CheckoutProof — Privacy Policy
Last updated: October 3, 2026
CheckoutProof ("the app", "we") is operated by Wigley Studios LLC. It helps Shopify merchants find legacy checkout customizations that stopped running when Shopify shut off its legacy checkout surfaces (August 26, 2026 for non-Plus stores), and plan their replacements. This policy explains what we access, why, and how we handle it.
What we access
- ScriptTag metadata (read) — the source URL, display scope, and creation date of script tags visible to the app (scope: read_script_tags). Shopify's ScriptTag API is app-scoped — we can only list tags the app itself can see, and the report says so.
- Checkout profile status (read) — your checkout profiles' names, published state, and whether the new Thank-you/Order-status pages are active (scope: read_checkout_branding_settings). Store-level design configuration only.
- Shop name, plan tier (Plus or not) and storefront URL — to tailor the report to your plan and to run the storefront check below.
- Your public storefront HTML — we fetch your store's public home page (exactly what any visitor's browser loads) to inventory the scripts rendered into it, because legacy scripts injected by other apps are only visible there.
What we do NOT access
We do not request or access orders, customers, or any personal / Protected Customer Data. CheckoutProof is a zero-PCD app by design.
What we store
- Scan results — your readiness score, findings, and suggested migration fixes, stored against your shop domain for history and trends. This is your own store configuration data, not customer data.
- Your checklist — the manual checklist items you tick off.
- Session/authentication tokens — to keep the app connected to your store.
- A copy of your subscription status from Shopify: plan, status, price, currency, billing interval, Shopify's subscription ID, start and renewal dates, and whether you have used the free trial.
- When you first and last opened the app, and how many times you have opened it.
How we process it
The gathered metadata is analysed by our engine, which runs on the same server as the app. On the Pro plan, each scan, including the weekly scheduled scan, also sends OpenAI up to 40 third-party script host names that our rules did not recognise (for example, a tracking provider's domain), so they can be classified. Nothing else is sent, and on the free plan nothing is sent to OpenAI. We do not send customer data, and we do not sell, rent or share your data for advertising.
Emails we send you
We use the email address on your Shopify account (or your store's contact email if there is none) to email you about the app: a welcome email when you first open it, another when a paid plan starts, and a monitoring alert, and a notice when we can't read your storefront. These emails are sent from noreply@wigleystudios.com through our email provider, Hostinger. We keep a record of the address each welcome email was sent to.
Data retention & deletion
- The app and its data are stored on a server we rent from Hostinger.
- When you uninstall, we delete your Shopify access tokens straight away and mark your subscription record as cancelled. The rest of your data stays until Shopify sends us its shop deletion request (
shop/redact), normally about 48 hours after you uninstall, and we then delete the data stored for your shop. - When you uninstall we also save a short summary of how the app was used, such as when you first and last used it, how many checks you ran, your first and last score, and your plan. When the deletion request arrives we remove your shop's domain from this summary and keep the rest to understand why stores leave.
- We also honor the
customers/data_requestandcustomers/redactwebhooks; because we store no customer personal data, these are acknowledged with nothing to return or erase. - You can ask us to delete your data at any time: support@wigleystudios.com.
Important limitation
CheckoutProof flags readiness risk against Shopify's published deprecation schedule and suggests the platform-approved replacements. Because the ScriptTag API is app-scoped and some surfaces (like the order-status "Additional scripts" box) have no API at all, no app can see everything — that's why the report includes a guided manual checklist. We do not certify that a migration is complete; the proof is your post-migration test order. The app is a migration-planning tool, not a guarantee.
Your rights
You can uninstall the app at any time to stop data collection and start deletion. For any data request, contact us.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.
Contact
Wigley Studios LLC, 8735 Dunwoody Place #12345, Atlanta, GA 30350, USA — support@wigleystudios.com