Privacy Policy
AfterCover: warranty registration & claims for Shopify. Last updated 28 July 2026.
AfterCover is a Shopify app that lets a merchant's customers register products for warranty coverage and file claims. This page explains what the app stores, why, and how to have it removed. In data-protection terms the merchant who installs AfterCover is the controller of their customers' data; AfterCover is a processor acting on their behalf.
What we store
| Data | Why |
|---|---|
| Shop domain, access token, plan and app settings | To install the app, keep you signed in, and apply your settings. |
| Customer name, email address and (if provided) phone number | To identify whose warranty a registration is, and to let that customer look it up later. |
| Product name, serial number, order number, purchase date, purchase channel | To calculate the coverage period and match the registration to a warranty policy. |
| An uploaded proof-of-purchase image, if the customer attaches one | Optional evidence the merchant asked for. |
| Claim descriptions and any photos the customer uploads with a claim | So the merchant can assess the claim. |
| Answers to any extra form fields the merchant configured | Whatever the merchant chose to ask. |
Customers give this information directly through the registration or claim form on the merchant's storefront. We do not buy data, and we do not track visitors across sites.
What we do not do
- We send no email. AfterCover has no mail service and never emails customers or merchants. Customers see their warranty on screen and can retrieve it any time from the merchant's warranty page.
- We never sell, rent or share personal data for advertising.
- We do not use customer data to train machine-learning models.
- We take no commission on warranties sold through the app; payments go directly through the merchant's own Shopify checkout, and we never see card details.
Who else may receive data
Only the services needed to run the app, or ones the merchant switches on themselves:
- Shopify: the platform the app runs on.
- Vercel: application hosting.
- Neon: the managed PostgreSQL database where records are stored.
- Klaviyo or Mailchimp: only if the merchant configures them and the customer ticks the marketing box on the form.
- Gorgias or Zendesk: only if the merchant configures them, to open a support ticket for a claim.
Where data is stored, and for how long
Records are stored in the European or United States region of our database provider and kept while the app is installed, because a warranty is only useful for as long as it lasts. When a merchant uninstalls, Shopify sends a shop-redaction request 48 hours later and we delete everything belonging to that shop: registrations, claims, policies, settings and sessions.
Your rights
AfterCover implements Shopify's mandatory privacy webhooks, so requests raised through a merchant's store reach us automatically:
- Access: a customer data request tells the merchant what we hold, so they can pass it on.
- Erasure: a customer redaction request anonymises that person's registrations and clears the text and photos they submitted with any claim.
- Shop erasure: all data for a shop is deleted after uninstall.
Depending on where you live you may also have the right to correct data, object to processing, or complain to a supervisory authority. Customers should contact the store they bought from first, since it is their data; merchants can contact us directly.
Security
All traffic is served over HTTPS. Storefront requests are verified with Shopify's signed app-proxy HMAC, and admin requests with Shopify's session tokens, so a request cannot be forged from outside. Data is encrypted at rest by our database provider, including its backups. Access to the production database is restricted to the application and the app owner. Development runs against a separate database, so testing never touches live records. Whenever a merchant opens an individual customer's registration or claim, or exports registrations, that access is recorded in an audit log.
Data processing terms
These terms form the data processing agreement between AfterCover ("processor") and each merchant who installs it ("controller"), and take effect on installation. They apply alongside Shopify's own terms.
- Subject matter and duration: processing the personal data described above so the app can provide warranty registration and claims, for as long as the app is installed.
- Nature and purpose: storing, organising, retrieving and deleting registration and claim records on the merchant's behalf. Nothing else.
- Data subjects: the merchant's customers who register a product or file a claim.
- Instructions: we process personal data only on the merchant's documented instructions, which the app's settings express, and as required by law.
- Confidentiality: anyone with access to the data is bound to keep it confidential.
- Security: we apply the measures described under Security above.
- Sub-processors: Shopify, Vercel and Neon, plus any marketing or helpdesk tool the merchant connects. We remain responsible for their performance, and we will give notice before adding another so the merchant can object.
- Assistance: we help the merchant answer access, correction and erasure requests, and we support them on security, breach notification and impact assessments. Shopify's privacy webhooks handle the common cases automatically.
- Breach notification: we notify the merchant without undue delay after becoming aware of a personal data breach affecting their data.
- Deletion: on uninstall we delete all of the merchant's data. A copy can be exported from the app beforehand.
- Audit: on request we make available the information needed to demonstrate compliance with these terms.
- International transfers: where data leaves the EEA or UK, the transfer relies on the European Commission's standard contractual clauses, which our hosting and database providers have in place.
A merchant who needs a countersigned agreement can request one at ranzostore1@gmail.com.
Children
AfterCover is a business tool and is not directed at children.
Changes
If this policy changes we will update the date at the top of this page. Material changes affecting merchants will also be noted in the app.
Contact
Questions, data requests, or anything else: ranzostore1@gmail.com. We aim to reply within two business days.