Privacy Policy
Draft — five items to complete, then legal review
This is a researched template, not finished legal copy. It was written against Shopify's published requirements for App Store apps, the EU/UK GDPR, and the CCPA as amended by the CPRA. It has not been reviewed by a lawyer, and it must be before Priceflag accepts its first merchant.
Counsel should also confirm the legal bases in section 5, whether an EU or UK Article 27 representative is required, and whether analytics cookies need consent in the markets Priceflag sells into.
Five facts cannot be determined from research. They are marked like this in the text below and listed here:
- [COMPANY LEGAL NAME] — the registered entity that acts as controller and processor.
- [REGISTERED ADDRESS] — the postal address for privacy correspondence.
- [HOME JURISDICTION] — where the entity is established, which sets the lead supervisory authority.
- [HOSTING PROVIDER AND REGION] — the actual cloud vendor and the region data sits in.
- [EFFECTIVE DATE] — the date this policy takes effect.
1. Who we are and what this covers
Priceflag is a pricing tool for Shopify merchants. It forecasts the likely effect of a price change, releases that change to a growing share of your store's traffic in stages, watches profit-per-visitor against a guardrail you set, and reverts the price automatically if the guardrail is breached.
This policy covers the Priceflag Shopify app, the Priceflag web application, and the priceflag.com marketing site. The company behind them is [COMPANY LEGAL NAME], established in [HOME JURISDICTION] at [REGISTERED ADDRESS].
In this policy, "you" means the merchant, or the person using Priceflag on a merchant's behalf. "Your customers" means the shoppers who buy from your store. Priceflag is a business tool. We do not build shopper profiles, we do not advertise to your customers, and we do not sell data to anyone.
2. Two different roles
Which privacy rules apply to a given piece of data depends on whose data it is, so it is worth separating the two cases up front.
- Your data — we are the controller. Your name, work email, the store you connect, your billing details, and how you use the app. We decide why and how that is processed, so under the GDPR we are the controller, and under the CCPA we are a business.
- Your store's data — we are the processor. Products, prices, inventory, orders, and the limited personal data about your customers that sits inside order records. That data is yours. We handle it on your documented instructions to run the features you have switched on. Under the GDPR you are the controller and we are the processor; under the CCPA we act as a service provider.
Shopify itself is a separate party with its own agreements with you, including Shopify's own data processing addendum. Nothing in this policy changes those.
3. What we collect
Account and billing information
- Your name, work email address, and the identifier used to sign you in.
- The Shopify store domain or domains you connect, and the role each teammate holds in your workspace.
- Subscription and billing records. Shopify's App Store rules require app charges to run through Shopify's billing, so your payment card is handled by Shopify and never reaches us.
Store data read from Shopify
- Products and variants — titles, SKUs, options, inventory levels, cost of goods where you have recorded it, and current and historical prices.
- Orders and line items — quantities, prices paid, discounts, currency, timestamps, and the channel the order came through. These are the inputs to every forecast and every guardrail check.
- Store configuration — currency, markets, price lists, and other settings that change how a price would apply.
- Traffic and session counts where Shopify exposes them, because profit-per-visitor cannot be computed without a visitor count.
Protected customer data
Shopify classifies order data as protected customer data, because an order relates to an identifiable person even when no name is attached. Shopify treats name, address, email and phone as a further tier — protected customer fields — that an app has to request individually and justify.
Priceflag's arithmetic works on quantities, prices, margins and counts. It does not need to know who bought anything. Our design intent is therefore to read order data without requesting the protected customer fields. The scopes the app actually asks for are shown to you on Shopify's install screen before you approve anything, and that screen — not this page — is the authoritative record of what we can see.
Usage and technical data
- The experiments you configure: candidate prices, traffic percentages, stage schedules, guardrail thresholds, and every rollout and rollback we execute.
- Product analytics — which screens you open and which features you use — so we can tell which parts of the tool work.
- Technical logs: IP address, browser and device type, coarse location derived from IP, and error traces.
- Support correspondence, including anything you send us by email or in-app chat.
4. What we do with it
- Run the service: forecasting, staged rollouts, profit-per-visitor calculation, and guardrail rollbacks.
- Write price changes back to your store, only for the products and experiments you have enrolled.
- Notify you when a guardrail is breached, a rollback fires, or an experiment ends.
