Privacy policy
CaterCap Reservations is designed around data minimization. It stores the operational details needed to reserve catering capacity while customer identity, contact details, addresses, and payments remain in Shopify.
Information the app processes
When a merchant installs and uses the app, it processes:
- The merchant's Shopify store domain and installation credentials.
- Configuration such as products, variants, pricing model, service windows, lead times, fulfillment options, and capacity limits.
- Reservation details such as service date, service time, fulfillment choice, guest count, capacity status, and technical reservation tokens.
- Technical Shopify product, variant, inventory, and location identifiers needed to protect the selected capacity.
- Application logs required for reliability, security, and troubleshooting.
Customer data boundary
The app does not request or store customer names, email addresses, phone numbers, delivery addresses, billing addresses, or payment data. Those details are collected and retained by Shopify through its checkout.
Reservation properties attached to the cart and order can be viewed by the merchant in Shopify Admin as part of their normal order workflow.
How information is used
- To display valid catering dates, service times, and fulfillment choices.
- To calculate and hold guest and order capacity before checkout.
- To commit or release reservation capacity as an order progresses.
- To give the merchant an operational capacity and reservation view.
- To secure, maintain, and improve the service.
Service providers and disclosure
The app uses Shopify to provide the commerce platform, Vercel to host the application, and Supabase to provide the managed PostgreSQL database. Information is shared with these providers only as needed to operate the service.
Information may also be disclosed when required by law, to protect legal rights or system security, or as part of a business transfer subject to appropriate confidentiality protections. The app does not sell personal information.
Retention and deletion
Operational data is retained while the merchant uses the service and only as long as needed for the purposes described here. When Shopify sends a shop-redaction request after uninstall, the app deletes the shop's stored application data. Mandatory Shopify privacy webhooks are supported.
Security and international processing
The service uses encrypted HTTPS connections, authenticated Shopify requests, least-privilege access scopes, and restricted database access. Service providers may process data in countries other than the merchant's country.
Changes and questions
This policy may be updated when the service or applicable requirements change. The effective date above identifies the latest version. For privacy questions or data requests, email michalvesecky@gmail.com.