Privacy policy
Last updated 5 September 2026
Who we are
Zonify is a Shopify app that decides which visitors may reach a merchant's storefront, using rules the merchant sets. In this policy, “we” means Zonify, “you” means the merchant who installs the app, and “a visitor” means a person or program that loads a page on your store.
For data about your visitors, you are the data controller and we are your processor. We handle that data only to apply the rules you set and to show you what happened, and only on your instructions.
What we do not ask Shopify for
The app requests no access scopes. It cannot read your orders, your products or your customers, and it does not ask to. It reads your store's name and myshopify.com domain, which every installed app can, and it holds the access token Shopify issues at install so that it can answer Shopify's requests.
What we record about a visitor
On every storefront page load, a small script asks the app whether the visitor may stay. To answer, and to show you what happened, we record:
- The visitor's country, as a guess made from the time zone and language their browser reports
- The visitor's IP address, as forwarded to us by Shopify
- The browser's user agent string, and the device type, browser name and version we read from it
- The page visited and the page that linked to it
- Screen size, time zone and language, as the browser reports them
- Whether the visitor was blocked, and which rule did it
- How long the visit lasted and how many pages it covered
Visits are grouped into a session for four hours using a random identifier the script stores in the browser's session storage. It is not a tracking cookie, it is not shared with anyone, and it is gone when the tab closes.
What we never collect
- Names, emails, phone numbers, addresses, or orders. The app has no access to any of them and no field to hold them.
- Anything from a third party. The script does not call any outside service to look up a visitor. Every request goes only to Shopify's app proxy for your store.
- Card or payment details. We never see them.
How we use it
- To decide, on each page load, whether the visitor may stay
- To show you which visits were blocked and why
- To let you export that record as a spreadsheet
- To investigate faults you report to us
We do not sell this data. We do not share it with advertisers. We do not use it to build profiles of visitors across stores.
Content protection
If you switch content protection on, the storefront script also loads a second script that stops right-click, image dragging and copying on your pages. That script records nothing and sends nothing. Pasting into form fields keeps working so checkout is not affected.
Who else touches the data
- Shopify — every request from your storefront to the app passes through Shopify's app proxy, which signs it. Shopify is also how you install and uninstall the app.
- Our hosting and database provider — stores the app, your rules and the visit log.
How long we keep it
Your rules and settings are kept for as long as the app is installed. The visit log is kept so you can look back at it; there is no automatic expiry today, and we will add one and say so here before the app is listed publicly.
When you uninstall, we delete the visit log at once — every recorded visit and its IP address. Your rules and settings are kept, so that reinstalling brings back your country list, your allowed addresses and your bot choices instead of an empty page. If you want those gone as well, Shopify's shop/redact request, which Shopify sends 48 hours after uninstall, removes everything we hold for your store.
We answer all three of Shopify's privacy requests — customers/data_request, customers/redact and shop/redact. Because the visit log holds no customer identifiers, a request about a specific customer has nothing it can match; we say so in our response rather than claim to have deleted something.
Your visitors' rights
A visitor may ask you what is held about them, or ask for it to be deleted. The log is keyed by IP address and session, not by name, so such a request needs the IP address and the approximate time. Forward it to business@frostleaf.co and we will action it within 30 days.
Security
Data is encrypted in transit. Every request from a storefront is verified against Shopify's signature before it is read, so a request that did not come through Shopify's proxy for your store is refused. Shopify webhooks are verified the same way. Rules, settings and the visit log live in a managed Postgres database with restricted access.
Changes
We will update this page when the app changes, and change the date at the top. Material changes will be emailed to installed merchants.