Skip to content
Install

Privacy Policy

Last updated: 21 September 2026

Launch Lock (“the App”) is operated by K2 Digital (“we”). This policy describes what personal data the App processes when a merchant installs it on a Shopify store, and why.

Launch Lock lets merchants schedule who may buy a product and from which date. It writes rules onto product metafields, enforces them at checkout with a Shopify Function, and shows the schedule on the product page.

  • Merchant store data: store domain, an API access token, granted permissions, and the plan status. Stored in our database for as long as the App is installed.
  • Merchant configuration: rule sets, purchase windows, messages, and the products they apply to. Stored in our database.
  • Customer segment list: for each customer who carries one of the merchant’s configured tags, the App writes a list of those tag names to a Shopify customer metafield ($app.segments). This list is stored in Shopify, not in our database. It contains tag names only — no name, email, phone, address, or order data. Our database keeps only the customer’s Shopify ID and the time of the last sync.
  • Customer identifiers at checkout: the Shopify Function receives the cart, whether the buyer is signed in, and the segment list above. This runs inside Shopify; nothing is transmitted to or stored by us.

We do not read or store customer names, email addresses, phone numbers, postal addresses, or order history.

Solely to provide the App’s functionality: deciding whether a customer may purchase a gated product. We do not use the data for analytics, advertising, profiling, or any other purpose, and we do not sell or share it with third parties.

Merchant data is stored on Cloudflare infrastructure (Workers and D1), encrypted at rest and in transit. Customer segment lists are stored by Shopify on the merchant’s store.

  • When a merchant uninstalls the App, all data we hold for that store is deleted.
  • When Shopify notifies us of a customer erasure request, we delete the customer’s sync record. The segment metafield is deleted by Shopify with the customer.
  • When Shopify notifies us of a store erasure request, we delete all data for that store.

Merchants decide which customer tags the App treats as segments and what those tags mean. Merchants remain the data controller for their customers’ data; we act as a processor on their behalf.

Questions about this policy: tech@k2.digital.

Install on the Shopify App Store

Merchant documentation · Support