Butter Commerce

Privacy Policy

Effective: 14 August 2026

Last updated: 14 August 2026

How to read this

Butter sits on both sides of a line, and the difference matters.

If you use Butter — you installed the Shopify app, you build in Framer with our components, you have an account — then we decide what to collect about you and why. We are the controller of that data, and we are accountable to you for it. Part A is about you.

If you shopped on a site built with Butter — you never signed up with us, you may never have heard of us — then any data we hold about you is held on behalf of the store you visited. That store decides what is collected; we act on their instructions. We are their processor. Part B is about you, and it explains who to contact.

Part C applies to everyone: security, retention, transfers, your rights, and how to complain.

This policy covers buttercommerce.co, the Butter Commerce Shopify app, the Butter Commerce Framer plugin, app.buttercommerce.co, and the Butter components that run on published Framer storefronts.

Who we are. Butter Supply Inc., a corporation incorporated in Ontario, Canada. Contact details are in Section 20.

We are the controller of the personal information described in this Part.

1. What we collect about you

You give us

Category

What it includes

Why we have it

Account

Name or display name, email address, password credentials, avatar, workspace and team membership

To create and secure your account and let you into the Product

Store connection

Your Shopify store domain, shop ID, storefront URL, primary domain, store name, and the access tokens Shopify issues when you install the app

To connect Butter to your Shopify store and operate the Product

Billing

Plan, subscription status, billing period, Stripe customer identifier or Shopify charge identifier, billing contact

To bill you and manage your subscription

Integration credentials

API keys and identifiers you enter for services you choose to connect — Klaviyo, Judge.me, Yotpo, Google Analytics, Meta Pixel

To make those integrations work on your storefront

Support

The content of emails, live-chat conversations, help requests, and anything you attach. Support runs through Intercom, email, and in some cases Slack.

To answer you and to improve our documentation

Marketing

Email address and preferences if you subscribe, and information you submit through forms on our Site

To send you what you asked for

Payment card details. We never see them. Card processing happens entirely within Stripe or Shopify. We receive only a token, the last four digits, and the outcome.

We collect automatically

Category

What it includes

Product usage

Events recording what you do in the plugin and app — which screens you open, which features you use, when you sync, when onboarding steps complete. Stored against your user ID and store ID.

Technical

IP address, browser and device type, operating system, referring page, timestamps, and pages viewed on our Site

Diagnostics

Error messages, stack traces, and surrounding context when something fails in the plugin, on a storefront, in our backend, or in a call to Shopify's API

Cookies

See the Cookie Notice

We receive from others

  • Shopify — your shop identity, plan, and the product, collection, inventory, market, and metaobject data we are authorized to read; plus webhook notifications when things change or when the app is uninstalled.

  • Google — your name, email address, and basic profile if you sign in with Google.

  • X (Twitter) — your name, email address, and basic profile if you sign in with X.

  • Stripe — subscription and payment status.

  • Framer — plugin installation context when you run Butter inside a Framer project.

2. Why we use it, and our legal basis

Where the EU or UK GDPR applies, this is our basis for each use.

Purpose

Legal basis

Create your account, connect your store, and deliver the Product

Performance of a contract

Bill you, collect payment, manage your subscription

Performance of a contract

Provide support and respond to you

Performance of a contract; legitimate interests

Keep the Services secure, prevent fraud and abuse, debug failures

Legitimate interests in operating a safe and functioning service

Understand how the Product is used, so we can improve it

Legitimate interests in developing our product

Send service and transactional messages — outages, billing, security, material changes

Performance of a contract; legal obligation

Send marketing emails

Consent, or legitimate interests where permitted. You can unsubscribe from any of them at any time.

Meet legal, tax, and accounting obligations

Legal obligation

Establish, exercise, or defend legal claims

Legitimate interests

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Automated decision-making. We do not make decisions about you with legal or similarly significant effects using automated processing alone.

3. When we disclose it

We disclose your personal information to:

  • Service providers who run parts of our infrastructure and operations on our behalf — including our hosting, database, email, and customer-support tools — listed in the sub-processor list. They may only use it to provide services to us.

  • Payment providers — Stripe and Shopify — to process your subscription.

