Privacy Policy – Who Pays How: Hide at Checkout
Effective date: 28 September 2026
This Privacy Policy explains what information the Shopify app Who Pays How: Hide at Checkout (the "App") handles, why, and what choices you have. It applies to merchants who install the App and to their staff who use it.
1. Who we are
The App is developed and operated by Netherfield Bond Ltd, trading as The Netherfield, a private limited company registered in Scotland (company number SC788058), with its registered office at Coachmans Cottage, Netherfield House, Glassford, Strathaven, ML10 6TB, Scotland ("we", "us", "our"). For the personal data described in this policy, we act as the data controller.
Contact: info@thenetherfield.com
2. What the App does
The App lets a merchant show different payment methods at checkout to different groups of customers, such as company (B2B) customers, customers with certain tags, and everyone else, with optional changes for individual markets.
3. What data we collect
We keep the data we collect to the minimum needed to run the App.
Data stored on our servers:
- Shop session data for each store that installs the App: the shop domain, the access token and refresh token issued by Shopify, the token expiry time, and the access scopes granted.
- No staff user data: the App uses only shop-level (offline) sessions, so it does not store the names or email addresses of staff who open it.
Data we do not store: the App does not store any personal data about your customers (buyers) on our servers.
Access scopes: the App asks Shopify only for read_payment_customizations and write_payment_customizations, which it needs to create and manage the payment rule on your store; read_markets, which it needs to let you choose markets in a rule; and read_customers, which it uses only to show the list of tags your customers have, so you can choose which tags put customers into a group. The App does not read or store your customers' names, contact details, addresses or orders, and it does not store the list of tags; only the tags you choose are saved, in your store (see section 4).
Request logs: our hosting provider keeps short-lived technical logs of requests to the App (such as time, URL and IP address) to help us find errors. These logs are deleted automatically after at most 7 days.
Firebase Hosting: requests to the App's address pass through Google Firebase Hosting, which forwards them to our servers and does not store the App's data. Google uses the IP addresses of these requests to detect abuse and keeps them for a few months, under the Firebase Data Processing and Security Terms.
4. Data kept in your own Shopify store
Your settings are saved in metafields on your own Shopify store, not on our servers. These settings include your customer groups (their names, the customer tags they use, and whether they include company customers), the payment method names you control, which group sees which method, and any changes for individual markets.
At checkout, your rules are applied by a Shopify Function, which runs on Shopify's own infrastructure. To decide which payment methods to show, the function checks, inside Shopify, whether the buyer has certain tags or is buying for a B2B company, the buyer's country, and the names of the available payment methods. None of this checkout data is sent to our servers.
5. How we use the data
We use shop session data only to:
- install the App on your store and authenticate requests between the App and Shopify;
- let you and your staff open and use the App in the Shopify admin;
- save your payment rules to your store and keep the App working;
- respond to the privacy requests and webhooks that Shopify requires.
Legal basis (UK GDPR / EU GDPR): we process this data because it is necessary to provide the App you installed (performance of a contract), and because we have a legitimate interest in running the App securely.
We do not sell data, use it for advertising, build profiles, or use analytics or tracking cookies.
6. Where the data is stored
Session data and request logs are stored with our hosting provider (currently Google Cloud) in data centres in Belgium. Firebase Hosting (see section 3) is a global Google service: it may handle a request in any Google location on its way to our servers in Belgium. We may change hosting providers in the future. If we do, we will choose providers that protect data to a comparable standard, update this policy, and use appropriate safeguards (such as standard contractual clauses) for any transfer outside the UK or EEA.
7. Retention and deletion
- When you uninstall the App, we delete the session data for your shop.
- Shop deletion request (
shop/redact): when Shopify sends this request, we delete all session data for that shop. - Customer data requests (
customers/data_request) and customer deletion requests (customers/redact): we handle these webhooks. Because the App stores no customer data, there is nothing to return or delete. - Your settings are saved in the App's own metafields on its payment customization in your store. You view and change them in the App. After you uninstall the App, Shopify may delete them, and we can't restore them because we keep no copy.
8. Sharing
We share data only with:
- Shopify, which provides the platform the App runs on; and
- our hosting provider (currently Google Cloud), which stores and processes session data and request logs for us, and passes requests to the App through Firebase Hosting.
We do not share data with any other third party, unless the law requires us to.
9. Your rights
If you are in the UK or EU, you have the right to access, correct, delete, restrict or object to the processing of your personal data, and the right to data portability. To use these rights, contact us at info@thenetherfield.com. You can also complain to a data protection authority. In the UK, this is the Information Commissioner's Office (ico.org.uk).
If you are a California resident, you have similar rights under the CCPA, including the right to know about and delete personal information. We do not sell or share personal information for cross-context behavioural advertising.
Buyers: if you shopped at a store that uses the App, please contact that merchant. The merchant controls your customer data, and the App does not store it.
10. Security
Data is sent over encrypted connections (HTTPS), and stored session data is encrypted at rest (AES-256) by our hosting provider. Only we can access the stored session data, and we limit what we store to what the App needs. The App does not set cookies; it signs you in with session tokens issued by Shopify. No system is completely secure, but we take reasonable steps to protect the data we hold.
11. Children
The App is a business tool for Shopify merchants and is not meant for children. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. The effective date at the top shows when it last changed. If we make significant changes, we will tell merchants through the App listing or by email.
13. Contact
Netherfield Bond Ltd (The Netherfield) Coachmans Cottage, Netherfield House, Glassford, Strathaven, ML10 6TB, Scotland Email: info@thenetherfield.com