EZDrop Privacy Policy

Last updated: April 30, 2026

This Privacy Policy applies solely to the EZDrop Shopify app, published by Extensions Market. It discloses what data EZDrop collects from merchants and waitlist participants (shoppers), how that data is used, with whom it is shared, and how it is stored and retained. By installing or using EZDrop, you (the merchant) agree to this policy on your own behalf and on behalf of your store's customers who join waitlists through EZDrop.

1. Data EZDrop collects

Merchant data (collected on install)

Merchant settings (stored per shop)

Drop data (created by the merchant)

Waitlist entry data (collected from shoppers)

When a shopper signs up for a drop on a public waitlist page, EZDrop collects:

Pre-drop interest data (collected from shoppers)

If the "Notify me" popup appears on a product page before a drop exists, EZDrop collects:

2. How this data is used

Merchant data

Shopper data

Shopper data is never used for advertising, profiling, or shared with any party beyond what is required to operate EZDrop.

3. Third parties your data is shared with

Third PartyData SharedPurposeTheir Privacy Policy
Shopify Shop domain, OAuth access token EZDrop is built on the Shopify platform. All app installation, OAuth, and Admin API interactions go through Shopify's infrastructure. shopify.com/legal/privacy
Resend Shopper email address, first name, drop title, referral URL, merchant from-name/from-address Transactional email delivery โ€” waitlist confirmation, launch emails, and pre-drop interest notifications. Resend processes the email content to deliver it and stores delivery logs for a limited period per their policy. resend.com/legal/privacy-policy
Railway Shop domain, OAuth token, merchant settings, drop data, waitlist entries Cloud infrastructure hosting EZDrop's application server and PostgreSQL database. railway.app/legal/privacy

4. Data storage and retention

5. Shopify API access and permissions

EZDrop requests the following Shopify API access scopes during installation:

EZDrop does not request access to customer order history, payment information, or any other merchant data beyond the above.

6. Shopper rights

Shoppers whose email addresses are collected by EZDrop may:

7. Merchant responsibilities

By using EZDrop, merchants are responsible for:

8. Data security

All communication between EZDrop and Shopify's API uses HTTPS/TLS encryption. OAuth access tokens are stored in our Railway-hosted PostgreSQL database with access restricted to the application server. We do not log OAuth tokens or email addresses in application logs.

9. Changes to this policy

We may update this policy as EZDrop evolves. The "Last updated" date at the top reflects the most recent revision. Continued use of EZDrop after changes constitutes acceptance of the updated policy.

10. Contact

[email protected]