  • Professional advisers — lawyers, accountants, auditors — under confidentiality.

  • Authorities, where we are legally required, or where we reasonably believe disclosure is necessary to protect rights, safety, or property. Where we may lawfully tell you first, we will.

  • A successor, in a merger, acquisition, financing, or sale of assets. We will give you notice, and this policy continues to apply until replaced.

That is the complete list. We do not sell your data, rent it, or hand it to advertisers.

4. Read this first

If you visited an online store designed in Framer and powered by Shopify, that store may use Butter components to show products, run its cart, and apply promotions.

The store you visited decides what is collected and why. We do not. We process that information only to provide our service to them, on their instructions. In data-protection terms, the store is the controller and Butter is their processor.

So if you want your data accessed, corrected, or deleted, contact the store you shopped with. They can act on it directly, and they can instruct us. If you contact us instead, we will pass your request to the store without undue delay, and help them respond — but we cannot act on your data on our own initiative.

If you cannot identify the store, write to us at privacy@buttercommerce.co with the website address and roughly when you visited, and we will try to route it.

5. What Butter may process about you

What a given store actually collects depends on which Butter features it has turned on. Across the Product, the categories are:

Category

What it may include

Device and session

A hashed version of your IP address, browser user agent, device type, country, and first and last seen times

Visit

Referring site, landing page, pages viewed, and campaign parameters in the link you arrived on — utm_source, utm_medium, utm_campaign, utm_term, utm_content

Referral and advertising identifiers

Affiliate codes and ad-platform click identifiers present in the link you arrived on, including gclid, gbraid, wbraid, fbclid, ttclid, msclkid, yclid, and epik

Storefront activity

Products viewed, searches, filters applied, items added to or removed from the cart, checkout started, and the cart or checkout token that ties those together

Order outcome

Shopify order identifier, order total, currency, and a one-way hash of the customer email — used to attribute an order back to a visit

Approximate location

A country derived from your IP address, where the store uses Butter's Markets or currency features

Local storage

Cart contents, selected market and currency, and a discount code, stored in your browser so your cart survives page loads. See the Cookie Notice.

On order data. Butter stores derived and hashed order fields for attribution — an order ID, a total, a hashed email. We do not store the full order payload, and we do not store shopper names, plaintext email addresses, phone numbers, or billing or shipping addresses. Those live in Shopify, with the store you bought from.

Current status. As of the effective date above, storefront analytics collection is built but not yet enabled. This section describes what will be processed when a store turns it on.

6. Aggregate and de-identified data

We may combine data across the stores we serve, strip everything that identifies a person, a store, or a shopper, and use the result to improve the Product and to publish aggregate industry benchmarks.

Two commitments about that:

  • We de-identify to a documented standard, described in the DPA. We do not attempt to re-identify, and we contractually require the same of anyone we give it to.

  • Aggregate output never names or is capable of identifying a store, a shopper, or an order.

Where the law treats de-identified data as still personal, we continue to treat it as personal.

7. Third parties on the storefront

A store can configure Butter to send storefront events to services it has chosen — Google Analytics 4, the Meta Pixel, Klaviyo, or a reviews provider such as Judge.me, Yotpo, or Loox. When it does, those services receive data directly and handle it under their own policies, as that store's providers, not ours.

Separately, some third parties receive your IP address, browser user agent, and referring page simply because your browser requests something from them while the page loads. On a Butter storefront these are:

  • esm.sh — the module CDN our storefront components load their JavaScript dependencies from

  • Iconify — serves country flag icons on stores using Markets

  • Framer — relays reviews API calls through its CORS proxy, where a store uses Yotpo or Judge.me

  • Our geolocation endpoint, with freeipapi.com as a fallback, to determine your country for Markets and currency

Consent. Where a store uses a cookie banner, Butter passes the shopper's choices through to Shopify's customer privacy framework so that consent is respected consistently across the store. Obtaining that consent in the first place, and describing Butter's processing in the store's own privacy policy, remain the store's responsibility.

8. Cookies and similar technologies

We and our components use cookies, local storage, and session storage. Full detail, including the 30-day attribution window, is in the Cookie Notice.

