GetJacked

GetJacked by Anchor Demand Inc · Effective Date: March 2026

Privacy Policy

This Privacy Policy describes how Anchor Demand Inc ("we," "us," or "our") collects, uses, stores, and shares information when you use the GetJacked application (the "App") available on the Shopify App Store. By installing or using the App, you agree to the practices described in this policy.

1. Information We Collect

1.1 Data Collected via Shopify APIs

When you install GetJacked, we access certain data from your Shopify store through the Shopify API, including:

  • Store information: shop name, domain, email address, and plan type
  • Customer data: names, email addresses, and purchase history used to power loyalty programs
  • Order data: order IDs, product details, order values, and transaction timestamps
  • Product data: product names, variants, and pricing for reward redemption purposes
  • Storefront session data: used to display the Rewards Center widget to shoppers

1.2 Data Collected Directly

In addition to Shopify API data, we may collect account registration details provided by merchants during onboarding, configuration settings and preferences set within the App, support and communication data when you contact us for help, and usage data such as feature interactions, session duration, and click patterns within the App.

1.3 Technical and Device Data

We automatically collect certain technical data including IP addresses and approximate geolocation, browser type, version, and operating system, device type and screen resolution, referring URLs and navigation paths within the App.

1.4 Cookies and Tracking

The App uses cookies and similar tracking technologies to maintain session state, remember merchant preferences, and analyze App performance. You may configure your browser to refuse cookies, though some App features may not function correctly without them.

2. How We Use Your Information

We use the information we collect to provide and operate the GetJacked loyalty program features (including points tracking, tier management, and reward redemption), to display the Rewards Center to shoppers on your storefront, to process and fulfill loyalty transactions between merchants and their customers, to send transactional communications related to your account and loyalty program activity, to improve, debug, and optimize App performance and user experience, to comply with legal obligations and respond to lawful requests from authorities, and to detect and prevent fraud, abuse, or unauthorized access.

3. Data Sharing and Disclosure

We do not sell your personal data. We may share data in the following limited circumstances:

  • Service providers: third-party vendors who assist us in operating the App (cloud hosting, analytics). These vendors are contractually obligated to protect your data and use it only for the services they provide to us.
  • Shopify: Data flows through Shopify's platform in accordance with Shopify's Privacy Policy and API terms.
  • Legal compliance: We may disclose data when required by law, court order, or government authority.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change.

4. Subprocessors

We use a limited number of trusted third-party service providers (“subprocessors”) to assist in operating the GetJacked application. These subprocessors access merchant and customer data only to the extent necessary to perform their services on our behalf, and are contractually bound to protect that data in accordance with applicable privacy laws and our data protection standards.

The following subprocessor is currently used by Anchor Demand Inc in connection with the GetJacked application:

  • Amazon Web Services (AWS) — Cloud infrastructure and application hosting provider. AWS stores and processes app data in secure data centers located in the United States. AWS is certified under SOC 1, SOC 2, ISO 27001, and complies with GDPR requirements. For more information, see the AWS Privacy Notice at https://aws.amazon.com/privacy/.

We will update this section if we engage additional subprocessors. Merchants who require advance notice of subprocessor changes may contact us at privacy@getjacked.io.

5. Data Retention

We delete or anonymize all shop-related data within 48 hours of receiving the mandatory shop/redact webhook from Shopify following app uninstallation.

6. Data Storage and International Transfers

Your data is stored and processed in the United States. If you or your customers are located in the European Union or other regions with data transfer restrictions, please be aware that data may be transferred to and processed in the United States, which may not provide the same level of data protection as your home jurisdiction. By using the App, you consent to this transfer.

We implement appropriate technical and organizational safeguards to protect data during international transfers, including standard contractual clauses where applicable.

7. GDPR — Rights of EEA Residents

If you or your customers are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to access
  • Right to rectification
  • Right to erasure
  • Right to restriction
  • Right to data portability
  • Right to object
  • Right to withdraw consent

To exercise any of these rights, contact us at privacy@getjacked.io. We will respond within 30 days.

7a. Lawful Basis for Processing

Under the GDPR, we are required to identify a lawful basis for each type of personal data processing. We rely on Contractual Necessity, Legitimate Interests, Legal Obligation, and Consent depending on the processing activity. For consent-based processing (such as optional marketing communications), you may withdraw consent at any time by contacting us at privacy@getjacked.io.

7b. Lodging a Complaint with a Data Protection Authority

If you are located in the EEA and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A full list of EEA DPAs is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

8. CCPA / CPRA — Rights of California Residents

If you are a California resident, you have rights under the CCPA/CPRA including the right to know, right to delete, right to correct, right to opt out of sale (we do not sell personal data), and right to non-discrimination for exercising your rights. To submit a request, contact us at privacy@getjacked.io. We will respond within 45 days.

8a. Do Not Track (DNT) Disclosure

GetJacked does not track users across third-party websites, apps, or online services. We do not engage in cross-site tracking, behavioral advertising profiling, or the sale or sharing of tracking data with any third party. Because we do not track users in any capacity, DNT signals have no applicable effect on our data practices.

9. Mandatory Shopify Compliance Webhooks

In compliance with Shopify's API requirements, we have implemented the following mandatory webhooks to honor data subject rights:

  • customers/data_request: Upon receiving a request from Shopify for customer data associated with a shop, we will provide the requested data within the required timeframe.
  • customers/redact: Upon receiving a redaction request from Shopify, we will delete or anonymize all personal data associated with the specified customer.
  • shop/redact: Upon receiving a shop redaction request (typically 48 hours after app uninstallation), we will delete all data associated with the merchant's store.

These webhooks ensure that GetJacked complies with GDPR erasure requests and Shopify's data protection standards. Merchants may also initiate data deletion directly by contacting us at privacy@getjacked.io.

10. Data Security

We implement industry-standard security measures to protect your data, including encryption of data in transit using TLS/HTTPS, encryption of sensitive data at rest, access controls and authentication requirements for internal systems, and regular security reviews and vulnerability assessments. While we take reasonable precautions, no method of transmission or storage is 100% secure. In the event of a data breach that affects your rights, we will notify you as required by applicable law.

11. Children's Privacy

The App is intended for use by merchants operating e-commerce businesses and is not directed at individuals under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices or applicable law. We will notify you of material changes by posting the updated policy at https://getjacked.io/privacy and, where appropriate, by email. Your continued use of the App after changes are posted constitutes acceptance of the updated policy. Under CCPA, we will update this policy at least once every 12 months.

13. Contact Us

For privacy-related questions, requests, or concerns, please contact:

Anchor Demand Inc
4162 Sorrel Way NE, Bainbridge Island, Washington, 98110
Email: privacy@getjacked.io
Website: https://getjacked.io