Privacy Policy

Last Orders: Business Hours — Last updated: September 26, 2026

Last Orders: Business Hours is a Shopify app that accepts orders only during a store's opening hours. Outside them it blocks checkout and shows a banner saying when ordering reopens, while leaving the storefront browsable so visitors can still look around. This policy explains what data this app touches and how it handles it.

What this app stores

Three things, and nothing else.

The merchant's own settings. The opening and closing time for each day of the week, which days the store is open at all, any holiday dates the store is closed on, and the wording shown to a shopper when checkout is locked. These are stored as app-owned metafields on the merchant's own Shopify shop, and a copy of the times needed to block checkout is stored on the checkout validation Shopify runs. These are business settings — opening hours and a sign in the window — not personal information about anybody.

A session for the merchant's store. Shopify's OAuth requires an installed app to hold a record identifying the store it is installed on: the shop's .myshopify.com domain, the access token Shopify issued for it, a refresh token, and the expiry of each. This is stored in this app's own database, on a server operated by Marquee Apps and hosted with DigitalOcean. It is what allows the app to read and write the settings above on the merchant's behalf, and it is used for nothing else.

That token is issued to the store rather than to a person, so no staff member's name, email address, or login is stored with it.

The access token and the refresh token are encrypted at rest: the app encrypts them with AES-256-GCM before they are written to its database and decrypts them only in memory, when it needs to act on the store's behalf. The key is kept on the server, apart from the database. Everything this app sends or receives travels over HTTPS (TLS), so the same data is encrypted in transit as well.

An install record for Marquee Apps. The shop's .myshopify.com domain, when the app was installed and uninstalled, whether it is a development or Shopify review store, and the name and number of the store's current subscription to this app. It is kept in the same database and used only for the notices described below. It is about the store, not a person. The database holds no other kind of record.

Logs. The server records which of the app's pages and notifications were requested — the address only, nothing after it — and which store they were for, and the web server records each visit's IP address and browser. The app never writes a token or anything a shopper entered to a log. All logs are deleted after about two weeks.

Notices to Marquee Apps, sent through Resend

When a store installs the app, subscribes, changes plan, cancels (or declines a charge, or lets one expire), or uninstalls, the app sends Marquee Apps a short email about it. These emails are sent through Resend (resend.com), our email provider, which delivers them on our behalf.

Each one contains the shop's .myshopify.com domain, the name, price and dates of the plan, the subscription number, and whether it is a test. It contains nothing about any person — no merchant or staff name, email address, or login — and nothing about shoppers. The emails go only to Marquee Apps; the store receives nothing from them.

Shopper information

This app does not collect, store, or process any personal information about shoppers. No names, email addresses, physical addresses, order contents, or payment details ever pass through it.

The banner a shopper sees is rendered by the merchant's own theme from the settings above. It makes no network requests of its own, so it does not report back that it was shown and it does not identify who saw it.

The check that blocks checkout runs inside Shopify, and is given only three things: which step of the checkout the buyer has reached, this app's own opening-hours settings, and the current date together with a set of true-or-false answers to "is it after this time?" and "is it before this time?" in the shop's own time zone. It is not given the contents of the cart, and it is not given anything about the person holding it.

What this app does not do

Data retention

The settings are stored on the merchant's own shop, and stay there until the merchant changes them or the app is uninstalled, at which point Shopify removes the app's metafields with it.

The session record described above is deleted when the merchant uninstalls the app. This app subscribes to Shopify's app-uninstalled notification for exactly that reason, so an uninstalled store's access token is not left sitting in a database.

The install record is kept while the app is installed, marked with the date when it is uninstalled, and deleted when Shopify sends the request to erase the shop's data, 48 hours after the app is uninstalled.

Data requests

This app subscribes to the three data-protection notifications Shopify requires of every app: a request for a customer's data, a request to erase a customer's data, and a request to erase a shop's data. Because the app holds no customer information, there is nothing to return or erase in response to the first two. A request to erase a shop's data removes that shop's session record and its install record.

A merchant who wants confirmation of what is held for their store, or who wants it removed, can write to the address below.

The merchant's own privacy policy

This page covers only what this app itself does. The store you are visiting has its own privacy policy covering how it collects and uses your personal information more broadly — that policy, not this one, governs your visit and any order you place.

Changes to this policy

If this policy changes, the updated version will be posted at this same address with a revised "Last updated" date above.

Contact

Questions about this policy or this app can be sent to Support@MarqueeApps.com.