Bounct privacy policy
Last updated: September 21, 2026
This policy describes how AOV Boosters (“we”, “us”) collects and uses personal data when you install or use Bounct, a Shopify app. It is written to meet Shopify App Store privacy requirements. It is not legal advice.
Who we are
Bounct is developed and operated by AOV Boosters, 24, Aam Chattor, Rajshahi, Bangladesh. We provide bot detection, checkout blocking, advertising pixel protection, analytics, and optional Klaviyo list cleanup to Shopify merchants.
For privacy questions, data requests, or complaints, email mstsuraya620@gmail.com.
What we collect through Shopify’s APIs
After a merchant installs Bounct, we access Shopify Admin APIs only as needed to run the app. Depending on granted scopes, that can include:
- Shop identity (shop domain, and staff name, email, phone, or address when Shopify provides them on the authenticated session).
- OAuth access tokens required to call Shopify APIs on the merchant’s behalf.
- Order data used to record checkout outcomes, read cart tokens / note attributes, and optionally tag orders that match a bot session.
- Customer contact fields (name, email, phone, physical address) when a blocked checkout or cleanup workflow needs them.
- Storefront and checkout configuration needed to run the theme app embed, web pixel, and checkout Function (including cart transforms and pixel settings).
- Product or collection writes only when required for app configuration on the shop.
We do not use Shopify API data to sell ads, build unrelated marketing audiences, or train unrelated products.
What we collect from merchants
- Shop domain entered on this website to start OAuth install or login.
- App settings the merchant saves (protection thresholds, blocking mode, Klaviyo API key, suppression preferences).
- Billing plan status from Shopify Billing (trial, Starter, or Pro).
- Operational logs generated by use of the app (install, uninstall, webhook processing, support debugging).
We do not require a separate merchant account. Authentication is through Shopify.
What we collect from merchants’ customers
Bounct runs on the merchant’s storefront and checkout to decide whether a session looks human. Directly from the visitor’s browser and request, we may collect:
- IP address and approximate network / ASN signals.
- User agent, browser, operating system, language, and device characteristics.
- Behavioural fingerprint signals such as WebGL renderer, canvas hash, mouse entropy, time to first interaction, screen vs window size, and similar anti-automation checks.
- Page path, page origin, and traffic source derived from the referring URL.
- Cart identifier and a signed human-verification token stored as a cart attribute.
- If a visitor is blocked and submits a recovery form: name, email, phone, and an optional message, plus a snapshot of cart contents the merchant needs for support.
- Checkout event types (for example checkout started, blocked, completed, or pixel suppressed) for the merchant’s analytics dashboard.
We collect this data to provide fraud prevention and marketing-signal protection requested by the merchant — not to profile shoppers for advertising of our own.
Cookies, tokens, and storage
Bounct uses the following storage on the storefront:
- Session storage: last risk verdict and score, app URL, shop domain, and whether pixel events were suppressed. These values stay in the visitor’s browser tab and are used so the web pixel can suppress bot-generated events.
- Cart attributes:
hv_token(HMAC-signed human-verification token, 15-minute TTL) and a session identifier used to join checkout events. - Merchant test flags: optional
localStorageor cookie flags such asbounct_test_modeused only when a merchant is testing detection. - hCaptcha: when a visitor completes human verification, hCaptcha may set its own cookies according to Intuition Machines’ policy.
This marketing site does not set advertising cookies. Shopify may set cookies required for OAuth login when a merchant installs the app.
How we use the information
- Score sessions and return a human, uncertain, or bot verdict.
- Issue and validate human-verification tokens for checkout.
- Suppress Meta and Google pixel events for bot and uncertain sessions.
- Show merchants analytics, blocked-customer logs, and cleanup tools.
- Optionally suppress or delete matching profiles in the merchant’s own Klaviyo account, when the merchant connects an API key and asks us to.
- Authenticate the merchant, bill through Shopify, and provide support.
