Privacy Policy

Aero LMS · Last updated: 29 July 2026

Aero LMS ("Aero", "we", "us") is a Shopify application that lets merchants sell and deliver online training on their Shopify store. This policy explains what we collect, why, and how it is handled when a merchant installs Aero or a learner uses a Aero-powered store.

Information we collect

From merchants: the store domain, an API access token scoped to the permissions listed at install (products, orders, customers, publications), plan/billing status supplied by Shopify, and the settings the merchant configures inside the app. From learners (the merchant's customers): name, email address, Shopify customer ID, course enrollments, lesson progress, quiz attempts and scores, issued certificates, and — where the merchant uses team features — group membership and seat license assignments. We do not collect payment card details; checkout is handled entirely by Shopify.

How we use it

Solely to provide the service: enrolling buyers into purchased courses, tracking progress, grading quizzes, issuing and verifying certificates, sending course-related emails (enrollment confirmations, certificate notifications, expiry reminders, and messages the merchant's team manager composes), and showing merchants reporting about their own learners. We do not sell personal data, use it for advertising, or share it with third parties except the processors below.

Where data lives (processors)

Application data is stored on managed infrastructure operated by WP Engine (application database, USA), Cloudflare R2 (uploaded course media, SCORM packages, certificate PDFs and documents), and Render (application hosting). Emails are delivered via the merchant's own SMTP provider when configured, otherwise via our hosting provider's mail relay. Each processor is bound by its own data processing terms.

Certificate verification pages

Certificates include a QR code linking to a public verification page that shows the learner's name, the course title, issue/expiry dates and validity status. This is intentional — it is how employers and auditors verify a certificate — and exists only for certificates actually issued. Merchants who use the audit page feature additionally publish a page listing their team's certificate statuses at a URL only reachable via its unguessable code.

Retention & deletion

We honour Shopify's GDPR webhooks automatically: when a customer requests erasure, their learner records are deleted or anonymised; when a merchant uninstalls and Shopify issues the shop redaction request, the store's data is deleted. Merchants can also delete courses, reviews, documents and learners from inside the app. Certificate verification records may be retained where required to keep issued compliance certificates verifiable.

Your rights

Learners should direct access or deletion requests to the store they bought from (the merchant is the data controller; Aero is a processor). Merchants can contact us directly at support@aeroapp.org for any data request. We respond within 30 days.

Security

All traffic is encrypted in transit (TLS). API calls between Shopify, the app and the backend are authenticated with signed tokens and HMAC signatures. Access to production systems is limited to the Aero team.

Changes

We will update this page when the policy changes and note the date above. Material changes will be announced to merchants inside the app.

Aero LMS · https://aeroapp.org · support@aeroapp.org