Privacy policy
Effective September 1, 2026
Milanus Tag and Cart helps Shopify merchants manage customer-tag pricing, product badges, and mobile-validated saved carts. The merchant that installs the app controls how its customer data is used; the app processes that data only to provide the installed features.
Data processed
The app processes shop identity and authorized administrator session data; Shopify customer IDs and managed pricing tags; product, variant, SKU, and pricing data; and order identifiers needed to mark a saved cart as converted. Customer email addresses and phone numbers can appear in a merchant-requested CSV export but are not retained by that export operation.
For a guest subject to the cart rule, the app stores an encrypted mobile number, a keyed one-way hash, the last four digits, the Twilio Lookup line-type result, the minimum cart-line data needed to restore the cart, and the customer's optional SMS-recovery consent record. Twilio Lookup confirms validity and mobile line type but does not prove that the guest owns the number, and no text message is sent during validation. Recovery marketing consent remains optional.
Purposes and sharing
Data is used to apply and verify customer pricing, run merchant-requested imports and exports, display badges, verify mobile numbers, save carts, send a single merchant-initiated recovery message where consent exists, prevent abuse, and meet legal obligations. Data is shared only with Shopify, the app's infrastructure provider, and Twilio as needed to deliver those functions. It is not sold.
Retention and deletion
CSV previews expire after 24 hours. Verification-attempt records are removed after 24 hours. Encrypted guest-cart retention is merchant-configurable from 1 to 365 days and defaults to 90 days. Uninstall and Shopify privacy webhooks delete the applicable shop or customer records. Database backups may persist briefly under the infrastructure provider's secured backup schedule.
Security and choices
Secrets are kept outside source code, mobile numbers are encrypted at rest, public requests are signed or authenticated through Shopify, and checkout rules are independently enforced by Shopify Functions. Customers may decline recovery SMS consent and can reply STOP to messages. Privacy access or deletion requests should be sent to the merchant first so the merchant can identify the relevant Shopify customer or cart.
Contact
Questions can be sent to sales@milanus.com, by telephone at +1 305-545-9778, or through Milanus contact support.