LS Blocklist & Guard
Privacy Policy
Effective September 24, 2026
Liza Solutions (“we”, “us”) operates LS Blocklist & Guard, a Shopify app that lets a merchant block unwanted checkouts before payment. This policy describes the data we process when a merchant installs the app.
Who this applies to
We deal with the merchant who installs the app. Shoppers do not create an account with us. Values the merchant types into Blocklist, Rules, or Allow list — including email, phone, name, and address — can be a shopper’s personal data. Country, city, ZIP, and order-total rules can also identify or relate to a shopper.
Shopify access
The app requests the read_orders scope so it can read order contact details and abandoned checkouts the merchant already has in Shopify. We do not request write_orders, read_customers, write_customers, or read_all_orders. We do not write orders or customers. We do not store complete order records. The Blocked attempts page reads abandoned checkouts live and does not save them. Orders older than 60 days are not available with this access.
What we store
On our PostgreSQL database we store:
- The shop domain and an encrypted Shopify session token used to call the Admin API.
- App settings: checkout protection on/off, default blocked message, match modes, watermark preference, and suggested high-risk countries.
- The shop’s plan (Free or Growth) mirrored from Shopify Billing.
- Merchant-entered list values and notes: emails, phones, names, countries, cities, ZIP codes, addresses, order-total ranges, and allow-list emails, domains, and phones.
To block checkout before payment, we write a compact copy of those lists and settings to a shop metafield. A Shopify Function reads that metafield during checkout. Shopify hosts the Function.
We do not collect card numbers, CVV, expiry dates, or bank details. Growth plan charges are created by Shopify Billing. We do not sell merchant or shopper data. We do not run a shared or community blocklist. We do not collect visitor IP, VPN, or device fingerprints from checkout.
Shopify privacy webhooks
customers/data_request. We do not keep a customer profile. There is no extra file for us to return. Any matching list values are already visible to the merchant in the app.
customers/redact. We do not store a customer record to erase. We do not automatically delete merchant-entered Blocklist, Rules, or Allow list values. Those values are the merchant’s checkout rules. The merchant can delete any value in the app at any time.
shop/redact and app/uninstalled. We delete all data for that shop: sessions, settings, subscription, block rules, conditions, and allow-list entries.
Contact
Questions about this policy: lizasolutions9@gmail.com. See also the Terms of Service.