Do Not Track. Browsers send inconsistent signals and there is no agreed standard, so we do not respond to DNT headers.

9. How long we keep things

Data

Retention

Account and workspace records

For the life of the account, then 90 days after deletion

Store connection and configuration

Until the app is uninstalled or the store is deleted, then 90 days

Access tokens

Revoked and deleted on uninstall

Billing and tax records

7 years, as required by Canadian tax law

Product usage events

24 months

Error and diagnostic logs

90 days

Storefront visitor, session, and event data

14 months

Order attribution records

25 months

Support correspondence

3 years

Marketing contacts

Until you unsubscribe, then suppression-list only

De-identified aggregate data

Indefinitely, in de-identified form only

Backups are retained on a rolling basis and overwritten in the normal course of operation. Deletion requests are applied to live systems immediately and to backups as they cycle.

10. Security

We protect personal information with measures appropriate to its sensitivity, including encryption in transit and at rest, row-level access controls in our database, credential and access-token isolation, least-privilege access for our team, and separated staging and production environments.

We are honest about the limit: no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant regulator as required by law.

11. Where your data goes

We are based in Canada. Our infrastructure and service providers operate in Canada, the United States, and the European Union. Personal information may be transferred to, stored in, and processed in any of those places, and it will be subject to the laws of those countries — including, in some cases, lawful access by their authorities.

For transfers out of the EU or UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the additional safeguards described in the DPA. Copies are available on request.

12. Children

The Services are for business use and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.

13. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you, and get a copy

  • Correct it if it is wrong or incomplete

  • Delete it, in certain circumstances

  • Port it to another provider in a structured, machine-readable format

  • Restrict or object to processing, including processing based on legitimate interests

  • Withdraw consent at any time, without affecting processing already carried out

  • Not be discriminated against for exercising any of these

How to exercise them. Email privacy@buttercommerce.co. We will verify your identity — usually by confirming control of the account email — and respond within the time the law allows: 30 days under PIPEDA, one month under the GDPR (extendable by two), and 45 days under the CCPA (extendable by 45). There is no charge unless a request is manifestly unfounded or excessive.

Authorized agents. You may use an agent. We will ask for proof of authority.

Shoppers, note: if you shopped on a store built with Butter, direct your request to that store — see Section 4.

14. If you are in Canada

We handle personal information in accordance with PIPEDA and, where applicable, Quebec's Law 25 and provincial privacy legislation.

Our Privacy Officer is Matthew Jumper, reachable at privacy@buttercommerce.co.

Under Law 25 you also have the right to data portability and the right to be informed when a decision about you is made exclusively by automated processing. We do not currently make such decisions.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca).

15. If you are in the EU or UK

You have the rights in Section 13 under the GDPR and UK GDPR, and the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address it first.

16. If you are in California

In the last 12 months we have collected the categories of personal information described in Part A, for the purposes in Section 2, from the sources in Section 1, and disclosed them to the recipients in Section 3.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the last 12 months. We do not knowingly sell or share the personal information of anyone under 16.

You have the rights to know, delete, correct, and opt out, plus the right to limit use of sensitive personal information. We do not use or disclose sensitive personal information for any purpose that triggers that right. Exercise any of them at privacy@buttercommerce.co. We will not discriminate against you for doing so.

17. If you are elsewhere in the United States

Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana — have rights comparable to those in Section 13, including the right to appeal a refused request. To appeal, reply to our decision with "Appeal" in the subject line. If we deny the appeal, you may contact your state Attorney General.

18. Third-party sites

Our Site and storefronts built with Butter may link elsewhere. We are not responsible for the privacy practices of sites we do not run. Read their policies.

19. Changes

We will update this policy as the Product changes. For material changes we will give notice by email or in-product at least 30 days before they take effect, and revise the date at the top. Continuing to use the Services after that means you accept the updated policy.

20. Contact

Butter Supply Inc.

2727 Steeles Ave West, Unit 103-180, Toronto, ON M3J 3G9, Canada

  • Privacy and data rights: privacy@buttercommerce.co

  • Privacy Officer: Matthew Jumper

  • General: hello@buttercommerce.co

  • Security disclosures: security@buttercommerce.co