Commonplace
Privacy policy
For the Commonplace HSA/FSA Letters app for Shopify. Last updated 6 August 2026.
The short version. This app reads your product catalogue so it knows which items may qualify for HSA/FSA spending. It does not read your customers, your orders, or anything about the people who shop with you. Health information is collected by Commonplace directly from the shopper, on Commonplace’s own platform, and is never shared with you or with Shopify.
Who we are
The app is operated by Commonplace Solutions Inc. Reach us at service@trycommonplace.com.
What the app accesses from your store
The app requests two permissions and no others:
- Read products. Product titles, types, prices, images and handles, so eligible items can be identified and reviewed.
- Write products. Used only to set eligibility markers on products you have approved, which is what makes the HSA/FSA badge appear on your storefront.
The app does not request access to customers, orders, checkouts, or any other protected customer data. It cannot read them.
What we store about your store
- Your myshopify.com domain and an access token, so the app can work
- Which products you have chosen to offer, and their approval status
- Your pricing choice and any amount you add
- Counts of how many letters were requested and issued
Health information, and why you never see it
When one of your customers asks for a Letter of Medical Necessity, they leave your store and complete a health questionnaire on Commonplace’s own platform. That information — their health conditions, date of birth, address, identifiers, and the letter itself — is collected by Commonplace as a healthcare provider, held on separate infrastructure, and governed by HIPAA.
It is never sent to your store, and never sent to Shopify. Through the app you see only a reference code, the product, and a status such as “with a clinician” or “letter issued”. Your customer’s name appears only where they have explicitly ticked a box asking us to share it with you so you can help with their order.
This is enforced by how the system is built, not by policy alone: the credential this app holds has no permission to read health data, and the interface it calls cannot return it.
Who else processes this data
- Shopify — hosts your store and delivers the app to you. Receives no health information.
- Stripe — processes the clinician review fee, and pays merchants who have chosen to add an amount. Stripe receives the payment amount and a reference code, never health information.
- DigitalOcean — hosts our infrastructure, under a Business Associate Agreement covering the systems that hold health data.
How long we keep things
Records tied to your store are deleted when you uninstall, except where we are required to keep them. A signed Letter of Medical Necessity is a medical record: it is retained for the period required by the clinician’s state licensing rules, and it is also the customer’s own evidence for their HSA/FSA administrator and for the IRS. Uninstalling the app does not delete a letter that has already been issued to your customer.
Deletion requests
Shopify sends us deletion requests on behalf of merchants and shoppers, and we act on them. Where a request covers a signed medical record we are legally required to retain, we delete the link between that record and your store, retain the clinical record itself under that legal obligation, and log the reason. We will always tell the person what was removed and what was kept, and why.
Your customers’ rights
Because Commonplace collects health information directly from the shopper, requests about that information are answered by us, not through you. Anyone can contact service@trycommonplace.com to ask what we hold about them.
Changes
If we change this policy in a way that affects what we collect or who receives it, we will tell installed merchants rather than only updating this page.