Captcha Guard (“the App”) is a Shopify application provided by Coastal Division (“we”, “us”). This policy explains what the App collects, why, and how it is handled. Questions go to hello@captchaguard.app.
What the App does
Captcha Guard helps merchants block automated (bot) checkouts and form spam by verifying visitors with Google reCAPTCHA before checkout, and enforcing that verification during checkout.
Information we collect
From the merchant (store owner)
-
Store domain (for example
example.myshopify.com) and the Shopify access token issued during installation. - App settings you choose: protection mode, sensitivity level, and which surfaces are protected.
- Your Google reCAPTCHA keys. Secret keys are encrypted at rest using AES-256-GCM. They are never displayed back to you after saving, and are used only to verify tokens with Google.
From store visitors (shoppers)
When a shopper triggers a protected action, such as starting checkout, the App records a verification event containing:
- The outcome of the check (passed, low score, challenge failed, no token) and the reCAPTCHA score.
- A cart or order identifier, used to match the verification to the order.
-
A truncated IP address. Full IP addresses are never
stored. IPv4 addresses are truncated to the /24 network (for example
203.0.113.0) and IPv6 to the first three segments. This is too coarse to identify an individual visitor.
The App does not collect names, email addresses, postal addresses, payment details, or browsing history. It does not use tracking cookies and does not build visitor profiles.
Information shared with third parties
Google reCAPTCHA. To verify that a visitor is human, the App sends the reCAPTCHA token and the visitor’s IP address to Google’s verification service. Google’s handling of that data is governed by the Google Privacy Policy and Terms of Service. Google reCAPTCHA also loads in the visitor’s browser on protected pages and may set cookies under Google’s own policies.
We do not sell data, and we do not share it with anyone else.
How data is stored and secured
Data is stored in a managed PostgreSQL database hosted in the United States. All traffic between shoppers, the store, and the App is encrypted with TLS. reCAPTCHA secret keys are additionally encrypted at rest with AES-256-GCM, using a key held separately from the database.
Data retention and deletion
- When you uninstall the App, your session and access token are deleted immediately.
- Verification events are kept only as long as needed to power the in-app dashboard and activity log, and are deleted when the store’s data is purged.
-
We implement Shopify’s mandatory privacy webhooks:
customers/data_request(respond to a shopper’s request for their data),customers/redact(delete verification events tied to the specified orders), andshop/redact(delete all settings and events for the store, 48 hours after uninstall).
You may request deletion of your store’s data at any time by emailing hello@captchaguard.app.
Your rights
Depending on where you live, including under the GDPR and CCPA, you may have the right to access, correct, export, or delete personal data we hold, and to object to its processing. Because the App stores only truncated IP addresses and no direct identifiers, we are usually unable to link stored data to a specific individual. Merchants can direct shopper requests to us at the address above, and we will respond within 30 days.
Data processing terms for merchants
For merchants who install the App, this section forms our data processing agreement. Coastal Division acts as a processor (or service provider) of the limited shopper data described above, and the merchant is the controller. We process that data only to provide the App’s features, on the merchant’s behalf and configuration, and for no other purpose. We do not sell personal data. Our subprocessors are Google (reCAPTCHA verification) and Railway (hosting and database); we will update this policy before adding others. We apply the security measures described above, delete all stored data when the App is uninstalled and on receipt of Shopify’s redaction webhooks, and will assist merchants with data subject requests as described under “Your rights.”
Children’s privacy
The App is not directed at children and does not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected in the “Last updated” date above and, where required, communicated to merchants directly.