Home Privacy Policy
Legal

Privacy Policy

How Custom Shipping Rules handles data when installed on your BigCommerce store. Last updated 11 June 2026.

Custom Shipping Rules (“the App”) is a BigCommerce app provided by Codinative (“we”, “us”). The App calculates UPS weight-based domestic shipping rates for a store's checkout. This policy explains what data the App accesses, stores, and processes.

Information we access

When a merchant installs the App via BigCommerce OAuth, we request only two permissions — both needed to calculate and display shipping rates:

  • Fulfillment Methods — shipping zones and carrier configuration, to connect the carrier so its UPS options appear at checkout.
  • Information and Settings — the store's weight/dimension units and default currency, to convert and price rates correctly.

The App does not access orders, customers, products, or payment data.

Information we store

We store the minimum required to operate the App, in Google Firebase (Firestore):

  • Your store hash and the OAuth access token issued by BigCommerce at install.
  • The store user(s) who installed or were granted access to the App (id, email, username).
  • Your per-store app settings (pricing strategy, percentages, dimensional divisor, on/off state).

Checkout data

At checkout, BigCommerce sends the App a quote request containing the cart's line items (weights and dimensions), the destination country, and the currency, so we can return rates. We log non-identifying request metadata (weights, currency, timestamps, user-agent) for diagnostics only. We do not store shopper names, addresses, emails, or payment information.

Third-party processors

  • BigCommerce — the platform the App integrates with.
  • Google Firebase / Firestore — stores the data described above.
  • Vercel — hosts the App.

We do not sell or share your data with advertisers, and we do not use it for any purpose other than operating the App.

Data retention & deletion

When you uninstall the App, BigCommerce notifies our uninstall endpoint and we remove your store record, access token, and associated user records. To request deletion at any other time, email us at info@codinative.com.

Security

All traffic uses HTTPS. Access tokens and credentials are stored server-side and are never exposed to the browser or to shoppers.

Contact

Questions about this policy? Email info@codinative.com or visit codinative.com.

Codinative · codinative.com