App
privacy.

This notice describes data processing when operating and using Offer Master: Function Discounts and handling support enquiries.

Controller and contact

Offer Master: Function Discounts is a VISIONS STUDIO product. The controller for app operation and support is Samuel Marques Lucio, sole proprietor, Sperlingweg 4, 80937 Munich, Germany. Privacy enquiries: contact@marqueslucio.com. Further provider details are in the legal notice.

App and website

This notice covers the Shopify app. The public website is served separately through OpenAI Sites and Cloudflare; the website privacy notice (German) applies to website visits. OpenAI Sites does not host the app database.

Data received from Shopify

For authentication and operation, the app stores the shop domain and Shopify sessions with session ID, authentication state, granted scopes, access token and, where applicable, expiry and refresh data. Installation uses offline access. Where Shopify supplies them, the Shopify session adapter can also contain an admin user's ID, name, email address, locale and account status.

Saved offers contain name, discount method and any discount code, product, variant and collection IDs, quantity tiers, gift rules, schedule, permitted discount combinations, Shopify discount ID, publication status, error details and timestamps. Shop currency and timezone are read from Shopify for amounts and scheduling. The simulator processes selected product variants and the prices and quantities you enter for each calculation. It does not create its own persistent product or collection cache for this.

This version uses product and discount access. It does not request customer or order history, store its own customer records, run its own revenue analytics or process app billing.

Cart discounts and optional gifts

The Shopify Function calculates discounts within Shopify using cart lines, product IDs, quantities, prices, currency and a private gift marker. The optional theme embed receives published gift rules through a Shopify app metafield and uses the store's cart APIs. It adds private line-item properties to gift items. These cart requests are not sent to our app server. The app does not create customer profiles.

Purposes, legal bases and required data

We use the data for secure Shopify access, merchant-configured discount rules, status reconciliation and troubleshooting. Where personal data are necessary to perform the app-use agreement with you, GDPR Article 6(1)(b) applies. For access and support involving employees of a merchant business, operational security and misuse prevention, we rely on Article 6(1)(f); our legitimate interest is the functional and secure operation of the app installed by the merchant.

The shop data and permissions needed for installation and operation are a condition of using the app. There is no legal obligation to install it. Without them, the app cannot provide the connection and discount management.

Support

For an enquiry, we process the message, sender and contact details, and shop or troubleshooting information you choose to provide. Depending on the contractual relationship, Article 6(1)(b) or (f) applies. Our legitimate interest is answering questions and fixing problems. Do not send passwords, access tokens or personal buyer data.

Recipients and international processing

Shopify provides the admin surface, APIs, discount calculation, cart and webhooks. IONOS provides the app server infrastructure and receives email sent to our support address. VISIONS STUDIO operates the app and handles support. The providers process data needed for their respective services.

Shopify describes international processing: its privacy notice says that information from people in the European Economic Area is initially received by Shopify International Ltd. in Ireland and may subsequently be processed, including in Canada and the United States. Shopify describes approved Binding Corporate Rules (BCRs) for internal transfers from the EEA and Switzerland and, where required, Standard Contractual Clauses (SCCs) for third-party processing. See Shopify’s privacy notice. IONOS explains third-country transfers and statutory safeguards in its privacy notice (German) and published data-processing terms (German). You can contact us for further information about the transfers and safeguards described here.

Storage and deletion

Shopify sessions and offer configurations remain stored for app operation. You can delete unpublished drafts in the app. Once a valid Shopify uninstall webhook or shop/redact is delivered and processed, the app deletes the shop's sessions and offers from its active database. Shopify delivers these events. Shopify's own procedures also apply to discount objects and cart data stored there.

Encrypted local backups of the app database and operating configuration are created daily. Backups older than 14 days are deleted at the next daily backup run. A shop deletion therefore removes active data first; existing backup copies expire through this rotation. Restoration is manual and requires reapplying shop deletions processed since the snapshot before returning the restored data to service. The end of an offer's schedule is not a deletion period for its configuration.

The app's front-end web server does not keep an access log. Technical app logs contain reduced startup and error messages and rotate by size: up to two files of 1 MB each. There is no fixed retention period in days. Support messages are deleted when the enquiry is resolved and no further handling purpose or statutory retention reason remains.

Your rights

Subject to the legal conditions, you may request access, correction, erasure, restriction of processing and data portability. For processing based on legitimate interests, you may object on grounds relating to your particular situation. Contact contact@marqueslucio.com. You may also complain to a data protection authority.

The app calculates merchant-defined cart discounts within Shopify. It does not make automated profiling decisions about buyers' personal characteristics. For questions about the processing of your order, contact the relevant store first.

Support

Last updated: 30 September 2026