KorAddress Privacy Policy
Effective August 30, 2026
In short: KorAddress requests no Shopify data access scopes at all. It cannot read your customers, orders, or products. The Korean address a shopper selects is held in that shopper's own browser and submitted straight to Shopify checkout — it is never sent to or stored on our servers.
1. What KorAddress does
KorAddress adds a Korean postcode search to the cart page of a Shopify store. A shopper searches for their address, selects it, and KorAddress passes the result into the Shopify checkout so they do not have to retype it. It is installed as a theme app extension and runs in the shopper's browser.
2. Information we collect from merchants
When a merchant installs KorAddress, we store the following on our servers:
- Store domain — the myshopify.com domain of the installing store.
- Shopify access token — issued by Shopify during installation and encrypted at rest with AES-256-GCM. It is used only to identify the store and to operate billing.
- App settings — your widget configuration: whether the widget is enabled, locale targeting, which fields are shown, button label, colour, and placement.
- Subscription status — the identifier and state of your Shopify app subscription, synced from Shopify's billing webhooks.
- Aggregate usage counts — a daily tally per store of four event types: widget opened, address confirmed, checkout prefill attempted, and manual entry used. These are counters only. They contain no address, name, phone number, order, or shopper identifier of any kind, and cannot be traced to an individual shopper.
- Authentication session records — created by Shopify's official app library. KorAddress uses offline access tokens only, so these records do not carry staff names or email addresses.
3. Information we do not collect
KorAddress requests no Shopify access scopes. It has no permission to read or write your customers, orders, products, inventory, or any other store data, and it makes no Shopify Admin API calls to retrieve them. We hold no shopper personal information on our servers at any time.
4. How shopper addresses are handled
The address a shopper selects is personal information, and it is handled entirely within their own browser:
- It is saved in that browser's sessionStorage and localStorage so the shopper does not lose it while moving between cart and checkout.
- It is passed to Shopify checkout as prefilled shipping fields. From that point Shopify — and the merchant, through their order — is the controller of that data, under Shopify's and the merchant's own privacy policies.
- It is erased from the browser once the order is placed.
- It is never transmitted to KorAddress servers and never written to our database.
5. Third-party services
The address search is powered by the Daum Postcode service, operated by Kakao Corp. When a shopper opens the search, their browser loads that service directly from Kakao's servers (t1.daumcdn.net) and sends it their search terms. That exchange is between the shopper's browser and Kakao; KorAddress does not intermediate, log, or retain it. Kakao's handling of that data is governed by Kakao's own privacy policy.
Our application servers are operated by us on cloud infrastructure. We do not sell, rent, or share merchant data with advertisers, data brokers, or any other third party.
6. Retention and deletion
We retain the merchant data in section 2 for as long as the app is installed. When you uninstall, Shopify notifies us and we mark the installation inactive and delete the authentication session.
We implement Shopify's mandatory compliance webhooks:
- customers/data_request and customers/redact — we confirm that we hold no shopper personal data, because we never collect any.
- shop/redact — sent by Shopify 48 hours after uninstall. We permanently delete the store record and everything attached to it, including settings and all usage counters.
A merchant may also request deletion at any time by contacting us.
7. Security
- All traffic is served over HTTPS with TLS.
- Shopify access tokens are encrypted at rest using AES-256-GCM.
- Requests from the storefront to our servers are verified against Shopify's app proxy signature before they are processed.
- We minimise risk by collecting no personal data in the first place.
8. Your rights
Depending on where you are located, you may have the right to access, correct, export, or delete the information we hold about your store, and to object to or restrict its processing. Contact us and we will respond within the period required by applicable law.
9. Changes to this policy
We may update this policy as the app changes. The effective date at the top of this page reflects the most recent revision. Material changes will be communicated to installed merchants.
10. Contact
Questions about this policy or about your data: devbiz654@gmail.com