage only the sub-processors named in this policy (Fly.io, Inc. for hosting, and Shopify for the operation of the App). We will assist the merchant, so far as the App allows, in responding to requests from individuals exercising their privacy rights. We will notify the merchant without undue delay, and in any event within 72 hours of becoming aware of it, of any security incident affecting the merchant's information. When the App is uninstalled and Shopify sends its erasure request, we delete the merchant's information as described under Retention and deletion.

Your rights

Merchants and shoppers may have rights under applicable privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the General Data Protection Regulation where it applies. Shoppers should first contact the merchant whose store they used, as the merchant controls any rule that may concern them. Requests may also be sent to us at the address below.

Changes

We may update this policy from time to time. The effective date above will change when we do.

Contact

Questions about this policy: bob@vintagevillages.ca