Effective date: June 27, 2026
This Privacy Policy explains how Rabby Labs processes information through Discord Members, a Shopify app that connects Shopify stores with Discord community membership features.
When a merchant installs or uses Discord Members, we may process Shopify shop and app installation information.
This may include shop domain, app installation status, granted Shopify scopes, app session information, timezone, and Shopify access credentials needed to operate the app.
Shopify access credentials, such as access tokens and refresh tokens where applicable, are stored in encrypted form and used to call Shopify APIs for the installed shop.
We also process merchant-created configuration, such as offers, coupon settings, product access rules, role discount rules, purchase reward rules, selected Shopify product identifiers and labels, Discord role mappings, claim button message records, and app setup status.
When merchants connect a Discord server or use Discord setup flows, we may process Discord information needed to configure the app.
This may include Discord user information returned during setup, Discord server or guild IDs, server names, server icons, channel IDs, message IDs, role IDs, and role names.
When customers connect Discord, we process the Discord user ID and display username returned by Discord.
Discord OAuth access tokens are used temporarily to complete the OAuth flow and fetch required Discord information. The current implementation is not designed to store Discord OAuth access tokens after the flow completes.
When a customer connects Discord through a merchant’s storefront, we may process the Shopify customer ID, Discord user ID, Discord display username, connection status, cached Discord role IDs, and role sync timestamps.
This information is used to determine whether the customer is eligible for configured member benefits, such as product access, offers, discounts, and purchase rewards.
The app may write Shopify customer metafields for connected customers so storefront and checkout-related features can evaluate member entitlements.
These metafields may include Discord role entitlement IDs, Discord connection status, Discord user ID, and role sync timestamp.
If a merchant enables Purchase Rewards, the app processes Shopify orders/paid webhook data needed to evaluate qualifying purchases.
This can include Shopify order ID, Shopify customer ID, and line item product IDs.
The app stores purchase reward attempt records, including the related rule, order ID, customer ID when available, Discord user ID when available, status, and reason.
These records help prevent duplicate grants and help merchants troubleshoot reward delivery.
The app stores Shopify subscription state, such as subscription ID, plan name, billing status, price, currency, test flag, and current billing period end where applicable.
We do not intentionally collect payment card numbers.
Where applicable, billing approval, payment processing, invoices, and payment method handling are managed by Shopify.
We use the information described above to install and operate the app, authenticate merchants, connect Shopify customers with Discord accounts, evaluate role-based benefits, sync Shopify metafields, grant configured Discord roles, display merchant dashboards, process billing status, provide support, protect security, debug issues, and comply with Shopify or legal requirements.
We do not sell merchant data or customer/member data.
We share or transmit data only as needed to operate the service, including with Shopify, Discord, hosting and infrastructure providers, logging or monitoring systems, and support tools.
These services may process data according to their own terms and privacy policies.
Technical logs may include shop domain, route paths, event status, webhook processing status, error messages, and non-secret identifiers needed for troubleshooting.
We avoid intentionally logging secrets such as access tokens, raw OAuth credentials, or payment card data.
If you contact support, we may process the information you provide, such as your email address, shop domain, screenshots, and troubleshooting details.
We retain information for as long as needed to provide the app, maintain security, troubleshoot issues, comply with legal or platform requirements, and keep appropriate operational records.
When a merchant uninstalls the app or Shopify sends required privacy webhooks, the app is designed to clear or delete relevant records according to Shopify requirements.
Merchants may also contact us to request assistance with deletion.
We use technical and organizational measures intended to protect app data, including encrypted storage for Shopify access credentials, signed sessions, webhook verification, and scoped access controls.
No method of transmission or storage is completely secure.
Customers can disconnect Discord through the storefront experience where available.
Disconnecting marks the customer as disconnected and clears active entitlement state used by the app, while some historical records may remain where needed for security, troubleshooting, legal, or operational reasons.
Merchants can uninstall the app from Shopify and remove the bot from Discord.
For privacy or support questions, contact:
support@rabbylabs.com