- Comply with law and Shopify’s mandatory privacy webhooks.
We do not sell personal data, and we do not use storefront behavioural data to retarget shoppers for Bounct’s own marketing.
Sharing and processors
We share data only with:
- Shopify: to authenticate, bill, run Functions, pixels, and webhooks, and to operate inside Shopify Admin.
- hCaptcha (Intuition Machines): to verify that a checkout visitor is human. A CAPTCHA token is sent to hCaptcha for validation.
- Klaviyo: only if the merchant pastes their own Klaviyo API key and enables cleanup or auto-suppress. Data goes to that merchant’s Klaviyo account, not to a Bounct-owned marketing list.
- Infrastructure providers: application hosting and database (currently Railway) process data to run the app.
- Professional advisors or authorities if required by law.
We do not sell or rent merchant or customer lists to data brokers.
How long we keep data
- Bot session logs, checkout events, and blocked-customer records are kept while the app is installed and as long as needed for security analysis, merchant reporting, and support.
- Shopify access tokens and shop settings are kept until the merchant uninstalls the app.
- On
app/uninstalledor Shopify’sshop/redactwebhook, we delete merchant sessions, bot events, checkout events, and blocked-customer records for that shop. - On
customers/redact, we delete blocked-customer and checkout-event rows for that shop that match the customer email. Session logs keyed only by cart ID and IP, with no email, may not be attributable to a specific customer and are removed with shop-level deletion.
International transfers
AOV Boosters is established in 24, Aam Chattor, Rajshahi, Bangladesh. The app is hosted on infrastructure that may process data outside the European Economic Area, the United Kingdom, or the visitor’s country — including the United States. Where required, we rely on appropriate transfer mechanisms used by our processors (for example standard contractual clauses) and Shopify’s own terms with the merchant.
Individual rights and Shopify compliance webhooks
Shopify requires public apps to honour the same privacy rights for personal data regardless of where a person lives. Bounct implements Shopify’s mandatory compliance webhooks:
customers/data_request— we locate data we store for the shop and provide it to the merchant so they can fulfil a customer access request.customers/redact— we delete customer personal data we can identify (email-matched blocked customers and checkout events).shop/redact— 48 hours after uninstall, Shopify asks us to delete all shop data; we do so.
Merchants and customers may also email mstsuraya620@gmail.com to access, correct, erase, or restrict processing. We respond within 30 days of a verified request, or sooner when Shopify’s webhook timeline is shorter.
If you are a shopper, the merchant is typically the controller of your storefront data. Contact the store you visited as well; we process storefront signals to provide the merchant’s requested fraud-prevention service.
Protected customer data
Bounct uses Shopify protected customer data, including name, email, phone, and address fields when a blocked checkout or list-cleanup feature needs them, plus device and activity data (IP address, geolocation inferred from IP, browser and OS, browsing behaviour). We:
- Collect only what the feature needs.
- Use it only for the purposes in this policy.
- Do not sell that data.
- Respect applicable marketing consent and opt-out instructions the merchant configures in Shopify or Klaviyo. Pixel suppression is a protective control; it does not replace the merchant’s cookie or marketing-consent banner.
Security
Access tokens and secrets are stored in our database and environment configuration, not in client-side source. Human-verification tokens are HMAC-signed with a server secret and expire. Webhook requests are verified using Shopify’s HMAC header before we process them. Data in transit uses HTTPS.
Children
Bounct is a merchant tool. We do not knowingly collect personal data from children under 16 for our own purposes. Storefront collection follows whatever audience the merchant’s shop serves.
Changes
We will update this page when our practices change and revise the “Last updated” date. Material changes will be reflected here before they take effect for new processing.
Contact
AOV Boosters
24, Aam Chattor, Rajshahi, Bangladesh
Email: mstsuraya620@gmail.com
You can also reach us through the Bounct Shopify App Store listing.