Privacy

Last updated 23 September 2026

Offer Suite is a Shopify app operated by Blackout Media, a company established in Brazil. It lets a brand build offers in its Shopify store, check that a real cart charges what each offer promises, and see the profit each offer earns. This page says what we collect, why, for how long, and where it is processed.

What we collect through Shopify's APIs

  • The store's products, variants, prices and selling plans, to build offers and check their carts.
  • The discounts, discount codes and web pixel that Offer Suite creates in the store.
  • Orders, when the store sends them to us: line items, quantities, prices, discounts, taxes, the shipping charged, refunds and edits, order tags, the cart attributes Offer Suite adds, and the order's source.

We never store a buyer's name, email, phone number, postal address, IP address, browser details or payment details. They are removed from every order before it is saved.

What we collect from merchants

  • The email addresses of the people a brand invites to its Offer Suite dashboard, to send sign-in links.
  • API keys, which we store only as hashes, and the store's Shopify access token, which we store encrypted with AES-256-GCM.
  • The offers the brand or its agents write, and the product costs the brand enters.

What we collect from merchants' customers

When a brand's page uses the Offer Suite script, or its checkout runs the Offer Suite web pixel, we receive:

  • A random visitor id that the script creates and keeps in the browser's local storage. It is not linked to a name, email or account.
  • Which offer was viewed, which option was selected, when it was added to the cart, when checkout started, and when the order was placed, with the cart id, order id and amount.

The web pixel follows the store's cookie consent: it runs only when the buyer allows analytics. A visitor's IP address is used for a moment to limit request rates and is not stored.

The waitlist form

When you join the waitlist on this site, the form sends your work email, your store's address, your monthly revenue band, your subscription app and your role to Blackout Media by email, so that we can invite you when Offer Suite opens to a store like yours. We do not keep the answers anywhere else: not in a database, not in our logs. We don't add you to a mailing list and we don't email you until we invite you. To have your answers deleted, email privacy@offersuite.io from the address you gave, and we delete the email.

The form uses Cloudflare Turnstile, which runs a check in your browser to tell people from bots before the form is sent.

How we use it

Only to provide Offer Suite to the brand: to build and check offers, to attribute each order to the offer that made it, and to report revenue, costs, profit and the steps from view to purchase. We do not sell data, share it with advertising networks, profile buyers, or make automated decisions about them.

How long we keep it

  • Order records are kept while the store is connected, because they are the brand's record of what its offers earned.
  • Browser events are deleted 13 months after they happen.
  • When a brand uninstalls Offer Suite, Shopify tells us 48 hours later, and we then delete that store's orders, offers, events and connection. We keep the brand's account, its members and the costs it entered, until the brand asks us to delete them.
  • When a buyer asks the store to erase their data, Shopify tells us which orders are theirs, and we remove every link between those orders and a visitor or a session. The order amounts stay, without anything that identifies the buyer.
  • A record of each privacy request and what we did about it is kept for as long as the brand's account exists.

Where it is processed

Requests are handled on Cloudflare's global network. Data is stored in the United States: the database in Neon Postgres and the event store in ClickHouse Cloud, both in Amazon Web Services' us-east-2 region (Ohio). Data is encrypted in transit and at rest.

Requests and questions

Buyers who want to see or erase their data should ask the store they bought from; Shopify passes the request to us, and we answer it within 30 days. Brands can see every request we received for their stores, and what we did, on the Privacy page of the Offer Suite dashboard or through the API. For anything else, email privacy@offersuite.io.