1. Roles
This policy explains how Profiter ("we") processes personal data on behalf of merchants who install the app. The merchant is the data controller; we are the data processor. A Data Processing Addendum is available on request.
2. Data we process
- Shopper leads you collect: email, optional phone, optional first name, and consent state.
- Behavioural events: a pseudonymous visitor id, campaign and experiment ids, event names and timestamps. We do not store payment data or raw personal data in logs.
- Order attribution: order id, order total and discount code — to connect a purchase back to a spin.
- Shop / merchant data: shop domain, contact email, and the access tokens needed to operate, stored server-side and encrypted at rest where applicable.
3. How we use it
To render campaigns, allocate rewards, measure incremental profit and provide analytics. We do not sell personal data.
4. Consent
Consent boxes are never pre-ticked. Where required we support double opt-in before an email is added to a marketing list.
5. Data minimization & retention
We store the minimum needed. Visitor identifiers are pseudonymous and, where
used as keys, hashed. Retention period: [review].
6. Sub-processors
Hosting, database, queue, error tracking, and any email/SMS provider you
connect (Klaviyo, Mailchimp, Omnisend, WhatsApp, Google Sheets). A current
list is available on request. [review]
7. Data subject rights
Access, rectification, deletion and portability are supported through
Shopify's mandatory webhooks: customers/data_request,
customers/redact and shop/redact. These perform real
export and deletion.
8. International transfers
Transfer mechanism (e.g. Standard Contractual Clauses): [review].
9. Security
Access tokens are never exposed to the browser. Storefront traffic is authenticated via signed Shopify App Proxy requests. Secrets are encrypted at rest.