How AirLock handles information for merchants and storefront visitors.
AirLock (“AirLock,” “we,” “us,” “our”) is a storefront security application for Shopify that allows merchants to screen, block, and redirect traffic to their online stores based on IP address, geographic location, and bot/VPN detection signals.
AirLock is operated by [LEGAL ENTITY NAME, e.g. Digital Lofts LLC], a [STATE] limited liability company located at [REGISTERED ADDRESS].
This policy explains what information we handle, why, and what rights you have. It applies to our website, our Shopify application, our merchant dashboard, and our storefront screening service.
AirLock handles two very different categories of information, and our legal responsibilities differ for each. This distinction runs through the rest of this policy.
When you are a merchant who installs AirLock, we act as a data controller (GDPR) / business (CCPA/CPRA) with respect to your account information. We decide how that information is used, and this policy governs it.
When a visitor arrives at a merchant’s storefront and AirLock screens that visit, we act as a data processor (GDPR) / service provider (CCPA/CPRA) on behalf of that merchant. The merchant is the controller. We process visitor information only on the merchant’s documented instructions — namely, the block lists, allow lists, and redirect rules that merchant has configured. We do not use visitor information for our own purposes.
If you are a storefront visitor and want to exercise privacy rights over information processed during a visit, direct your request to the merchant whose store you visited. We will assist that merchant in responding. If you contact us directly and can identify the store, we will forward your request.
Our processing of visitor information on a merchant’s behalf is governed by our Data Processing Addendum, available at getairlock.com/dpa, which is incorporated into our Terms of Service.
When you install AirLock through Shopify, we receive from Shopify’s OAuth flow:
yourstore.myshopify.com) and storefront URLWe also collect:
Billing. Subscription charges are handled entirely by Shopify Billing. We do not receive, process, or store your payment card details. We receive only subscription status and plan level from Shopify.
No third-party product analytics. We do not use Mixpanel, PostHog, Amplitude, Segment, FullStory, Hotjar, or any comparable product analytics, session recording, or behavioral tracking service in the AirLock dashboard. Your use of the app is not instrumented for any third party.
When a visitor loads a page on a merchant’s storefront where AirLock is active, or attempts to complete checkout on a Shopify Plus store using our Checkout UI Extension, we process:
We log screening events. Logging blocked and flagged attempts is a core feature of AirLock — it is what populates the threat log in your merchant dashboard. The records above are retained as described in Section 7.
We do not collect or process storefront visitors’ names, email addresses, shipping or billing addresses, order contents, or payment information. AirLock does not request Shopify’s Protected Customer Data scopes. [VERIFY against your app’s actual requested scopes before publishing.]
An IP address is treated as personal data under the GDPR and UK GDPR, and as personal information under the CCPA/CPRA. We treat it accordingly even though it does not identify a person by name.
On getairlock.com we collect standard server log data. We do not run any third-party analytics, session recording, or advertising trackers on our website. Cookie details are in Section 11.
AirLock uses WebSocket connections in the following ways. A WebSocket is a persistent two-way connection between a browser and our servers that lets data move in real time without repeated page requests.
Merchant dashboard. When you have the AirLock dashboard open, we may open a WebSocket connection to stream new screening events into your threat log as they happen, so the log updates live without refreshing. Over this connection we transmit the screening event records described in Section 3.2 — the same records already stored for your store — plus the authentication context needed to confirm the connection belongs to your session and route events only to your store.
Storefront screening. When a visitor loads a page on a merchant’s storefront where AirLock is active, AirLock opens a WebSocket connection from the visitor’s browser to our servers at [DOMAIN, e.g. api.getairlock.com] in order to screen the visit. Over this connection we transmit the request metadata described in Section 3.2 — IP address, derived geolocation, network metadata, risk signals, and request context — and return the screening decision for that visit (allow, block, or redirect). The connection exists to carry out the screening the merchant has configured. It is not used to observe the visitor’s activity on the page.
Regarding these connections:
wss://). We do not accept unencrypted connections.Origin of every connection and authenticate the session before transmitting any data.That last point matters and we state it deliberately: AirLock is not a session replay or behavioral analytics tool, and our real-time connections are not used to observe the contents of a visitor’s interaction with a store.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the app, authenticate you, and honor your configuration | Performance of a contract |
| Bill you and manage your subscription | Performance of a contract |
| Provide support and respond to inquiries | Performance of a contract; legitimate interests |
| Maintain security, prevent abuse of our own service, and debug | Legitimate interests |
| Improve and develop features | Legitimate interests |
| Send service announcements | Legitimate interests |
| Send marketing email | Consent, where required |
| Comply with legal obligations | Legal obligation |
We process visitor information solely to perform the screening the merchant has configured: evaluating each visit against the merchant’s rules, applying the resulting allow, block, or redirect action, and recording the outcome in the merchant’s log. The legal basis for this processing is determined by the merchant, who is the controller. In most cases merchants rely on legitimate interests in fraud prevention and network security, which Recital 49 of the GDPR expressly recognizes.
Merchants: this is your obligation, not ours. You are responsible for disclosing AirLock’s screening in your own storefront privacy policy, identifying an appropriate legal basis, and complying with any applicable consent requirements in the jurisdictions you serve.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have never done so.
