Effective date: 14 September 2026. This is the published policy for the Benetti Gift Wrap Shopify app.
Operator: Benetti Corporation, a Texas C-Corporation
Contact email: benettimedia@gmail.com
Mailing address: Benetti Corporation, 1401 Lavaca Street #40044, Austin, TX 78701, USA
Governing jurisdiction: Texas, USA
This policy covers information processed when a merchant installs or uses Benetti Gift Wrap, adds its theme block, reviews the list of what the app has recorded in their store, or uninstalls the app.
No customer personal information is collected, stored or processed by this app. A shopper's gift message travels on the order as a line item property: the theme block's form writes it to the cart line, Shopify holds it on the order, and it is never copied to this side. The app requests no customer scope and reads no order.
An app cannot remove what it never wrote down. The ledger is what makes the uninstall promise checkable rather than a claim: the merchant can read the full list of what the app has added to their store at any time, before they ever decide to uninstall, and each entry names the option that put it there.
The session is used to call the Shopify Admin API on the merchant's behalf. The ledger is used to show the merchant what the app has changed and to remove exactly those things on uninstall. Nothing is used for advertising, profiling, resale, or training a model.
Sessions and the artifact ledger are stored in Google Cloud Firestore, in separate collections, in a Google Cloud project operated by Benetti Corporation. The app runs on Google Cloud Run. Google Cloud is the only third-party processor; there is no analytics vendor, no advertising network and no error-reporting vendor outside Google Cloud.
shop/redact webhook. Both stores are read back afterwards and a
failure names which of the two still holds rows.customers/data_request — the app holds no customer data, so
there is nothing to furnish. The request is answered and recorded rather than
ignored.customers/redact — the app holds no customer data, so there
is nothing to erase. Answered and recorded on the same basis.shop/redact — every session row and every ledger row for the
shop is deleted, and the deletion is verified by reading both stores back
before success is reported.Every delivery is verified before it is acted on: the raw request body is read before anything parses it, an HMAC-SHA256 is computed over those exact bytes with the app's client secret, and the comparison is constant time. An unverified request is refused with 401 and no record is written for it. This applies to the uninstall webhook as well as the privacy ones — an unverified uninstall endpoint would be a URL anyone could use to make the app delete a merchant's data.
A merchant may remove the theme block at any time, read the full list of what the app has recorded in their store from inside the app, uninstall, or write to the address below to ask what is held for their shop.
The controls stated here — signature verification before any action, the verified read-back on both erasure paths, the removal order that does not orphan a theme block, and the refusal to report a removal that was not measured — are each covered by tests in this app's repository. This is a description of what the code does. It is not a certification and not a claim about encryption, backups, region, or incident response times.
If data categories, purposes, storage, providers, retention, or merchant controls materially change, this page is updated before or with that change, and the effective date at the top is moved forward.
Privacy and data requests: benettimedia@gmail.com
Mail: Benetti Corporation, 1401 Lavaca Street #40044, Austin, TX 78701, USA
Governing jurisdiction: Texas, USA