Privacy Policy
Lokally - Regional Engine, operated by Nocodelane
This policy explains what personal data Lokally collects and processes, why, who we share it with, how long we keep it, and your rights. It is written in plain language, but it is a binding document.
1. Who we are
Lokally - Regional Engine ("Lokally" or the "App") is a Shopify app that lets merchants set regional prices, payment rules, storefront content and rewards by PIN code or region. It is operated by Nocodelane, based in Kolkata, West Bengal, India ("we", "us", "our").
This policy also covers our website, getlokally.com.
NocodelaneKolkata, West Bengal, India
Email: support@getlokally.com
2. Our role: controller and processor
We handle personal data in two different capacities:
- As a controller for data about merchants who install the App (store owners and staff) and visitors to getlokally.com. We decide why and how that data is used, as described here.
- As a processor (a "data processor" or "service provider") for data about a merchant's shoppers and customers, which we process only on the merchant's behalf and on their instructions, to provide the App's features. For that data the merchant is the controller, and our Data Processing Addendum applies. Shoppers should read the privacy policy of the store they shop with and send requests about their data to that store.
3. Data we collect about merchants
From Shopify, when you install and use the App
- Store details: store domain, contact email, currency and Shopify plan. Used to run the App, show prices in your currency, send you service emails (for example customer data request reports) and apply the right billing.
- Access credentials: the access and refresh tokens Shopify issues to the App. Used only to call Shopify on your store's behalf.
- Staff details: if Shopify provides them for a signed-in staff member, their name, email and locale. Used to keep the admin session working.
- Billing status: your plan and subscription status from the Shopify Billing API. We never see or store card or bank details; Shopify bills you.
What you create in the App
Regions and their PIN codes, pricing rules, payment rules, storefront content, reward rules, email templates and settings, plus a history of changes (who changed what, and when) so you can review them.
Support and feedback
Messages you send through the in-app chat, by email, or through our feedback form, and the contact details you give us, so we can answer you.
How you use the App
Product usage events (for example "rule created" or "changes published"), identified by your store domain, and technical error reports, so we can fix problems and improve the App. See section 7 for the services we use.
4. Data we process for merchants about their shoppers
We process the following on the merchant's behalf, as their processor:
The region or PIN code a shopper enters
When a shopper enters a PIN code or chooses a region in the store's popup, the App's storefront code saves it in the shopper's browser (see section 10) and adds it to the shopper's Shopify cart (cart attributes _pce_region and _pce_pincode) so checkout can apply the right price and payment rules. Once an order is placed, these become part of the merchant's order in Shopify.
The location button
If the merchant turns on the popup's location button and a shopper taps it and allows location access in their browser, the shopper's browser sends their location coordinates directly to OpenStreetMap's Nominatim service, which returns the matching postcode. The coordinates are not sent to us. The postcode is then used like a PIN code the shopper typed.
Region analytics
When a shopper uses the popup, the storefront sends us an event: what happened (for example "PIN code entered" or "popup skipped"), the PIN code entered and the region it matched. We store it with the store domain and time, but not the shopper's name, email or IP address. Merchants use these to see, for example, which PIN codes shoppers asked for that no region covers.
Rewards
When a merchant's reward rule applies to an order, we read the order from Shopify and store the order number, the customer's email address and first name, the reward given and whether the reward email was sent. We use this to issue the reward (for example a Shopify discount code), email it to the customer if the merchant has turned reward emails on, and show the merchant a reward log.
Orders we are notified about
Shopify notifies the App about paid, cancelled and refunded orders so rewards stay correct. We keep a copy of each notification only while processing it, with a limited set of order fields, and delete it as described in section 9.
What stays inside Shopify
Regional prices and payment rules are applied at checkout by Shopify Functions that run on Shopify's own servers. They read the cart, including the delivery PIN code, and do not send any data to us. Storefront content blocks are stored as metaobjects in the merchant's own Shopify store.
5. Data we collect on our website
- Waitlist and enquiries: if you join our waitlist or contact us, your email address and anything you choose to tell us (such as your store domain, what you want to use Lokally for, or your question).
- Website analytics: getlokally.com (not the App or merchants' storefronts) uses Google Analytics to measure visits and Microsoft Clarity to understand how pages are used, including recordings of clicks and scrolling. These services use cookies and collect information about your device, browser and approximate location. See section 10.
