M10 RuleSafe
Privacy Policy
Effective August 30, 2026. This policy explains how DaelVista LLC processes information for M10 RuleSafe.
Information M10 RuleSafe processes
To provide the service, M10 RuleSafe may store:
- The connected Shopify store domain, store identifier, installation status, and store currency.
- Shopify authentication and session information, granted scopes, credentials, and expiration information.
- Rule configuration, Product and Product Variant identifiers, thresholds, currency, and customer messages.
- Rule revisions, safety findings, simulator inputs and results, activation history, and runtime state.
- Minimal plan and subscription information needed to apply Free or Pro entitlements.
M10 RuleSafe uses Shopify API scopes read_products, read_validations, and write_validations for catalog-target verification and M10 validation configuration.
Checkout data processed transiently
When an active rule is evaluated, Shopify's validation runtime provides cart-line quantities, Product Variant and parent Product identifiers, subtotal amount and currency, and the active rule configuration. This processing is transient in Shopify's runtime. M10 RuleSafe does not retain complete customer carts as application records.
Information not required for core features
M10 RuleSafe does not require buyer names, buyer email addresses, postal addresses, payment details, or normal Shopify order records for core rule enforcement. Shopify may include customer fields in a mandatory privacy webhook; M10 authenticates and handles the request without creating a customer profile or application record.
M10 RuleSafe does not use advertising trackers and does not sell personal information or use service data for cross-context behavioral advertising.
How information is used
- Authenticate authorized merchants and maintain the Shopify connection.
- Verify catalog targets, save drafts and revisions, generate Safety Reports, and run simulations.
- Publish, disable, reconcile, and recover M10 RuleSafe validation configuration.
- Apply plan entitlements, synchronize Shopify subscription status, secure the service, and provide support.
Service providers and disclosures
Shopify provides installation, authentication, merchant administration, catalog APIs, checkout validation runtime, privacy webhooks, and subscription presentation and billing. Cloudflare provides application hosting, network delivery, operational logging, secrets storage, and the D1 database.
Information may also be disclosed when required by law, to protect the service or its users, or in connection with a lawful business transaction subject to appropriate protections.
Storage and security
Shop-scoped records are stored on M10-specific Cloudflare infrastructure. Credentials use provider secret-management controls. Operational records are designed to be minimal and can include request path, response status, timing, error type, webhook topic, and store domain. M10 is designed not to log access tokens, cookies, payment details, or complete carts. No security measure can eliminate every risk.
Retention and deletion
Service records are retained while needed to provide, secure, support, or recover M10 RuleSafe. Uninstall deletes stored Shopify sessions, disables M10 enforcement, and marks the installation inactive, but does not immediately erase every historical shop record.
After a verified shop/redact request, M10 deletes the shop record and its related rules, revisions, targets, findings, simulations, snapshots, activation events, runtime state, billing entitlement, and sessions. Short-lived logs, provider recovery data, and controlled backups remain only while reasonably needed for security, reliability, recovery, disputes, or legal obligations, then are deleted, overwritten, or anonymized.
Shopify privacy requests
M10 authenticates Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. Because M10 does not create customer identity profiles or retain normal customer/order records, customer-specific requests generally find no M10 customer record to return or delete.
Merchant choices and privacy requests
Merchants can deactivate enforcement and uninstall the app in Shopify Admin. Where applicable under law, contact M10 RuleSafe Support about access, correction, deletion, or another privacy question. Identify the connected store and do not send passwords, access tokens, payment details, or unnecessary customer information.
International processing
Shopify and Cloudflare may process information in jurisdictions other than the merchant's location. Applicable locations and protections depend on the provider, merchant, and service configuration.
Changes to this policy
Material changes will be posted with a revised effective date and, where required, additional notice.
Contact
M10 RuleSafe Support
Email: m10support@daelvista.com
Support: M10 RuleSafe Support