KOKO Privacy Policy
KOKO is a Shopify app made by First Pull Co. ("we", "us"). It adds quantity discounts, add-ons, a sticky mobile Add to Cart and a cart shipping-goal bar to a store, styled to match the store's theme. This policy explains what information KOKO uses when a merchant installs it, and why.
Information KOKO accesses
When a merchant installs KOKO, Shopify lets the app access the following store information, and only for the purposes described here:
- Products (titles, variants, prices and images), to show tier and add-on amounts and to let the merchant choose which products an offer covers.
- Discounts, to create and update the automatic discounts KOKO runs for the merchant.
- Themes, to check that KOKO's blocks are placed on the store's product page.
- The store's public product page, which KOKO opens in an automated browser when the merchant clicks "Match my theme", to read how the theme styles its text and to take a screenshot of the product details area.
Customer information
KOKO does not collect, read or store personal information about a store's customers, such as names, email addresses, phone numbers, addresses or order history. The "Check my store" feature builds temporary test carts through Shopify's storefront cart; these carts contain only products and are never ordered.
What KOKO stores
- Settings the merchant chooses (discount tiers, covered products, add-ons, the shipping goal) and style settings produced by "Match my theme" are stored inside the merchant's own Shopify store, in data that belongs to the KOKO app installation.
- If the merchant enters a storefront password (used only for password-protected stores so KOKO can view the product page), it is stored in the same place.
- KOKO's server does not keep a database of stores or customers. Access to the Shopify API is granted per request through short-lived tokens that expire within 60 minutes and are not saved.
- Our hosting provider keeps routine server logs (such as the store's myshopify.com address and request errors) for troubleshooting, for a limited period.
Service providers
- Shopify hosts the store, the app's storefront blocks and the stored settings.
- Vercel hosts KOKO's server.
- Anthropic provides the AI model used by "Match my theme". KOKO sends it a screenshot of the store's public product details area and the text styles measured on that page. No customer information is included.
We do not sell store or customer information, and we do not use it for advertising.
Uninstalling and deletion
When a merchant uninstalls KOKO, Shopify removes the app's blocks from the store's theme and deletes the data stored with the app installation, including KOKO's settings, style settings and any storefront password. KOKO responds to Shopify's data requests, including requests to delete store data, as described in Shopify's privacy requirements. Because KOKO does not store customer information, customer data requests have nothing further to delete.
Security
All connections to KOKO's server use HTTPS. Requests from the Shopify admin are verified with Shopify session tokens, and notifications from Shopify are verified with Shopify's signatures.
Changes
If we change how KOKO uses information, we will update this page and the date above.
Contact
First Pull Co.
1520 North Old Rand Rd, Wauconda, IL 60084, United States
Email: john@firstpull.com