Privacy Policy
Last updated July 13, 2026
This policy explains what data DepositDesk (“we”, “us”) processes when a Shopify merchant installs the app and when that merchant’s customers place a deposit order. DepositDesk is operated by Skeg Software, a sole proprietorship operated by Justin Breshears.
DepositDesk never sees or stores payment card details. Shopify securely vaults the customer’s payment method and executes the balance charge. We only reference Shopify’s payment-mandate identifier — we are not a payment processor and never handle card data.
Who is responsible for your data
The merchant (the store you bought from) is the data controller. Skeg Software acts as a data processor, handling personal data only on the merchant’s instructions to provide the app’s functionality. If you are a shopper with a question about your data, contact the store you ordered from; you may also contact us at support@depositdesk.app.
What we process
We collect the minimum data needed to schedule and collect the remaining balance on a deposit order, and to send notices about it:
| Source | Data | Why |
|---|---|---|
| Merchant | Store domain, store contact email, deposit-plan settings | Run the app, contact the store about balance issues |
| Customer | Name, email address | Send transactional notices about that customer’s own order — a deposit confirmation showing the balance owed and its scheduled charge date, a declined-payment or action-required notice if a charge fails, and a notice if the saved card is removed; Shopify may also email a secure card-update link on our request |
| Order | Order, selling-plan, and payment-mandate identifiers; amounts | Track the deposit, the balance owed, and its capture status |
We do not use this data for advertising, marketing, profiling, resale, or any automated decision-making beyond executing the payment schedule the customer already agreed to at checkout.
Who we share it with (sub-processors)
We do not sell data. We use a small set of vetted service providers to run the app:
| Provider | Purpose |
|---|---|
| Shopify | Platform, order data, and secure payment execution |
| Supabase | Encrypted application database (hosted in the United States) |
| Vercel | Application hosting |
| Resend | Delivery of transactional email notices |
| Sentry | Error monitoring (technical diagnostics; not used for tracking) |
How long we keep it
We retain a store’s data while the app is installed. When a merchant uninstalls DepositDesk, we revoke access immediately and permanently delete the store’s data when Shopify sends the shop/redact signal (about 48 hours after uninstall). We also honor Shopify’s privacy requests: a customer data request is fulfilled within 30 days, and a customer redaction request erases that customer’s personal data from our records.
How we protect it
- Encryption in transit (TLS) and at rest (AES-256).
- Least-privilege access with multi-factor authentication.
- An internal audit log of every access to customer personal data.
- Separate development and production databases that never share data.
Your rights
Depending on where you live (for example, under the GDPR or CCPA), you may have the right to access, correct, export, or delete your personal data. Because the merchant is the controller, please direct requests to the store you ordered from; we will assist them promptly. You can also reach us at support@depositdesk.app.
Changes to this policy
If we make a material change, we will update the date at the top of this page and, where appropriate, notify merchants in the app.
Contact
Skeg Software, a sole proprietorship operated by Justin Breshears
515 S Fry Road, Ste A PMB 1002, Katy, TX 77450, United States
support@depositdesk.app