Fortuna Raffles · Last updated: 5 August 2026
Fortuna Raffles ("the App", "we", "us") is a Shopify app that lets merchants run raffles for their customers. Each paid order earns the customer raffle tickets, and the App draws a winner on the merchant's chosen schedule. This policy explains what data the App accesses, how it is used, how long it is kept, and the choices available to merchants and their customers.
When you install the App on your Shopify store, and while it operates, it accesses:
orders/paid webhook and read_orders scope): the order's identifier, its subtotal, and its line item quantities. These determine how many raffle tickets an order earns under the rule you configure.read_customers scope): the Shopify customer ID and email address attached to a paid order. These attribute a raffle ticket to the right person and let a winner be contacted.read_products scope): product titles and images, used only so you can select a product as a raffle prize and see it in the App.write_gift_cards scope): where you configure a gift card as the prize, the App creates a gift card in your store to award the winner.write_customers scope): when someone enters a raffle through the free entry page, the App creates a customer record for them in your store, so you can see who entered and can reach a winner. Their email marketing consent is set to subscribed only if they ticked the optional consent box; otherwise it is explicitly recorded as not subscribed. Where the entrant is already a customer and did not tick the box, their existing record and any marketing preference they set elsewhere are left untouched.The App does not request or store customer names, phone numbers, or shipping or billing addresses.
Data is used only to operate the raffle features you configure:
We do not sell personal data, share it with advertisers, or use it to build profiles of customers. We do not send marketing of our own to your customers: where an entrant opts in, the subscription is created in your store and any marketing that follows is sent by you, as the data controller, under your own privacy policy. We do not use personal data to make automated decisions with legal or similarly significant effects; winner selection is a random draw among entries and does not evaluate personal characteristics.
The App runs on Render and stores data in a PostgreSQL database hosted by Neon. Data is encrypted in transit (HTTPS/TLS) and at rest. Backups are managed and encrypted by Neon.
shop/redact request, which Shopify sends 48 hours after uninstall.The App implements Shopify's mandatory compliance webhooks:
customers/data_request — we compile the raffle entries held for that customer, along with any free-entry participant record (email, referral code, and marketing consent status), so you can provide them within the required window.customers/redact — we remove the customer's email address and Shopify customer ID from their raffle entries, and delete any free-entry participant record and its stored consent. Ticket numbers are retained without identifying information so past draw results remain verifiable.shop/redact — we delete all data held for the shop.Customers should direct requests to the merchant whose store they purchased from; the merchant can action them through Shopify, and Shopify will notify the App.
Access to production systems is limited to the App's operator and protected by strong credentials and multi-factor authentication. Access to the application and database is logged by our hosting providers. We maintain a security incident response policy and will notify affected merchants and Shopify without undue delay, and within 72 hours, of becoming aware of a personal data breach.
If this policy changes materially, the updated date above will change and, where the change affects how merchant or customer data is handled, we will notify merchants through the App.
Questions about this policy or about data the App holds can be sent to popmartblindboxshop@gmail.com.