Privacy Policy
GateKeeper age verification app · Last updated July 18, 2026
This Privacy Policy explains how the GateKeeper app (“GateKeeper”, “we”, “us”) collects, uses, and protects information when a Shopify merchant (“Merchant”) installs and uses GateKeeper, and when a visitor interacts with the age gate on a Merchant’s storefront. GateKeeper is a Shopify app that helps Merchants add age verification to their store.
1. Information we collect
From Merchants (store owners)
- Store details — your
.myshopify.comdomain, store locale and country, and installation date. - App configuration — the age-gate settings you choose (minimum age, verification mode, targeting rules, country rules, theming, and copy).
- Authentication tokens — the access token Shopify issues so GateKeeper can operate on your store. This is stored securely and never shared or displayed.
From storefront visitors
- Age-gate interaction — when a visitor confirms their age, GateKeeper stores a cookie in the visitor’s own browser to remember that they passed, so they are not asked again for a configurable period. This cookie stays on the visitor’s device.
- Verification records — for auditing, GateKeeper may record that a verification event occurred: a timestamp, the result (pass/fail/exit), the surface (storefront or checkout), the visitor’s country, and, if applicable, an associated order ID. We do not collect or store a visitor’s name, email, phone, address, date of birth, or any government ID. The age check happens in the visitor’s browser; only the outcome is recorded.
2. How we use information
- To provide and operate the age-verification service you configured.
- To remember a visitor’s verification so the experience isn’t repetitive.
- To give Merchants an audit log and analytics about verification activity (in aggregate, without personal identifiers).
- To comply with legal obligations, including age-restriction laws.
3. Legal bases (GDPR)
Where the EU/UK GDPR applies, we process data on the basis of (a) legitimate interests in operating the service and preventing under-age access, (b) legal obligation where age verification is required by law, and (c) contract to deliver the app to the Merchant.
4. Sharing and sub-processors
We do not sell personal data. GateKeeper runs on infrastructure operated by our hosting provider and integrates with Shopify, which provides the app platform and store data. We do not send storefront visitor data to third-party advertising or analytics networks.
5. Data retention
- Merchant configuration is kept while the app is installed and deleted when you uninstall GateKeeper.
- Verification records are retained only as long as needed for auditing and are removed on request or on app uninstall.
- The verification cookie expires automatically after the period the Merchant configures.
6. Data deletion and your rights
GateKeeper honors Shopify’s mandatory privacy webhooks. When a Merchant uninstalls the app, or when Shopify sends a data-erasure request (customers/redact, shop/redact) or a data-access request (customers/data_request), we respond by deleting or providing the relevant data. Depending on your location, you may have rights to access, correct, or delete personal data, or to object to processing. Contact us using the details below to exercise them.
7. Security
Access tokens and Merchant data are stored in a secured database. Traffic to and from the app is encrypted in transit (HTTPS). We follow the principle of data minimization — the age gate is designed so that no sensitive personal identifiers are collected from storefront visitors.
8. International transfers
Data may be processed in countries other than where the visitor or Merchant is located. Where required, we rely on appropriate safeguards for such transfers.
9. Children
GateKeeper is a tool that helps Merchants restrict access to age-gated content. It is not directed at children and does not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.
11. Contact
Questions or requests about this policy or your data? Contact us at mznbnsd@gmail.com.