Dashmint privacy policy
Dashmint is a Shopify app that adds a short pixel game to a store. Shoppers collect coins by playing and trade them for rewards the store sets. This policy says what Dashmint stores about the stores that install it and about their shoppers, why, for how long and where.
Dashmint is made by ENSOMEDIA (https://ensomedia.dev). Write to hello@ensomedia.pl with any question about this policy.
Who is responsible for what
A store that installs Dashmint decides to run the game for its shoppers and remains responsible for its customers' data. ENSOMEDIA processes that data on the store's behalf and only to run the game, the coins and the rewards in that store. ENSOMEDIA is responsible for the data about the store itself: its domain, plan and settings.
What Dashmint stores about a store
- The store's domain and name, currency and time zone, and the plan chosen in Shopify's app pricing.
- An access token for Shopify's Admin API. Dashmint uses it to create reward codes and to read orders and products.
- The settings the store chooses in Dashmint: rewards and their prices in coins, the monthly budget, the game mode, texts, colours, a link to its terms and a minimum age.
- The store's revenue and average order value over the last 30 days, worked out from its orders, which set the reward budget.
- Titles, prices, pictures and links of the products the game shows as product cards. This is catalogue data, not personal data.
- Messages the store sends to support.
- Answers of the AI assistant for up to 24 hours, and a daily count of the requests the store made.
What Dashmint stores about shoppers
The game block loads as soon as it scrolls into view on the store's page, before a shopper does anything else. For a logged-in customer, that first contact already creates their player record, before they press Play. Dashmint never asks for and never stores names, email addresses, phone numbers or postal addresses.
- A player id. For a logged-in customer it is the customer id that Shopify sends with each request; for a guest it is a random key. A guest's key and the receipts of their runs stay in their own browser (local storage) for up to 30 days, so the coins can move to their account when they log in.
- Coins: the balance, coins waiting for an order to clear, and each change to the balance (runs, bonuses, orders, rewards, refunds) with its date.
- Runs: the day, the game mode, map and character, the score and stars, and the run's input log, meaning the key presses and their timing, which the server replays to check the score. To limit how often runs can start from one address, Dashmint keeps a salted hash of the IP address that changes every day. The IP address itself is never stored.
- Rewards: which reward was redeemed, the discount code created in the store for that customer, its amount and end date, and the order it was used on.
- Orders that earn coins or use a reward code: the order id and number, total and currency, the customer id and the codes used.
- Up to five cart tokens per player from the store's cart, used to match a guest's order to their runs.
In the shopper's browser the game also keeps the day's best score. The game sets no cookies, runs no analytics and shows no ads.
What the data is used for
- Running the game: today's route, scores and stars, the daily run limit and the fair play checks.
- Crediting coins, issuing and tracking reward codes, and keeping rewards within the budget the store set.
- Showing the store its reports and players in the Dashmint admin.
- Answering support requests.
Dashmint does not sell data, does not use it for advertising and does not combine shoppers' data across stores.
AI suggestions
The Dashmint admin can suggest settings, texts and promotions with an AI model run by Groq, Inc. (https://groq.com). Groq processes each request for Dashmint as a processor, only to produce the suggestion the store sees in its admin. A request is sent when the store asks for a suggestion and, on the Studio plan, when the store opens or changes a setting that has a tip, within the plan's daily limit. The store can switch AI suggestions off in Settings; then no request leaves Dashmint. Nothing in the store changes until the store applies a suggestion.
A request carries only:
- the store's totals: revenue and average order value over 30 days, runs, players, coins, rewards and budget use;
- the store's name and currency, and the titles of its collections and products;
- the texts the store asks the assistant to improve, such as the label of the game button.
- On the Studio plan, the game world builder also sends the store's own written description of itself and, for each product it is shown, that product's type and its main colours. It never sends a product's price or whether it is in stock.
Customer data is never sent: no customer ids, names, email addresses, postal addresses, order numbers or IP addresses. Before a request leaves Dashmint, email addresses, phone numbers and long numbers are removed from the store's titles, and a text to improve that holds one is not sent at all.
Dashmint keeps the answers for up to 24 hours, so the same suggestion is not asked for twice, and counts the requests per day to apply the plan's daily limit.
Reward codes
Reward codes are ordinary Shopify discount codes created in the store. A code made for a customer account is tied to that customer; a code made for a guest (on stores that let a guest redeem without an account) is not tied to any customer, since a guest has none, but is otherwise the same: it works once, has an end date and appears in the store's Shopify admin under the title Dashmint reward. A nightly job removes expired codes from the store.
How long Dashmint keeps data
- Input logs of runs
- 30 days
- IP address hashes
- 7 days
- Guest runs not moved to an account
- Cannot be claimed after 30 days; the guest's own record and balance stay, like everything below, while the store uses Dashmint
- Daily run and coin counters
- 60 days
- Records of Shopify webhook deliveries
- 30 days
- Coins, runs, rewards and orders
- While the store uses Dashmint
- Answers of the AI assistant
- 24 hours
- Daily counts of AI requests
- While the store uses Dashmint
- Which admin features and suggestions a store uses
- 13 months, to improve the app
- Custom briefs, with the contact email the store gave
- While the store uses Dashmint, and 24 months after the last reply
- All data of a store that uninstalls Dashmint
- Deleted when Shopify sends its deletion request, 48 hours after the uninstall, and in any case within 30 days
Codes already given to shoppers keep working in the store until their end date.
Requests about personal data
- When a customer asks a store to erase their data, Shopify sends Dashmint the request. Dashmint then deletes that customer's player record with its runs and counters, and removes the customer id from coin, reward and order records, which keep only anonymous totals for the store's reports.
- When a customer asks a store for their data, Shopify sends Dashmint the request and Dashmint prepares an export of everything it holds about that customer for the store.
- When a store uninstalls Dashmint, Shopify sends a request to erase the store's data 48 hours later, and Dashmint deletes it.
- Shoppers can also write to hello@ensomedia.pl. The store is responsible for its customers, so Dashmint passes the request on to the store and acts on its instructions.
Where the data is kept
Dashmint runs on Google Cloud, in Cloud Run and Cloud SQL for PostgreSQL, in the European Union region europe-central2 in Warsaw, Poland. Google Cloud processes the data for Dashmint as its hosting provider. Data travels over encrypted connections (TLS) and Google Cloud encrypts it at rest.
Data also passes through Shopify, between the store, its shoppers and Dashmint, under Shopify's own privacy policy.
Requests for AI suggestions go to Groq, Inc., which runs the model on its own infrastructure, as described under AI suggestions.
What the store is responsible for
The store decides to offer the game and its rewards to its customers. It is responsible for describing Dashmint in its own privacy policy and in the terms of its promotion, for the minimum age it sets in Dashmint, and for any consent its local law requires.
Changes and contact
When Dashmint changes what it stores, this page changes and the date at the top moves. Questions and requests go to ENSOMEDIA at hello@ensomedia.pl or through https://ensomedia.dev.