Cursors by Codeja

Privacy Policy

Last updated 3 September 2026

Cursors by Codeja lets a merchant choose a mouse cursor for their storefront. It is built so that it never needs access to store data, and this policy describes the little that it does handle.

What the app requests from Shopify

No access scopes at all. The app requests zero Shopify API permissions. It cannot read or write your products, orders, customers, inventory, discounts, or any other store data, because it was never granted permission to do so. You can confirm this on the install screen: the only access listed is the standard store-owner identity that every embedded app receives.

What the app stores

Only what is needed to keep you signed in: your store’s myshopify.com domain and the session token Shopify issues when you install the app. These live in the app’s own database and are used for nothing but authenticating your admin session.

Your chosen cursor and its motion are not stored on our servers. They are saved to your own store as an app metafield, held by Shopify, and read directly by your theme.

What your shoppers’ browsers send us

Nothing. The cursor is delivered as a small block of CSS inside your theme, with the images embedded in it. A visitor’s browser makes no request to our servers, so we set no cookies, run no scripts, and receive no visitor data — no IP addresses, no page views, no analytics, no tracking of any kind.

Who we share data with

No one. We do not sell, rent, or share data with third parties. There are no advertising networks, analytics vendors, or data brokers involved in this app.

Where the data lives

The app runs on Fly.io in the United States. Session records are stored on an encrypted volume there.

Deletion and retention

When you uninstall the app, its session records for your store are deleted. The app also honours Shopify’s mandatory privacy webhooks (customers/data_request, customers/redact and shop/redact). Because the app holds no customer information, the two customer webhooks have nothing to return or erase; shop/redact deletes everything held for the shop.

The cursor metafield belongs to your store. Removing the app removes the theme embed that reads it, so your storefront returns to its default cursor.

Your rights

You may request a copy or deletion of anything we hold for your store at any time by emailing support@codejainfotech.com. Given the above, that is your store domain and a session token.

Changes

If this policy changes materially, the date at the top of this page changes with it.


Questions? Email support@codejainfotech.com.