EZDrop Privacy Policy
Last updated: April 30, 2026
This Privacy Policy applies solely to the EZDrop Shopify app, published by Extensions Market. It discloses what data EZDrop collects from merchants and waitlist participants (shoppers), how that data is used, with whom it is shared, and how it is stored and retained. By installing or using EZDrop, you (the merchant) agree to this policy on your own behalf and on behalf of your store's customers who join waitlists through EZDrop.
1. Data EZDrop collects
Merchant data (collected on install)
- Shop domain โ your
myshopify.com domain. Used to identify the merchant account and authenticate Shopify Admin API calls.
- OAuth access token โ a Shopify-issued token provided during OAuth installation. Used to authenticate API requests. Stored securely in our database.
Merchant settings (stored per shop)
- Email from-name โ the sender name shown on waitlist confirmation and launch emails.
- Email from-address โ an optional custom sender email address (Pro plan). If not set, emails are sent from
[email protected].
- Badge visibility toggle โ whether the storefront FOMO badge popup is enabled.
Drop data (created by the merchant)
- Drop title, description, linked product handle and GID, slot count, status, scheduled release date โ all entered by the merchant in the EZDrop admin. Stored in our database and associated with the merchant's shop domain.
Waitlist entry data (collected from shoppers)
When a shopper signs up for a drop on a public waitlist page, EZDrop collects:
- Email address โ required to send confirmation and launch emails.
- First name โ optional, used to personalise confirmation and launch emails.
- Referral code โ a unique code assigned to each entry, used to track referrals and compute queue position.
- Referred-by code โ the referral code of the person who shared the signup link, if any.
- Queue score and position โ computed from signup time and referral count. Updated in real time as new signups occur.
- Email sent timestamp โ records when a launch email was sent to this entry.
- Signup timestamp โ date and time the entry was created.
Pre-drop interest data (collected from shoppers)
If the "Notify me" popup appears on a product page before a drop exists, EZDrop collects:
- Email address โ stored to send a notification email when the merchant creates a drop for that product.
- Shop domain and product handle โ used to match the interest record to the correct drop when it goes live.
2. How this data is used
Merchant data
- To authenticate Shopify API requests and render the EZDrop admin panel.
- To personalise transactional emails sent to shoppers on the merchant's behalf.
Shopper data
- To assign a unique referral link and compute queue position.
- To send a waitlist confirmation email immediately after signup.
- To send a launch notification email when the merchant activates a drop.
- To send a pre-drop interest notification when a drop goes live for a product the shopper expressed interest in.
Shopper data is never used for advertising, profiling, or shared with any party beyond what is required to operate EZDrop.
3. Third parties your data is shared with
| Third Party | Data Shared | Purpose | Their Privacy Policy |
| Shopify |
Shop domain, OAuth access token |
EZDrop is built on the Shopify platform. All app installation, OAuth, and Admin API interactions go through Shopify's infrastructure. |
shopify.com/legal/privacy |
| Resend |
Shopper email address, first name, drop title, referral URL, merchant from-name/from-address |
Transactional email delivery โ waitlist confirmation, launch emails, and pre-drop interest notifications. Resend processes the email content to deliver it and stores delivery logs for a limited period per their policy. |
resend.com/legal/privacy-policy |
| Railway |
Shop domain, OAuth token, merchant settings, drop data, waitlist entries |
Cloud infrastructure hosting EZDrop's application server and PostgreSQL database. |
railway.app/legal/privacy |
4. Data storage and retention
- Merchant data and drop data โ stored in a private PostgreSQL database on Railway for as long as the app is installed.
- Waitlist entries and pre-drop interest records โ stored in the same database, linked to the merchant's drops. Retained until the merchant deletes the drop or uninstalls the app.
- On app uninstallation โ when a merchant uninstalls EZDrop, Shopify sends an
app/uninstalled webhook. All merchant data, drops, waitlist entries, and interest records for that shop are permanently deleted within 48 hours.
- GDPR shopper data requests โ if Shopify sends a
customers/data_request webhook for a specific shopper, we will provide that data to the merchant within 30 days. If Shopify sends a customers/redact webhook, we delete all waitlist entries and interest records matching that shopper's email within 48 hours.
5. Shopify API access and permissions
EZDrop requests the following Shopify API access scopes during installation:
- read_products โ to resolve product handles and display product information on waitlist pages.
EZDrop does not request access to customer order history, payment information, or any other merchant data beyond the above.
6. Shopper rights
Shoppers whose email addresses are collected by EZDrop may:
- Request access โ contact the merchant whose waitlist they joined, or email us at [email protected] to request a copy of their data.
- Request deletion โ contact the merchant or email us. We will delete the relevant waitlist entry / interest record within 7 days of a verified request.
- Unsubscribe โ each email sent by EZDrop includes a note referencing the merchant. Shopper consent is collected by the merchant on the waitlist signup page. Merchants are responsible for maintaining appropriate consent records for their jurisdiction.
7. Merchant responsibilities
By using EZDrop, merchants are responsible for:
- Obtaining appropriate consent from shoppers before collecting their email addresses via EZDrop waitlist pages.
- Maintaining a privacy policy on their Shopify store that discloses the use of EZDrop and transactional email communications.
- Complying with applicable data protection laws (GDPR, CCPA, CAN-SPAM, CASL, etc.) in their jurisdiction when using EZDrop to contact shoppers.
8. Data security
All communication between EZDrop and Shopify's API uses HTTPS/TLS encryption. OAuth access tokens are stored in our Railway-hosted PostgreSQL database with access restricted to the application server. We do not log OAuth tokens or email addresses in application logs.
9. Changes to this policy
We may update this policy as EZDrop evolves. The "Last updated" date at the top reflects the most recent revision. Continued use of EZDrop after changes constitutes acceptance of the updated policy.
10. Contact
[email protected]