We share information with the following categories of subprocessors:
| Subprocessor | Purpose | Data handled | Location |
|---|---|---|---|
| Shopify Inc. | App platform, authentication, billing | Merchant account data | Canada / US |
| [HOSTING PROVIDER] | Application hosting and databases | All categories | [REGION] |
| [IP INTELLIGENCE PROVIDER — e.g. MaxMind, IPinfo, ipapi] | Geolocation and VPN/proxy/bot lookups | Visitor IP addresses | [REGION] |
| [CDN/EDGE — e.g. Cloudflare] | Delivery, TLS termination, DDoS protection | Request metadata | Global |
| [ERROR MONITORING — e.g. Sentry] | Diagnostics | Technical logs | [REGION] |
| [EMAIL — e.g. Postmark, Resend] | Transactional and support email | Merchant email | [REGION] |
A current list is maintained at [SUBPROCESSOR PAGE URL]. We will give merchants advance notice of new subprocessors as set out in our DPA.
We may also disclose information where required by law, valid legal process, or to protect our rights, our users’ safety, or the integrity of our service. If we receive a government request for merchant or visitor data, we will notify the affected merchant unless legally prohibited.
If AirLock is acquired or merges with another company, information may transfer as part of that transaction. We will notify merchants before their information becomes subject to a different privacy policy.
| Data | Retention |
|---|---|
| Merchant account and configuration | Duration of installation, then [30/60/90] days after uninstall |
| Screening event logs (blocked/flagged attempts) | 30 days, rolling |
| Allowed-visit records | [SPECIFY — if not retained, say “not retained”] |
| Aggregate counts and statistics (no IP addresses) | Retained indefinitely |
| Support correspondence | [e.g. 24 months] |
| Server and error logs | [e.g. 30 days] |
| Billing records | As required by tax and accounting law, typically 7 years |
On uninstall. When you uninstall AirLock, Shopify sends us a shop/redact webhook. We delete or irreversibly anonymize your store’s data within 48 hours of receiving it, except where retention is legally required. See Section 10.
[IMPORTANT: the 30-day screening log retention above must be enforced by an actual TTL or scheduled purge. Confirm before publishing. The remaining bracketed rows still need numbers that match what your infrastructure does. A stated retention period you don’t enforce is a worse position than a long one you do.]
We are based in the United States and process information there [AND: other regions if applicable]. If you or your visitors are in the European Economic Area, the United Kingdom, or Switzerland, information is transferred outside those regions.
For those transfers we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable. Our SCCs are incorporated into the DPA at getairlock.com/dpa. We apply supplementary technical measures including encryption in transit and at rest.
We maintain technical and organizational measures appropriate to the risk, including:
No system is perfectly secure. If we become aware of a breach affecting personal information, we will notify affected merchants without undue delay and, where required, within 72 hours of becoming aware, consistent with GDPR Article 33 and applicable US state breach notification laws.
Scope of access. AirLock accesses data from a merchant’s Shopify store only through the API access scopes that merchant granted at installation, and only as needed to operate the Service. We do not request Shopify’s Protected Customer Data scopes. Our handling of Shopify data is also governed by Shopify’s own terms for app developers and by our DPA at getairlock.com/dpa.
Mandatory webhooks. As a Shopify app we implement Shopify’s mandatory privacy webhooks:
customers/data_request — a merchant’s customer has requested their data. We respond with any data we hold for the identified individual, or confirm we hold none.customers/redact — a merchant’s customer has requested erasure. We delete or anonymize matching records within 30 days.shop/redact — sent 48 hours after uninstall. We delete the store’s data as described in Section 7.Note that AirLock’s visitor records are keyed to IP addresses and are not linked to Shopify customer accounts, so in most cases a customers/data_request will return no matching records.
Merchant dashboard. We use strictly necessary cookies to maintain your authenticated session. These cannot be disabled without breaking the app.
getairlock.com. Our website sets no cookies. We do not use analytics, advertising, or session recording cookies, so no consent banner is required and there is nothing for you to opt out of.
Storefront screening. AirLock does not set cookies on storefront visitors’ devices, and does not write to or read from local storage, session storage, or any other client-side store. Screening operates on the request metadata described in Section 3.2, transmitted over the WebSocket connection described in Section 4. Because that connection carries the screening data directly, AirLock has no need to store an identifier on the visitor’s device. We do not fingerprint devices.
Merchant responsibility. Where a merchant is required to obtain consent or provide notice to storefront visitors under the ePrivacy Directive or any other law applicable to that merchant’s storefront, obtaining that consent is the merchant’s responsibility. AirLock does not display any notice or consent interface to storefront visitors and cannot discharge this duty on a merchant’s behalf. See Section 5.
You have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing based on legitimate interests. You may lodge a complaint with your local supervisory authority. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
Under the CCPA/CPRA you have the right to know, delete, correct, and opt out of sale or sharing, and to limit use of sensitive personal information. We do not sell or share personal information and do not use sensitive personal information for purposes requiring a limitation right. We will not discriminate against you for exercising any right.
For storefront visitor information, AirLock acts as a service provider. We process that information only to perform the screening service, and we are contractually prohibited from retaining, using, or disclosing it for any other purpose.
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights, including appeal rights where a request is denied.
Contact [privacy@getairlock.com]. We respond within 30 days (45 days in California, extendable). We may need to verify your identity, typically by confirming control of the store domain or email on file. You may use an authorized agent where the law permits.
AirLock is a business tool not directed to children. We do not knowingly collect personal information from anyone under 16. AirLock’s screening operates on network metadata and does not distinguish visitor age.
We may update this policy. Material changes will be announced by email to merchants and by notice in the dashboard at least [14/30] days before taking effect. The “Last updated” date above always reflects the current version. [Consider keeping an archive of prior versions at a stable URL.]
[LEGAL ENTITY NAME] [ADDRESS] Privacy: [privacy@getairlock.com] Support: [support@getairlock.com]
[If you have EEA merchants: you likely need an EU representative under GDPR Art. 27 and possibly a UK representative under Art. 27 UK GDPR. Name them here, or note that you have assessed and concluded the exemption applies.]