Privacy Policy

Last updated: February 21, 2026

SleekPass ("we", "our", "us") is operated by Itod Inc. SleekPass provides Apple Wallet and Google Wallet loyalty cards for Shopify merchants ("merchants"). This policy describes how we collect, use, store, and protect data when merchants install SleekPass and when their customers ("customers") receive loyalty passes.

What Data We Collect

From Shopify (via the merchant's store)

When a merchant installs SleekPass, we request the following Shopify access scopes:

For each customer who receives a loyalty pass, we read the following from Shopify:

This customer data is cached in our database as part of the pass record so that passes can be generated and updated without repeated Shopify API calls.

From Merchants

From Customers Directly

When a customer enrolls via a walk-in enrollment page (QR code at the store counter):

This information is used to find or create a Shopify customer record in the merchant's store and generate wallet passes.

From Devices

When a customer adds an Apple Wallet pass to their device, Apple's PassKit protocol provides:

These are stored solely to deliver pass updates (e.g., when order count changes) via Apple Push Notification Service.

Scan Events

When a merchant's staff scans a customer's QR code at point of sale, we record:

Scan events are used for merchant analytics and are not shared with third parties.

What We Do NOT Collect

How We Use Data

Data Storage and Security

Data Sharing

We share data with the following third parties solely to deliver the service:

We do not sell, rent, or share customer data with advertisers, data brokers, or any other third parties.

Data Retention and Deletion

When a Merchant Uninstalls SleekPass

  1. Immediately: Shopify API access tokens are deleted. The merchant's store is marked as uninstalled.
  2. After 30 days: if the merchant has not reinstalled, all shop data, passes, and scan events are permanently deleted. Google Wallet pass objects are expired.
  3. If the merchant reinstalls within 30 days: existing passes are preserved and the shop is reactivated.

Shopify GDPR Webhooks

We implement all three mandatory Shopify GDPR webhooks:

Customer-Initiated Deletion

Customers who wish to have their loyalty pass data deleted should contact the merchant directly. The merchant can delete the customer from Shopify, which triggers our deletion webhook. This invalidates all QR codes and permanently deletes all pass records for that customer.

Scan Event Retention

Scan events are retained for merchant analytics purposes. After a customer's passes are deleted or anonymized, scan events no longer contain any link to identifiable customer data.

Children's Privacy

SleekPass is a business tool for Shopify merchants. We do not knowingly collect personal information from children under 13. If you believe a child's information has been collected, please contact us.

Changes to This Policy

We may update this privacy policy from time to time. The "Last updated" date at the top of this page indicates when the policy was last revised. Continued use of SleekPass after changes constitutes acceptance of the updated policy.

Contact

For privacy-related questions or data requests: