Skip to content
Get the appsGet the apps

Our apps

Order EditingOrder CancellationsPost-Purchase UpsellsRule-based Order EditingAutomated Order TaggingAddress & Contact EditingNotificationsSelfServe overview →
CartServe Cart drawer · NewUpServe Popup upsells · New
All apps on the Shopify App Store →

Explore

TestimonialsUpsell storiesAffiliate programFAQSupport

We serve the Shopify community.

Three apps, one job: stores that run themselves.

✳

100+stores served

App StoreApp Store

On this page

Who is responsible for whatWhat we collectWhy we process it and on what basisWho we share data withHow long we keep itInternational transfersSecurityYour rightsCookiesChildrenChanges to this policyContact

Applies to the ServeApps website and to all ServeApps apps: SelfServe, CartServe and UpServe.

Privacy Policy

Effective 8 September 2026 · ServeApps, a brand of Grumspot Ltd

This policy explains what ServeApps (operated by Grumspot Ltd, “ServeApps”, “we”) does with personal data when you visit serveapps.com or install one of our Shopify apps: SelfServe (order editing), CartServe (cart drawer) and UpServe (popup upsells). One policy covers all of them, so a merchant only has to read it once.

Who is responsible for what

For the website and for merchant accounts (the store owner or staff who installs an app), we act as the data controller.

For your customers’ data processed inside the apps (for example the order a shopper edits with SelfServe, or the cart a shopper builds with CartServe), the merchant is the controller and ServeApps is the processor, acting on the merchant’s instructions and Shopify’s platform terms. Shoppers should read the privacy policy of the store they bought from; this page explains our part.

What we collect

From merchants

  • Shopify account data when you install an app: store domain, store name, contact email, plan, and the access scopes you approve.
  • App settings you create: rules, editing windows, popup designs, cart blocks, notification preferences.
  • Support communications: messages sent through our forms, in-app chat or email, and the details you include.
  • Usage data: which app screens are used and when, error logs, and technical data such as browser type. We use this to keep the apps working and to decide what to build next.

From shoppers, on behalf of merchants

  • SelfServe reads and updates orders through Shopify’s API to let a customer edit, cancel, or change the address on their own order. That includes the order contents, shipping and billing address, email and phone on the order, and payment status. SelfServe never sees full card numbers; payments for order changes are handled by Shopify.
  • CartServe renders the cart drawer in the storefront. It processes the current cart contents, market and currency, and applied discounts. It stores no shopper profile.
  • UpServe shows an offer after add-to-cart. It processes the product added, the offer shown, and whether it was accepted, so merchants can see impressions, conversions and revenue per popup. Frequency caps use a first-party cookie or local storage on the store’s domain.
  • None of the apps use cross-site tracking, advertising identifiers or fingerprinting.

From website visitors

  • Necessary cookies for the site to work and to remember your cookie choice.
  • Analytics only if you accept it in the cookie banner. See the cookie policy.
  • Anything you send through the support or affiliate forms.

Why we process it and on what basis

  • To provide the apps you installed and the features you configured: performance of a contract (our terms).
  • To support you, answer questions and fix bugs: contract and legitimate interest.
  • To keep the apps secure and reliable: legitimate interest.
  • To improve the apps using aggregated usage data: legitimate interest.
  • To send product updates to merchants: legitimate interest, with an unsubscribe link in every email. We do not send marketing to shoppers.
  • Website analytics: your consent, given in the cookie banner and revocable at any time.
  • Legal obligations such as tax and accounting records.

Who we share data with

We do not sell personal data and we do not share it with advertisers. We use a small number of service providers (sub-processors) who act on our instructions:

  • Shopify: the platform the apps run on; all store data flows through Shopify’s APIs under Shopify’s terms.
  • Cloud hosting and databases in the European Union and the United States, to run the apps.
  • Email delivery for notifications and support replies.
  • Error monitoring and analytics tools that receive technical events, never full order contents.
  • Payment and billing: app charges are billed through Shopify Billing; we never handle your card details.

We will share data if the law requires it, or to protect the rights and safety of merchants, shoppers or ServeApps. A current list of sub-processors is available on request.

How long we keep it

  • While an app is installed: for as long as you use it.
  • After uninstall: settings and store data are kept for 30 days so you can reinstall without starting over, then deleted permanently.
  • Shopper data processed for merchants follows the merchant’s instructions and Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact and shop/redact are honoured within 30 days.
  • Support messages: up to 24 months, so we can help with follow-ups.
  • Accounting records: as long as tax law requires.

International transfers

ServeApps operates from the European Union. Where data is processed outside the EU/EEA or the UK (for example by a US hosting provider), we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, and on providers that maintain appropriate safeguards.

Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it to run and support the apps, protected by strong authentication. Shopify API tokens are stored encrypted and scoped to the minimum permissions each app needs. If a breach ever affects your data, we will notify you and the relevant authority as the law requires.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA and similar laws), you can ask us to access, correct, delete or export your personal data, to restrict or object to processing, and to withdraw consent at any time without affecting past processing. You also have the right to complain to your local data protection authority.

Merchants can write to business@grumspot.com. Shoppers should contact the store they bought from; the merchant can instruct us through Shopify, and we will act on it. We answer within 30 days.

Cookies

The website uses a necessary cookie to remember your consent choice and, only with your permission, analytics. The apps use first-party cookies or local storage inside the merchant’s store solely for functionality (such as remembering that a shopper already saw a popup). Details, lifetimes and how to change your choice are in the cookie policy.

Children

Our website and apps are for businesses and are not directed at children under 16. We do not knowingly collect their data.

Changes to this policy

When we change something material we will update the effective date above and, for merchants, announce it inside the apps or by email before it takes effect. Earlier versions are available on request.

Contact

Privacy questions and requests: business@grumspot.com. Support: support page.

This policy is written to be read. It is not a substitute for the Shopify Partner Program terms or for the merchant’s own privacy policy towards their shoppers, both of which continue to apply.

At your service.

Install any of the three from the Shopify App Store. They work alone, and better together.

Install the appsInstall the apps
ServeApps
© 2026 ServeAppsPrivacyTermsCookiesCookie settingsAffiliatesSupport
✳

Cookies, served plainly.

We use a couple of necessary cookies to make the site work. With your OK we also use analytics to see which pages help merchants most. No ad trackers, ever. Cookie policy

NecessaryConsent choice, security. Always on.
AnalyticsAnonymous page statistics.
MarketingMeasuring campaigns. Off unless you say so.