Last updated: 15 September 2026.
What this page covers
This notice covers Climate Counts, our app for Shopify shops. It sits alongside our main privacy notice, which covers the website, our carbon calculators and getting in touch with us.
If you run a shop that uses Climate Counts, this page is about you and about your orders. If you have bought something from a shop that uses it, the short answer is in the next section.
If you bought something from a shop that uses this app
We hold your order number and the money on it. We hold nothing that names you.
The message Shopify sends us about your order does carry your name and your address. The app never reads those fields out of it, never stores them and never writes them to a log. The message itself is gone the moment the app has finished with it.
What we keep is the order number Shopify gave your purchase, the amounts on it, the currency and exchange rate, and whether any of it was later refunded.
That order number means nothing on its own. Shopify can match it back to you, and so, in theory, could we, because the shop has given us permission to read its orders. We do not, and nothing in the app is built to. We say it plainly here because “we hold nothing about you” would be a tidier sentence and a slightly untrue one.
We do not track you, advertise to you, or make any decision about you. The only thing the app works out is how much the shop owes towards carbon credits. Nothing it calculates affects you.
We never sell or share your information, and there is no third party to opt out of.
If you want a copy of what we hold, or you want us to erase you, ask the shop. Shopify passes the request to us with your order numbers on it. Here is what each one does.
- A request for a copy. We build the answer and it goes to the shop, not to you, because the shop is the one who holds your account. It says, for each of your order numbers, how many entries we hold, what they come to, and which month they sit in. Shopify allows 30 days. A person at C Level sends it, because the app itself cannot send an email.
- A request to erase you. We delete our record of the messages Shopify sent us about those orders, their entries in the shop’s list of recent orders, and any refund on them that we had not yet finished working out. We also remove your order numbers from the figures that remain, so what is left is an amount and a month and nothing that can be matched to you. We tell the shop what we did.
If you run a shop that uses the app
Who we are. C Level Earth Limited, company number 04105851, registered in England and Wales. Our registered office is The Innovation Centre, University of Sussex, Science Park Square, Falmer, Brighton, BN1 9SB. You can reach us about this app at [email protected], by phone on +44 (0)1273 234666, or by post at that address.
Our data protection contact for this app is Piers Moore-Ede, at that email address. For anything outside the app, our general address is [email protected], which is the one on our main privacy notice.
What we get from Shopify. One permission, called read_orders, and nothing else. Shopify’s messages about your paid orders, refunds and cancellations carry your customers’ names, email addresses, phone numbers and addresses. We read none of those. What we read is the order’s identifier, the money on it, the currency, and when it happened.
What we ask Shopify. These things, and nothing else. When you install, and again each time you save your settings, we ask which currency your shop sells in, whether it is a development store, which country your shop is billed from and which currency Shopify bills it in. Where your store can be charged, each time you save your settings and when you approve charging, we also ask for your shop’s name and billing address, including the company name if you have given Shopify one, so we can put them on your VAT invoices. When you approve charging, we ask Shopify to set up the charge you approve, and each month we tell Shopify how much to charge. When you save your settings, we also store your percentage on your shop, so the Climate Counts block on your storefront can show it. Once a day we ask whether the messages we asked for are still switched on. If they have stopped, your sales have stopped counting and somebody here needs to know. And while you are choosing how much to give, we ask what your last thirty days of paid orders came to, so we can show you what your choice would have cost. That last question does read your orders. It asks for the amounts on them and nothing else, it asks for nothing that names a customer, and it keeps nothing.
What we ask anybody else. To convert an order that is not in pounds, we look up the European Central Bank’s exchange rate for that day. The lookup sends a currency code and a date, and nothing about you or your customers.
What we store. Your shop’s address, the currency it sells in, the country it is billed from and the currency it is billed in, your shop’s name and billing address and the VAT number you give us in Settings, if you give one, which we use for your VAT invoices, the charging approval and each monthly charge, your Shopify order identifiers and your own order numbers (such as #1001), the event identifiers Shopify sends, the amounts, the currency and exchange rate, which version of our calculation produced a figure, the resulting entry in your account, and the Shopify user who accepted the merchant terms, with the date. Nothing that identifies one of your customers.
What we do with it. We work out one figure for each order: your eligible sales, after discounts and excluding tax, shipping, duties, tips and gift cards. Your own rule then decides how much of that goes towards buying and retiring carbon credits. We use it for nothing else. We do not use it to sell to you or to anybody else, and we do not sell it or share it for advertising.
What you tell us directly. Your company name, the name and address of whoever we deal with, and anything you send us in an email or a support message.
Who else holds it. Cloudflare hosts the app, its database and our run log. Brevo sends alert emails to C Level staff, which name a shop and hold no customer names or contact details. Nobody else. Shopify holds the underlying order data as your own platform.
Where it sits. The database is set to store its data in the European Union, using Cloudflare’s EU jurisdiction setting, which cannot be switched off afterwards. There is one copy of it. The app itself runs on Cloudflare’s network, which means the moment of calculation happens at whichever of Cloudflare’s machines is nearest the order, and that may be outside Europe. The order message is never written down there. Only the resulting figures go to the database.
How long we keep it. Once a store approves charging, C Level keeps that store’s accounting records for six years after the month they belong to, because UK VAT law requires it. They hold the store’s details, the monthly totals, the charges and the credits retired for it. They hold no customer names, contact details or order numbers. A store that never approves charging has no accounting record.
- You remove the app. We delete your Shopify access token straight away, because it has no use after that. Shopify then asks us to erase your shop, about 48 hours later, and we delete everything this app holds for it. Take your own copy before you remove the app if you want one. The only exception is information we must keep to establish, exercise or defend a legal claim.
- One of your customers asks to be erased. We delete our record of the messages about their orders and remove their order numbers from the figures that remain.
- On a timer. The list of recent orders on your figures page is deleted after 90 days.
Before charging begins, this will change. Records genuinely needed for invoices, tax and legal duties will then be kept for the period the law requires, and we will update this page first.
How it is protected.
- Everything travels over an encrypted connection.
- Every message we receive from Shopify is checked with a signature before we act on it, so a message that did not come from Shopify is refused.
- Your screens inside Shopify need a token that Shopify itself issues. Knowing a shop address opens nothing.
- Our own operations pages need a separate secret. If that secret is not set, they refuse everybody, including us.
- Our secrets are held in Cloudflare’s secret store and never in our code.
- Cloudflare encrypts what it stores. We add no encryption of our own, so your Shopify access token sits in the database in the form Shopify gave it to us. It is now a key that expires, and the app renews it rather than holding one that never runs out. It is the same key the thirty-day totals are read with, described under “What we ask Shopify” above, so it does read your orders, for the amounts on them. It is used for those two things and nothing else. We delete it the moment you remove the app.
- Our test systems never hold your real order data.
- Every time somebody at C Level opens the app’s operations pages, that access is recorded and the record is kept for 12 months.
What you can ask us to do. See a copy of what we hold, correct it, delete it, or take it elsewhere. Ask, and we will do it. If we get something wrong, tell us and we will put it right. If you are still not happy you can complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
If something goes wrong. If data is lost or reached by somebody who should not have it, we will tell you and, where the law requires it, the Information Commissioner’s Office. We have no automatic alarm that would tell us, so we would learn of it from Cloudflare, from Shopify or from you. Write to us at the address above, for the attention of Piers Moore-Ede.
If we change this page. We will update it and change the date at the top.