Last updated: 10 September 2026
flashpin is a Shopify app that runs pincode-based flash discounts and a referral coin wallet for online stores. This policy explains what we collect, why, and what you can do about it.
It covers two different groups: the merchants who install flashpin on their Shopify store, and the shoppers who buy from those stores. We hold very little about shoppers, and the detail below says exactly what.
flashpin is operated by MicroKorant, Bengaluru, Karnataka, India. For anything in this policy, write to admin@microkorant.in.
| Data | Why |
|---|---|
Store domain (yourstore.myshopify.com) | Identifies your account |
| Shopify access token | Lets the app read orders and write discounts. Encrypted at rest. |
| Business name, contact email, phone | Account setup and support |
| Campaign settings - pincodes, percentages, caps | Runs your campaigns |
| Subscription status and billing periods | Managing your plan |
We never receive or store card details. Payment is handled entirely by Shopify.
When someone buys from a store running flashpin, we record:
| Data | Why |
|---|---|
Shopify customer ID (a number, e.g. 7281…) | Attaches a coin balance to the right shopper |
| Order ID, order number, order value, discounts applied | Works out what was earned or spent |
| Delivery postal code (pincode) | Decides whether the order qualified for that day's flash deal |
| Referral code used, and who referred whom | Pays the right person |
| Coin balance and a running ledger of every change | So a balance can always be explained |
| A one-way fingerprint used to detect self-referral | Stops someone referring themselves for free coins |
A postal code plus a customer ID can, in combination, say something about where a person shops from. We treat that pairing as personal data and it is covered by every right described in section 7.
We use a small number of service providers. Each one only receives what it needs to do its job.
| Provider | Role |
|---|---|
| Shopify | Source of order and customer data; handles all payments |
| Supabase | Database where balances and ledgers are stored |
| Cloudflare | Runs the background services that process orders |
| Vercel | Hosts the merchant dashboard |
Data may be processed outside India, including in the EU and the United States, depending on where these providers run. We rely on their standard contractual protections for those transfers.
| What | How long |
|---|---|
| Raw order data received from Shopify (names, email addresses, phone numbers, delivery addresses) | Deleted 7 days after we process it. We only need it long enough to work out who earned which coins; after that we keep the amounts, not the person |
| The record that an order event happened (an id and a topic, no personal data) | 60 days, so a repeated delivery from Shopify is not counted twice |
| Coin ledger entries (amounts, dates, no contact details) | Kept while the store is active, so a balance can always be explained |
| Order records we build ourselves (totals, discounts, delivery pincode) | Kept while the store is active |
| A copy of a shopper's data assembled in response to an access request | 30 days, then deleted whether or not it was collected |
| Merchant account and access token | Deleted within 48 hours of uninstalling |
| Everything for an uninstalled store | Deleted when Shopify tells us the store is gone, which is 48 hours after uninstall |
A shopper deletion request from Shopify removes that person from every one of the above at once, including the raw order data, whether or not the 7 days have passed. Their coin amounts stay in the ledger with no name attached, because a store's outstanding coin liability is a financial record.
Depending on where you live, you may have the right to see what we hold about you, correct it, have it deleted, or object to how we use it. Indian users have these rights under the Digital Personal Data Protection Act; users in the EU and UK under the GDPR; users in California under the CCPA.
Ask the store you bought from. They can request your data or its deletion through Shopify, and Shopify passes that request to us automatically. We answer it within 7 days. You can also write to us directly and we will help you reach the right store.
Write to admin@microkorant.in. We will respond within 7 days.
When a deletion request arrives, we detach the identity and keep the amounts. The customer ID and referral code are replaced with anonymous markers, so nothing links back to a person, while the ledger still adds up. This matters because coin balances are a financial record for the merchant: deleting rows outright would leave other shoppers' balances unexplainable.
Inside the Shopify admin. The merchant dashboard uses only the session cookies Shopify requires to keep you signed in. No analytics or advertising script is loaded there at all.
The storefront widget. It stores a referral code in the visitor's browser so the right person is credited if they buy. Nothing else, and no advertising identifier.
Our public website (the flashpin marketing pages, this policy and the support page) uses Google Analytics to count visits and see which pages people read before installing. Google sets its own cookies to do that, and the data it collects is covered by Google's privacy policy. You can opt out with Google's browser add-on, or by blocking the script — nothing on the site depends on it. This is the only third-party script flashpin loads anywhere, it runs on public pages only, and it never sees a merchant's store data or a shopper's order.
flashpin is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.
If we change this policy we will update the date at the top, and tell merchants by email if the change is significant.
admin@microkorant.in
MicroKorant, Bengaluru, Karnataka, India