- Bill you through Shopify, keep account records, and prevent fraud and abuse.
- Debug problems, keep the service secure and available, and improve forecast quality for your store.
- Answer support requests and send service notices. Marketing email is separate and goes only to people who asked for it; every marketing message carries an unsubscribe link.
We do not use one merchant's store data to produce forecasts for a different merchant, and we do not train shared models on your data, unless you separately and explicitly opt in. We do not use protected customer data for advertising, profiling, or anything other than delivering the features you switched on — Shopify's API terms forbid it, and so does this policy.
5. Legal bases
Where the GDPR or UK GDPR applies to data we control, we rely on the following bases.
- Performance of a contract — creating your account, running experiments you configure, billing, and support.
- Legitimate interests — keeping the service secure, preventing abuse, debugging, and understanding aggregate product usage. We weigh those interests against your rights and you can object at any time.
- Consent — marketing email and any non-essential cookies. You can withdraw it whenever you like, without affecting processing already carried out.
- Legal obligation — tax, accounting and responses to lawful requests.
For data inside your store, the lawful basis is yours to determine as controller. We process it on your instructions.
6. Shopify access and price writes
Priceflag connects through Shopify's standard OAuth install flow. You see the exact permissions before you grant them, and you can revoke them at any time from your Shopify admin. Shopify requires apps to ask only for the access they genuinely need, and we ask on that basis.
- Write access is used to set a price on a product you enrolled in an experiment, and to restore the prior price during a rollback. Nothing else.
- We do not modify orders, customers, fulfilment, discounts, or any field outside the pricing fields an experiment touches.
- Every write is recorded with a timestamp, the experiment that triggered it, and the before and after values. That log is visible to you in the app.
- Uninstalling the app revokes our access instantly. Whatever price is live at that moment stays live — with write access gone we cannot roll it back, so settle your prices before you uninstall.
7. Shopify's privacy webhooks
Every app in the Shopify App Store has to answer three mandatory compliance webhooks. We verify the HMAC signature on each one and reject anything that fails verification. Here is what each does and what we do about it.
- customers/data_request — one of your customers has asked you for the data held about them. Shopify forwards the request; we acknowledge it and return what we hold to you, the merchant, within the 30 days Shopify allows. You answer your customer; we supply you the material.
- customers/redact — you have asked, on a customer's behalf, that their data be erased. Shopify sends this 10 days after the request if that customer has not ordered in six months, and otherwise withholds it until six months have passed. We delete or irreversibly redact the identified customer and order records.
- shop/redact — sent 48 hours after you uninstall the app. We erase the data held for that shop.
Separately, Shopify's API License and Terms of Use require an app to delete every copy of a merchant's data within 30 days of uninstall or termination, except where the law requires us to keep something. We treat that as a hard obligation, not an aspiration.
8. Who else sees it
We use a small number of vendors to run the service. Each is bound by contract to process data only on our instructions and only to provide their service to us, with terms that meet Article 28 of the GDPR.
- Shopify — the platform your store runs on, the source of the data we read, and the channel through which app subscriptions are billed. Your relationship with Shopify is governed by your own agreements with them.
- Cloud hosting and databases — [HOSTING PROVIDER AND REGION].
- Operational vendors — the providers we use for transactional email, error monitoring, product analytics and support. We will name every one of them, and tell you the country each processes in, on request at the address in section 15. We will not add a sub-processor that touches store data without updating that list.
Beyond those, we disclose data only where the law compels it, to establish or defend legal claims, to protect the rights and safety of our users or the public, or in a merger, acquisition or sale of assets — in which case we will tell you before your data becomes subject to a different policy, so you can leave first.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We have never done so.
9. How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for.
- Store, product and order data — for as long as the app is installed and the data is needed to run and evaluate your experiments. After uninstall, deleted within the 30 days Shopify's API terms require, prompted by the shop/redact webhook.
- Account records — while your account is open, then deleted after a short wind-down window that lets you change your mind and reinstall.
- Experiment history and price-change logs — kept while you are a customer so you have an auditable record of what changed and when. Exportable at any time, and removed with the rest of your data when you leave.
- Billing and tax records — for the period tax and company law requires, which in most jurisdictions runs to several years and overrides a deletion request.
- Technical logs and product analytics — for a limited operational period, then deleted or aggregated past the point of re-identification. We will tell you the current schedule if you ask.
