CashEnginePrivacy PolicyTerms of Service

CashEngine Privacy Policy

Last updated: September 17, 2026

CashEngine: Upsell & Bundles ("CashEngine", "the app") is a Shopify app published by Ehud Erlich ("we", "us"). This policy explains what information the app collects when a merchant installs it, how we use it, and the choices merchants and their customers have.

Contact: erlich.udi@gmail.com

1. Who this policy covers

  • Merchants who install CashEngine on a Shopify store.
  • Shoppers who visit a store that uses CashEngine. For shopper data, the merchant is the controller and we act as the merchant's processor.

2. Information we collect

From the merchant's store (through Shopify APIs, with the merchant's permission)

  • Store details: shop domain, store name, contact email, currency, languages, time zone, country, plan.
  • Products, variants, prices, collections and inventory status, used to build and show offers.
  • Orders created or paid in the store: order ID, line items, amounts, discount codes, payment status, and the customer's email address and phone number when the order involves an app offer, a lead or a message the merchant sends through the app.
  • Discounts created by the app and shipping settings, when the merchant turns on the free-shipping sync.

From shoppers on the storefront

  • Offer interactions: which offer was shown, clicked or added to the cart, with a random session identifier. The identifier is kept in the shopper's browser storage across visits only when the shopper's analytics consent (Shopify's Customer Privacy API) allows it; otherwise it lasts only for the browser tab session.
  • Lead forms, only when the shopper submits one: name, email address and/or phone number, and the consent choices the shopper ticked. Consent boxes are never pre-selected.
  • WhatsApp replies, when the merchant has connected WhatsApp and the shopper writes back, including opt-out requests.

From the merchant directly

  • Settings, offer configurations, designs and, if the merchant connects WhatsApp, the WhatsApp number the merchant links and the access token of that WhatsApp line (stored encrypted).

We do not collect payment card details. Checkout and payment are handled by Shopify and the merchant's payment provider.

3. How we use information

  • To run the app's features: show offers, apply discounts, count revenue from paid orders, capture leads, and send WhatsApp messages the merchant configures.
  • To send leads to the merchant's Shopify customer list, with the shopper's marketing consent.
  • To provide support, fix problems, prevent abuse and keep the service secure.
  • To bill the merchant through Shopify's billing system.

We do not sell personal information, we do not use shopper data for advertising, and we do not combine data between different stores.

4. Messages to shoppers

WhatsApp messages are sent only from the WhatsApp number the merchant linked and only to shoppers who gave consent or have a transactional reason to be contacted (for example, an unpaid order). Every message flow honours opt-out: a shopper who replies STOP is not messaged again by that store. Merchants are responsible for complying with the messaging and marketing laws that apply to them.

5. Service providers (subprocessors)

ProviderPurposeLocation
ShopifyPlatform, authentication, billingGlobal
Vercel Inc.Application hostingUnited States
Neon Inc. (Databricks)Encrypted PostgreSQL databaseUnited States (AWS us-east-2)
Whapi.CloudWhatsApp message delivery, only for merchants who connect WhatsApp (through the app's Whapi partner account, or the merchant's own Whapi account)See whapi.cloud
Google LLC (Google Fonts)Web fonts for the storefront offer widget, loaded only when the merchant's widget design uses one of the Google fonts offered in the design settings (Assistant, Heebo, Rubik, Secular One, Frank Ruhl Libre). The shopper's browser then requests the font from fonts.googleapis.com, and Google receives the shopper's IP address and browser details. Designs that use the theme's font load nothing from GoogleGlobal

Each provider processes data only to deliver its service to us.

6. Retention

  • Store data is kept while the app is installed. When the merchant uninstalls, Shopify sends a shop data erasure request 48 hours later and we delete that store's data.
  • Shopper profiles (with their activity timeline), leads and WhatsApp message logs: deleted after 730 days (24 months) without activity by default. Merchants can change this within 90–1825 days on the app's Privacy page.
  • Shopper contact details (email, phone, checkout link) on order and reminder records, and abandoned-cart records: removed after 180 days by default. Merchants can change this within 60–1825 days.
  • Storefront events: deleted after 180 days by default. Merchants can change this within 90–730 days.
  • WhatsApp inbox messages: deleted after 90 days by default. Merchants can change this within 30–730 days.
  • WhatsApp opt-out (STOP) records are kept while the app is installed, so that shopper is never messaged again by that store.
  • Fixed periods that merchants cannot change: webhook logs are deleted after 30 days, and data export files for customer data requests are deleted after 30 days.

7. Shopper rights and GDPR/CCPA requests

Shoppers can ask the merchant to access or delete their data. Shopify forwards these requests to us through its mandatory privacy webhooks (customer data request, customer erasure, shop erasure), and we complete them within 30 days. Shoppers and merchants can also write to erlich.udi@gmail.com.

8. Security

Data is encrypted in transit (TLS) and at rest. Messaging credentials and data request exports are additionally encrypted at the application level (AES-256-GCM). Production access is limited to the developer, protected by strong passwords and two-factor authentication, and logged. Test data is kept separate from production data. We have a written incident response procedure and will notify affected merchants and Shopify without undue delay if a breach affects their data.

9. International transfers

Data is stored in the United States. Where the law requires it, transfers rely on the providers' standard contractual clauses.

10. Children

CashEngine is a business tool and is not directed to children.

11. Changes

We will post changes on this page and update the date above. Material changes will be shown in the app.

12. Contact

Ehud Erlich, Israel
erlich.udi@gmail.com

CashEngine: Upsell & Bundles