Versioned privacy policy
Privacy policy
Ready, Set, Go operates Little Lift, an app for optional USD donations to Meyer & Friends through Shopify POS and online carts, with donation/refund accounting and monthly remittance records. This document describes the information used for that service and how privacy requests and recovery copies are handled.
- Meyer & Friends is the donation beneficiary. Ready, Set, Go provides the app and technical support.
- Order references remain protected data even though the donation ledger excludes buyer contact and payment details.
- Contact letsgo@helloreadysetgo.com for privacy questions or access, correction, export and deletion requests.
Privacy version: little-lift-privacy-v2. Document date: September 14, 2026. Accompanies agreement meyer-free-remittance-privacy-v2.
Information and purposes
Shopify supplies store identity and domains, name, contact email, currency, timezone, installation status and authorized scopes. Donation-product and variant IDs support donation selection and product checks. Location references support reporting. The storefront widget reads the cart and the customer's donation choice to show and add an optional donation; it does not create a donor profile or add advertising cookies.
Paid-order and refund events identify donation lines. Accounting records contain order IDs and names, donation-line and refund IDs, amounts, currency, processing/payment dates, channel and location references, adjustments and monthly statements. These are used to calculate donations and refunds, prevent duplicate processing and reconcile remittance. An order reference can be linked to a customer in the merchant's Shopify account.
Agreement versions and acceptance time, authenticated actor identifiers, remittance instructions, reported payments, beneficiary verification and audit metadata support participation and reconciliation. Authentication sessions may contain Shopify account IDs, names, emails, access credentials and expiry information. Credentials connect the app and are not included in merchant reports or access exports.
Pending Shopify customer privacy requests are stored with request/event references, requested order IDs, receipt time, deadline and handling status. The queue does not retain buyer contact fields or raw request payloads. Its order references identify the scope of an access export or deletion. An explicit merchant delivery confirmation replaces the access request's order-selection metadata with the merchant-reported status and report time. Redaction removes processed order selectors and keeps a count of remaining work.
After order details are removed, monthly contributions retain amounts, currency, donation channel and entry count without the original order, refund, location or payment-time references. Separate keyed safeguards prevent deleted details from returning and prevent duplicate accounting. A private recovery journal records keyed store, installation and affected-order scope, processing times and outcomes. It contains no customer contact fields, raw order IDs, donation amounts or payment credentials. These safeguards are protected pseudonymous records and are disclosed in a scoped access response where they relate to the requested order.
The donation ledger does not store buyer names, emails, phone numbers, addresses, payment details or raw webhook payloads. We use information sent to support to respond; please do not send customer details, passwords, tokens or payment credentials. The app does not sell personal data or use donation records for advertising or competitive benchmarking.
Instructions, access and sharing
For order-related data, Ready, Set, Go processes the information for the merchant's donation service, authenticated settings and applicable privacy requests. The merchant is responsible for required customer notices and permissions. Contact us if an instruction requires a change that Little Lift cannot currently perform.
Shopify supplies the store, checkout/payment environment and authentication. Cloudflare hosts the app, database and public assets. Authorized Meyer & Friends administrators use remittance records to confirm merchant payments. Authorized technical operators use necessary information to maintain the service and resolve support requests. Little Lift does not provide the beneficiary with a donor mailing list.
Shopify authentication and store-scoped access protect merchant views and access exports; beneficiary verification requires a separate restricted role. Shopify and Cloudflare may process data outside your country. This version does not promise a particular processing location or a completed international-transfer assessment. Ready, Set, Go remains responsible for its handling of data.
Retention purposes and limits
Donation, refund, statement and payment history serves the installed merchant's ongoing reporting, reconciliation and remittance needs. Necessary accounting history has no fixed anniversary-based expiry. Retention must remain limited to that purpose: installation alone is not a reason to keep every identifier or diagnostic record indefinitely. Merchants are responsible for their independent copies and recordkeeping needs.
Settings and agreement records identify the active service and accepted terms. Expired sessions are removed when no longer needed for access or a pending uninstall check. Customer redaction removes affected active order details and processing metadata while preserving monthly totals. We retain only the minimum keyed safeguards needed to keep deleted details from returning and prevent duplicate accounting, for as long as those purposes remain necessary. These restricted records contain no raw order IDs or links between an order and its amounts; they remain protected pseudonymous data and are not used to rebuild customer profiles or contact customers.
Shopify's deletion obligations apply when the app is uninstalled, information is no longer needed for its service or an enforceable deletion request is received. They cover affected originals and copies within 30 days unless applicable law prohibits or changes that obligation. Necessary suppression records and recovery handling are limited to their stated purposes; they do not provide a general exemption. If we cannot comply, Shopify's API Terms require us to notify Shopify.
Requests and current handling
Email letsgo@helloreadysetgo.com with Little Lift privacy in the subject for access, correction, export or deletion. Include your store domain and the kind of request, without customer details or credentials. We may need to verify your connection to the store. Customers should also contact the merchant that collected the donation for order and payment information held by that merchant.
Little Lift records Shopify customer access and redaction requests with their order scope and a 30-day deadline. The authenticated merchant can see pending requests in Setup and help and download a shop-scoped JSON access export for delivery through the merchant's customer privacy process. Generating an export does not prove customer delivery. Acknowledging a webhook or queuing redaction does not mean deletion has occurred.
After delivering the requested data, the authenticated merchant can explicitly report delivery in the app. Little Lift records the merchant's confirmation and clears the pending request's order-selection metadata. This is merchant-reported delivery, not independent verification of delivery or deletion. Downloading an export does not record this confirmation, and the action cannot complete a redaction request.
Customer redaction automatically removes the affected active order details in bounded steps and preserves reconciliation totals. Failed steps retry, and incomplete work remains visible. Request status distinguishes active-data removal, remaining work and retained deletion safeguards. Contact support for the handling status, the minimum safeguards retained and the applicable backup or retirement handling. A queued request alone is not completion; we remain responsible for responding and applying the required handling within the applicable deadline.
Uninstalling and recovery copies
Uninstall and Shopify shop-redaction requests start deletion of that installation's active store data, including its sessions, settings, agreements, order/refund records, statements and associated metadata. Before deletion, Little Lift checks for a current installation and protects a concurrent reinstall. If installation status is uncertain, the request remains pending for retry or operator review. Export records you need before uninstalling; a successful webhook response alone does not prove erasure.
Cloudflare D1 has a verified 30-day recovery history. Affected backup data is kept beyond active use until it expires through that rolling history. A separate private journal preserves later deletion instructions across a database rollback. Before restored data can return to service, operators must reapply later deletions in quarantine and verify that the affected details have been removed and accounting reconciled. Unresolved journal outcomes and snapshots predating the journal prevent reopening through this recovery procedure.
Encrypted legacy migration archives and inactive hosting recovery copies remain protected solely for the current migration recovery purpose. They are retired once replacement recovery verification ends; retirement has not yet occurred. These copies cannot return to service through the current recovery procedure because they predate its journal. Retention and recovery handling do not waive privacy rights or Shopify's requirements.
Version and contact
This is the fixed privacy document little-lift-privacy-v2, presented with agreement meyer-free-remittance-privacy-v2. Its disclosures are contained here, rather than incorporated from a mutable privacy page. Provider links are additional information. Later material changes require new document versions and fresh agreement acceptance; earlier remittance-only acceptance does not accept this policy.
Ready, Set, Go operates and supports Little Lift. Contact letsgo@helloreadysetgo.com for questions about this policy or a specific request.