# Data and Privacy

> Source: https://primemoq.app/help/settings/data-privacy
> Collection: Settings
> Updated: 2026-08-26

What Prime MOQ stores and where it stores it, in plain terms, with links to the Privacy Policy and Terms of Service for your compliance records.

**Short answer.** Settings > Data and privacy states in plain language what Prime MOQ holds. No customer personally identifiable information is stored, your rules live in your own shop's Shopify metafields rather than a separate database, analytics are aggregate counts rather than individual records, and Shopify's mandatory GDPR webhooks are implemented. The section links to the Privacy Policy and the Terms of Service.

## Key takeaways

- No customer personally identifiable information is stored by the app.
- Rules live in your shop's own Shopify metafields, which is also how the checkout Function reads them.
- Analytics are aggregate counts, not per-shopper records.
- Shopify's mandatory GDPR webhooks are implemented.

## What is stored, and where

| Claim | What it means in practice |
| --- | --- |
| No customer PII | Nothing that identifies an individual shopper is kept by the app |
| Rules live in your metafields | Your rule set is stored in your own shop's Shopify metafields |
| Analytics are aggregate | Counts and totals, not a record per shopper |
| GDPR webhooks implemented | Shopify's mandatory data-request and erasure webhooks are handled |

The metafield point is the one worth understanding, because it explains most of
the others. Your rules are not held in a database Prime MOQ controls and you
cannot see. They live in your shop, which is also how the checkout Function reads
them fast enough to run on every cart. That is why
[Safe uninstall](https://primemoq.app/help/plans-billing-account/safe-uninstall) can hand you a
complete export, and why enforcement does not depend on a call out to us at
checkout time.

Analytics follow from the same shape. What a
[blocked attempts report](https://primemoq.app/help/checkout-and-enforcement/blocked-attempts-and-analytics)
counts is how many carts a rule stopped and what they were worth in total, not
who was pushing them.

## The links

The section links to two documents, both opening in a new tab:

- Privacy Policy

- Terms of Service

Those are the citable versions. If you keep a register of the apps installed on
your store and what each one processes, they are the pages to reference rather
than this article.

## Common mistakes

- Assuming an uninstall wipes your rules. They are in your shop's metafields.
Export before uninstalling anyway, described in
Safe uninstall, because a
reinstall on a cleared store is much faster from a backup file.

- Expecting per-shopper reporting. Aggregate counts are a deliberate limit,
not a missing feature. There is no per-customer blocked-attempt log to open.

## FAQ

### Does Prime MOQ store customer personal data?

No customer personally identifiable information is stored. The analytics shown in the app are aggregate counts rather than individual records, so there is no shopper-level history held anywhere in it.

### Where does my rule data actually live?

In your own shop's Shopify metafields. That is also how the checkout enforcement Function reads your rules, rather than from a separate database outside your store.

### Are GDPR data-request webhooks supported?

Yes. Shopify's mandatory GDPR webhooks are implemented, which covers the customer data request, customer redact and shop redact topics Shopify requires of every app.

### What happens to my data if I uninstall?

Your rules are metafields on your own shop, so removing the app does not hand them to anyone. Export a backup first anyway so a later reinstall is a restore rather than a rebuild.

**Best for:** Merchants who need a written account of what an installed app handles for their own privacy documentation.

**Applies to:** All plans