Backups expire on their own rotation, so data removed from live systems can persist in backups for a short period afterwards before being overwritten.
10. Security
Shopify's protected customer data requirements set a floor that every app handling order data has to meet: encryption in transit and at rest, encrypted backups, defined retention periods, separated test and production environments, staff access limited to those who need it, logging of access to protected customer data, strong authentication on staff accounts, and a written incident response process. Those are the controls we are required to operate and are committed to operating.
We hold no third-party security certification. We are not SOC 2 audited and not ISO 27001 certified, and we will not claim either until it is true. If a certification matters to your procurement process, ask us where we actually stand before you install.
No system is perfectly secure. If a breach affects personal data we hold, we will notify you without undue delay so you can meet your own obligations as controller, and we will notify regulators where the law requires it — under the GDPR that means within 72 hours of becoming aware, where the breach is notifiable.
11. International transfers
Our infrastructure runs in [HOSTING PROVIDER AND REGION], and the company is established in [HOME JURISDICTION]. If you or your customers are elsewhere, personal data will be transferred to and processed in those places, where privacy law may give weaker protection than your own.
For transfers of EEA, UK or Swiss personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where UK data is involved, plus a transfer risk assessment and supplementary technical measures. You can request a copy of the clauses we rely on.
12. Your rights
If the GDPR or UK GDPR applies to you, you have the right to access the personal data we hold about you, correct it, delete it, receive it in a portable machine-readable format, restrict or object to processing, object to direct marketing at any time, and withdraw consent you previously gave.
- Much of this is self-service: your data can be exported from the app, and uninstalling the Shopify app stops further collection immediately.
- For anything else, email hello@priceflag.com. We respond within one month, as the GDPR requires, and may extend by two further months for genuinely complex requests — we will tell you inside the first month if that happens. We may need to verify who you are first.
- If the request comes from one of your customers, it belongs to you: you are the controller of that data. Forward it and we will give you what you need to answer, or use Shopify's customers/data_request and customers/redact flows, which reach us automatically.
- You can complain to your data protection authority. If we are established in [HOME JURISDICTION], that authority is your lead supervisory authority, but you may also complain to the regulator where you live or work.
We will not discriminate against you, degrade your service, or charge you more for exercising any of these rights.
13. California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we have collected and where it came from, to access and delete it, to correct inaccuracies, to receive it in a portable form, and to limit the use of sensitive personal information. Since 2023 these rights cover personal information collected in a business-to-business context too, so they apply to you as a merchant, not only to consumers.
- Categories collected. Identifiers (name, work email, IP address), commercial information (subscription and transaction records), and internet activity (how you use the app). Sections 3 and 4 describe the sources and the purposes.
- Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of and no "Do Not Sell or Share My Personal Information" link to click. If that ever changes, we will say so here first and provide the mechanism the law requires.
- Sensitive personal information. We do not collect it for the purposes that would trigger the right to limit its use.
- Store data. For the data inside your Shopify store we act as a service provider, processing it only for the business purpose you engaged us for, and never retaining, using or disclosing it for our own purposes.
- Making a request. Email hello@priceflag.com. We confirm within 10 business days and respond within 45 days, extendable once by a further 45 days where the request is complex. An authorised agent may act for you with proof of authority.
14. Cookies
The marketing site and the app use a small number of cookies and similar technologies.
- Strictly necessary — keeping you signed in, remembering your workspace, and protecting against cross-site request forgery. These cannot be switched off, and no consent regime requires them to be.
- Analytics — counting visits and seeing which features get used, so we can prioritise. Where consent is legally required for these, we will ask before setting them.
We do not use advertising cookies, cross-site tracking pixels, or any cookie that follows you off our own properties. You can block or clear cookies in your browser; the app will not function properly without the necessary ones.
15. Children
Priceflag is a business tool sold to merchants. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us data, write to us and we will delete it.
16. Changes and contact
We will update this policy as the product changes and as the law does. The date at the top always reflects the current version. For changes that materially affect how we handle your data we will give notice by email or in the app before they take effect, and where the law requires consent we will ask for it rather than assume it.
Questions, requests, or anything on this page that looks wrong: hello@priceflag.com. We read every message that arrives there.
Postal mail: [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. If you need a signed data processing agreement, a copy of our Standard Contractual Clauses, or the current sub-processor list, ask at the same address.