Last updated: July 27, 2026
This Privacy Policy explains what data JLX Shipping Rates & Routing ("the app") collects, how it's used, and how it's protected. The app is built and operated by JLX InnoTech.
When a merchant installs the app, we collect:
The app never stores a customer's name, email address, phone number, or postal address.
It does read addresses, but only in the moment. At checkout, the app reads the destination postcode, state, and city from the address Shopify sends it, purely to calculate a matching shipping rate, and does not save that address anywhere. If you're on a plan with Order Routing enabled, the app reads a new order's shipping address to decide which fulfillment location it should be assigned to; again, the address is used and discarded.
The one customer-linkable thing the app does keep is the per-order record described above, used for the Reports feature. It holds a Shopify order reference, the delivery option chosen, the amounts, and which of your zone rows matched - never the address itself. The order reference is needed so the same order can't be counted twice, and so the record can be found and erased if a customer asks.
Store and configuration data is used only to operate the app for your store: calculating shipping rates at checkout, and (if enabled) routing new orders to the right location. We don't sell data, and we don't use it for advertising or share it with any third party other than Shopify itself, which processes it as the platform the app runs on.
Your store's data is kept for as long as the app stays installed. When you uninstall, the app immediately deletes its session credentials, but deliberately keeps your configuration and report history for a short window - roughly 48 hours - because uninstalls are often accidental or part of re-approving permissions, and that window means a reinstall doesn't cost you your rate table. Shopify then sends a shop redact request, at which point everything for your store is permanently deleted: rate tables, accessory rules, location rules, settings, and report records.
The app also responds to Shopify's standard data protection webhooks. A customer redact request deletes the app's per-order report records for the orders Shopify lists, which is everything the app holds that could be linked to that customer. A customer data request is logged and can be answered from those same records, since no name, email, phone, or address is stored to hand over. A shop redact request deletes all of that shop's data as described above.
One record is kept beyond that deletion: an audit log of when the app accessed data, and of the deletion itself. It holds no personal data - a store domain, a date, the type of action, and a count - and exists so that data handling can be reviewed after the fact. Deleting it alongside the data it describes would leave nothing documented.
You are the controller of your store's data. This app is a processor: it handles that data only on your instructions, for the purposes described above, and for no purpose of its own. We do not decide what data your store collects, and we do not use it to build any profile, model, or product of our own.
Two other processors are involved, both acting on our behalf: Shopify, as the platform the app runs inside and the source of every piece of data it receives, and Heroku (a Salesforce company), which hosts the application server and its database. No one else receives your data - we do not sell it, share it for advertising, or pass it to any other third party.
The app's server and database are hosted in the United States (Heroku's US region, running on Amazon Web Services infrastructure). If your store operates outside the United States, the data described in this policy is transferred to and stored in the US.
Worth knowing what that transfer does and doesn't include: no customer name, email address, phone number, or postal address is ever stored, so none of those cross a border. Destination postcodes are read at checkout and discarded without being written down. What is stored is your configuration, plus one record per order holding an order reference, the delivery option chosen, the amounts, and which of your zone rows matched.
Data is stored in a managed PostgreSQL database, access-controlled and reachable only by the app's own backend. Every record is tied to a specific store, so one merchant's data is never mixed with or exposed to another's.
Data is encrypted in transit (TLS between your browser, Shopify, and the app, and for the app's own database connections) and encrypted at rest on disk. Test and production environments are kept separate, so real store data is never used for development or testing.
We may update this policy from time to time as the app changes. The "Last updated" date above reflects the most recent revision.
Questions about this policy or your data? Email info.jltechconsulting@gmail.com.