Privacy Policy
Checkout Sentry App
Last updated: July 2, 2026
This Privacy Policy describes how IDCLIP APLICATIVOS E SOLUÇÕES LTDA, registered under CNPJ No. 67.687.255/0001-45 (“IDCLIP”, “we”), processes Personal Data within the scope of the Checkout Sentry app (“App”), in compliance with Law No. 13.709/2018 (“LGPD”) and other applicable regulations.
1. Roles in data processing
1.1. The App processes Personal Data in two distinct contexts, with different roles:
- Store Consumer Data (buyers who interact with checkout): the Merchant is the Controller and IDCLIP acts as Processor, processing data under the Merchant's instructions, as set forth in the Data Processing Addendum (DPA).
- Merchant Data (account, contact, App usage, and billing): IDCLIP acts as Controller, as such data is processed to enable the relationship with the Merchant.
2. Data we process
2.1. Data provided by the Merchant or collected in the relationship
- Store owner identification and contact data (name, email, and other Shopify account data);
- Store configuration data and alert preferences (Slack, email, WhatsApp, webhooks);
- Usage records, access logs, and technical App data (date/time, IP address, dashboard session identifiers).
2.2. Data accessed via Shopify APIs (processed as Processor, on behalf of the Merchant)
To monitor checkout and diagnose failures, the App accesses, according to scopes authorized at installation:
- Customer/Consumer data: name, email, phone, and address, as well as sensitive, device, and activity data when made available by the platform;
- Order and checkout data: cart items, amounts, coupons, shipping and payment options, status, and checkout events;
- Checkout navigation and behavior data: steps completed, fields with errors, abandonment points, and friction signals;
- Error and anomaly data: gateway, shipping, and coupon failures and other technical events detected at checkout stages;
- Store data and analytics: order metrics and performance data required for diagnosis.
Data minimization. We process only Personal Data strictly necessary for the App to function. Whenever possible, we use aggregated or anonymized data.
3. Purposes of processing
- Monitor the Store's checkout in real time and detect failures, errors, and friction;
- Generate diagnostics, alerts, webhooks, and reports for the Merchant;
- Identify the source of problems (buyer, operations, shipping, or payment) and enable accountability vis-à-vis third-party providers;
- Provide support, ensure security, prevent fraud and abuse, and comply with legal and regulatory obligations;
- Operate, maintain, and improve the App, including through aggregated/anonymized data.
4. Legal bases (LGPD, Art. 7 and Art. 11)
Processing relies, as applicable, on the following legal bases:
- Performance of contract (Art. 7, V) — to provide the features contracted by the Merchant;
- Legitimate interest (Art. 7, IX) — for security, fraud prevention, and App improvement, always with impact assessment and safeguards;
- Compliance with legal or regulatory obligation (Art. 7, II);
- Consent (Art. 7, I, and Art. 11, I), when required.
With respect to Consumer Data, defining the legal basis is the responsibility of the Merchant, as Controller. IDCLIP processes such data under the Merchant's instructions.
5. Sharing and subprocessors
5.1. IDCLIP does not sell Personal Data. Sharing occurs only in the following cases:
- Infrastructure providers acting as subprocessors, under contract and security and confidentiality obligations — Cloudflare (data ingestion) and Supabase (data persistence/storage);
- Shopify, as the platform on which the App operates;
- Alert channel providers chosen by the Merchant (for example, Slack, email provider, and WhatsApp), when configured by the Merchant;
- Public authorities, when required by law, court order, or legitimate request;
- In corporate reorganizations, subject to maintenance of obligations under this Policy.
The list of subprocessors is detailed in the Data Processing Addendum (DPA).
6. International data transfers
6.1. Cloud providers and Shopify may process or store data outside Brazil. In such cases, IDCLIP adopts safeguards compatible with the LGPD (Art. 33), such as appropriate contractual clauses and engagement of providers that offer equivalent protection guarantees.
7. Retention and deletion
7.1. Personal Data is retained only for as long as necessary for the purposes of this Policy. Checkout event history is retained according to the period of the plan contracted by the Merchant (for example, 30, 60, 90, or 180 days), after which it is deleted or anonymized.
7.2. Some data may be retained for a longer period when necessary to comply with a legal obligation, exercise rights, or upon authority determination.
7.3. Upon termination of the relationship with the Merchant, Personal Data processed as Processor is deleted or returned in accordance with the DPA, subject to legal retention requirements.
8. Information security
8.1. IDCLIP adopts technical and administrative measures to protect Personal Data, including:
- Encryption of data in transit and at rest;
- Access control based on the principle of least privilege and authentication;
- Logging, monitoring, and environment segregation;
- Internal security and confidentiality policies and periodic vendor assessment.
8.2. No system is entirely immune to incidents. In the event of a security incident that may pose relevant risk to data subjects, IDCLIP will notify the Merchant and, when applicable, the National Data Protection Authority (ANPD) and data subjects, under the LGPD.
9. Data subject rights
9.1. Under Art. 18 of the LGPD, the data subject may request: confirmation of processing; access to data; correction; anonymization, blocking, or deletion of unnecessary or unlawfully processed data; portability; information about sharing; and revocation of consent.
9.2. When IDCLIP acts as Processor, Consumer requests should, as a rule, be directed to the Merchant (Controller). IDCLIP will assist the Merchant in handling requests, as provided in the DPA.
9.3. Requests may be sent to the Data Protection Officer at dpo@checkoutsentry.com. We may request information to confirm the requester's identity.
10. Cookies and dashboard technologies
10.1. The App dashboard may use cookies and similar technologies strictly necessary for authentication, security, and service operation. Non-essential cookies, if used, will comply with applicable legal bases.
11. Data Protection Officer (DPO)
11.1. IDCLIP provides a channel to address matters related to Personal Data and this Policy:
Data Protection Officer (DPO): dpo@checkoutsentry.com
Controller: IDCLIP APLICATIVOS E SOLUÇÕES LTDA — Rua Areobaldo Pinto dos Santos, No. 04, Santos Dumont, Vila Velha/ES, ZIP 29.109-340, Brazil
12. Changes to this Policy
12.1. This Policy may be updated at any time. The current version will always be identified by the “last updated” date and made available on the App page and official website. Material changes will be communicated by reasonable means.
13. Governing law and jurisdiction
13.1. This Policy is governed by Brazilian law, with the courts of Vila Velha, State of Espírito Santo, Brazil elected as the forum, without prejudice to mandatory forums, such as the consumer's domicile.