Shopify Services Policy

Shopify Services Privacy Policy

How Five Acre Code handles inquiry, project, store-access, storefront, support, and business information during Shopify service engagements.

As of August 24, 2026. This Shopify Services Privacy Policy applies to consulting, theme customization, development, migration, launch, and ongoing-support services provided by HansonCore, LLC DBA Five Acre Code ("Five Acre Code," "we," "us," or "our").

The general Five Acre Code Privacy Policy covers the public website. Cart Marshal and B2B Marshal have separate app-specific privacy policies. A signed data-processing agreement can provide additional terms for a particular Client.

Information we receive

Depending on the inquiry and engagement, we can receive:

  • Contact name, business email, company, role, Shopify shop domain, request type, message, desired timing, and engagement context.
  • Proposals, statements of work, approvals, billing contacts, invoice/payment status, tax information, and business correspondence.
  • Shopify store, organization, plan, theme, market, catalog, product, collection, content, app, integration, domain, checkout/accounts, B2B, and configuration information needed for the work.
  • Authorized Shopify admin identity and activity visible through collaborator, staff, Theme Access, app, or other approved access.
  • Theme files, source repositories, designs, brand assets, copy, translations, metafield/metaobject definitions, app configuration, logs, exports, screenshots, recordings, and test evidence supplied for the project.
  • Support requests, reproduction steps, browser/device information, affected URLs, request IDs, error output, recent changes, and project history.

Storefront and Shopify-admin surfaces can display customer, order, address, company, or other personal data even when that data is not the purpose of the service. We minimize access and avoid copying production personal data unless it is necessary for the agreed work.

Sources of information

We receive information directly from the Client and its representatives; from Shopify and other systems the Client authorizes us to access; from Client-selected themes, apps, repositories, and providers; from project communications and support activity; and automatically from fiveacrecode.com requests, security tools, and form processing as described in the general Privacy Policy.

How we use information

We use information to evaluate requests, prepare scopes, communicate, deliver and test services, maintain project records, invoice, provide support, protect systems, investigate incidents, comply with law, and enforce agreements.

We do not sell personal information. We do not use Client customer data for advertising, data brokerage, cross-client profiling, lending, underwriting, or an unrelated product dataset.

Client and Five Acre Code roles

The Client determines the purpose and lawful basis for personal data in its Shopify store and instructions given to Five Acre Code. For personal data processed only to deliver the Client's instructions, Five Acre Code generally acts as a service provider or processor. Five Acre Code acts independently for its own business contacts, contracting, security, billing, legal, and abuse-prevention records.

The Client must provide required customer, employee, or user notices and must not instruct Five Acre Code to process data unlawfully. We may decline access to or request removal of data that is unnecessary for the engagement.

Store access and credentials

Use Shopify collaborator accounts, appropriately scoped staff access, Theme Access, or another approved least-privilege method. Do not send owner passwords, payment credentials, customer passwords, API secrets, or active access tokens through the public contact form or ordinary support email.

Credentials are used only for the authorized engagement, restricted to personnel who need them, and revoked, returned, or deleted when no longer required, subject to security and legal needs. More detail is published in Store Access and Client Responsibilities.

Sharing and service providers

We disclose information only as needed to deliver, secure, communicate about, bill for, or support the services; follow Client instructions; comply with law; protect rights and safety; investigate abuse; or complete a business transaction subject to appropriate safeguards.

Current provider categories and purposes are listed in the Data Processing Addendum. Client-selected themes, apps, integrations, repositories, communication tools, or providers remain governed by their own terms and the Client's configuration.

Retention and deletion

Inquiry records are retained while evaluating the request and for a reasonable business follow-up period. Project records, agreements, approvals, invoices, communications, source changes, deliverables, testing evidence, and support history are retained while needed to deliver and support the engagement and for reasonable security, audit, tax, warranty, legal, and dispute-resolution periods.

Temporary exports, theme copies, logs, screenshots, and credentials are deleted, returned, or access-revoked when no longer needed for the agreed work, unless the written agreement or a legal/security need requires a different period. Source repositories and completed deliverables follow the handoff and retention terms in the written scope.

Provider backups and security records can persist for a limited period under provider retention processes. We do not restore deleted Client data to ordinary project systems merely to resume unrelated use.

To request deletion or return of eligible project data, contact support@fiveacrecode.com. We may verify identity and authority, and some records can be retained where required for contracts, billing, security, law, or legal claims.

International processing

Five Acre Code is based in the United States. Information can be processed in the United States and in other locations where Shopify, website, communications, source-control, hosting, or Client-selected providers operate. Where required, the parties can enter additional transfer terms.

Security

We use administrative, technical, and organizational safeguards appropriate to the engagement, including least-privilege access, Shopify-native access methods, multi-factor authentication where available, controlled development themes, source-control practices, secure credential handling, minimized production data, and incident response.

No service can guarantee perfect security. Review the Services Security Policy and promptly report suspected unauthorized access.

Rights and requests

Depending on location and role, individuals can have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. Five Acre Code does not sell personal information or share it for cross-context behavioral advertising.

Requests can be sent to support@fiveacrecode.com. When the Client controls the relevant store data, we can direct the request to the Client or assist under the applicable agreement.

We will not discriminate against an individual for making a privacy request. A request can be limited or denied when permitted by law, including when we cannot reasonably verify identity or authority, the Client controls the relevant data, or an exception applies.

Children

These services are offered to businesses and authorized business users, not children. We do not knowingly collect children's personal information through Shopify service engagements.

Changes

We can update this policy to reflect service, legal, security, or provider changes. The date above identifies the published version. Material project-specific changes will be handled under the applicable agreement where required.

Contact

Five Acre Code
HansonCore, LLC
127 Cochran Poole Rd
Lucedale, MS 39452
support@fiveacrecode.com