6. How and why we use personal data
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Provide the App: apply your rules, issue rewards, send reward emails you turned on, show your analytics | Performance of our contract with the merchant; for shopper data, the merchant's instructions |
| Bill you through Shopify and manage your plan | Performance of contract |
| Answer support requests and feedback | Performance of contract; legitimate interests in helping users |
| Keep the App secure, prevent abuse (for example rate limiting) and fix errors | Legitimate interests in a secure, working service |
| Understand how the App and website are used, to improve them | Legitimate interests; consent where the law requires it for cookies |
| Answer Shopify's privacy requests and meet legal obligations | Legal obligation |
We do not sell personal data, share it for cross-context behavioural advertising, or use shopper data for our own purposes. We do not use personal data to make decisions that have legal or similarly significant effects on anyone.
8. Where data is stored and international transfers
The App's data is stored on Fly.io servers in Singapore. Some providers above process data in other countries, including the United States and the European Union. Where the law requires it, for example for data from the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses offered by those providers.
9. How long we keep data
| Data | Kept for |
|---|---|
| Your settings, rules, reward log and change history | While the App is installed |
| Region analytics events | 90 days, then deleted automatically |
| Copies of Shopify order notifications | 7 days after processing (30 days if processing failed) |
| Rate-limiting records | About one minute |
| Support conversations | Up to 2 years |
| Waitlist entries | Until you ask us to remove them or we no longer need them |
When a merchant uninstalls
When you uninstall, we immediately delete the App's access tokens and remove the automatic discounts the App created in your store (reward codes already sent to customers stay valid in your store). Shopify then sends us a request to erase your store's data 48 hours after uninstall, and we delete all remaining data about your store and its customers when we receive it.
Shopper erasure and access requests
When a merchant's customer asks the merchant to erase or see their data, Shopify tells us. We delete that customer's reward records and remove their email from our logs, and we send the merchant a report of the data we hold for a customer, within 30 days.
10. Cookies and browser storage
On merchants' storefronts
The App's storefront code stores the shopper's chosen region and PIN code, so they don't have to enter it again, and caches the store's settings so pages load quickly. It uses:
- a first-party cookie,
pce_region, kept for 30 days; - browser storage entries starting with
pce_orpce-(for examplepce_region,pce_pincodeand cached settings and content), and short-lived session entries such as whether the popup was dismissed.
These are functional only. They are not used for advertising or to track shoppers across sites. Merchants should list them in their store's cookie or privacy notice.
In the App admin
The App admin loads Shopify App Bridge, PostHog (usage analytics) and Crisp (support chat), which may use cookies or browser storage to work.
On getlokally.com
Google Analytics and Microsoft Clarity use cookies to measure visits and page usage. You can block or delete cookies in your browser settings, or use Google's opt-out add-on.
11. Security
- All connections to the App, Shopify and our providers use HTTPS (TLS).
- Our database and its backups are encrypted at rest by our hosting provider.
- Access tokens are kept in that database, are never shown in the App, and are used only to call Shopify for your store.
- Access to our systems is limited to the people who run the App.
- We keep our software dependencies updated and review security issues.
No system is completely secure. If we become aware of a breach affecting personal data we hold, we will tell affected merchants without undue delay and give them what they need to meet their own notification duties. Please report security issues to support@getlokally.com.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict how we use it, to withdraw consent, and to complain to a data protection authority. To use them, email support@getlokally.com. We will reply within 30 days, and may need to confirm your identity first.
India (Digital Personal Data Protection Act, 2023)
You can ask for a summary of your personal data and how it is used, ask us to correct, complete or erase it, nominate someone to act for you, and raise a grievance with our Grievance Officer (section 15). If you are not satisfied with our response, you may approach the Data Protection Board of India.
California (CCPA / CPRA)
We do not sell or share personal information, and we do not use sensitive personal information. You can ask to know, correct or delete the personal information we hold about you, and we will not treat you differently for doing so.
Shoppers
If you shopped at a store that uses Lokally, please contact that store: it controls your data. We help the store answer your request.
13. Children
The App and website are for businesses and are not directed to children. We do not knowingly collect personal data about children for our own purposes. If you believe we have, contact us and we will delete it.
14. Changes to this policy
We will update this policy when our practices change. The date at the top shows the latest version. For material changes we will tell merchants by email or in the App at least 14 days before they take effect.
15. Contact and grievances
For questions, requests or complaints about this policy or your data, email support@getlokally.com. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.
Grievance Officer: Privacy and Grievance Officer, Nocodelane, Kolkata, West Bengal, India. Email: support@getlokally.com.
Related: Privacy Policy · Terms of Service · Data Processing Addendum