Shoplix privacy policy
Operator: Rastova Logic, Room 4, Apt 11, Floor 5, Building 1, Al Thamania Emarat Project, Nasr City, Cairo, Egypt. Contact: support@shoplix.ai. Last change: 2026-10-11.
Shoplix is a Shopify app. It builds a native mobile shopping app for a merchant's store and sends push notifications to shoppers who installed that app. This policy says what personal data Shoplix processes, why, for how long, who else touches it, and what rights people have. It is written for two readers: the merchant who installs Shoplix, and the shopper who uses a merchant's app.
1. Roles
For a merchant's store data and their shoppers' data, the merchant is the controller and Shoplix is the processor. Shoplix processes that data only to provide the app to the merchant and only on the merchant's instructions, which are the merchant agreement and the settings the merchant chooses in the Shoplix dashboard.
For the merchant's own account with Shoplix (the people who sign in to the dashboard), Shoplix is the controller.
2. What Shoplix processes
2.1 Store data read from Shopify
Shoplix reads the merchant's catalog through Shopify: products, collections, prices, media, markets, languages and publication state. This is the content of the mobile app. It is not personal data.
2.2 Order, fulfillment and checkout data (protected customer data)
To send the three notifications below, Shoplix receives order, fulfillment and checkout events from Shopify by webhook, and keeps only these fields:
| What | Fields | Why |
|---|---|---|
| An order placed through the merchant's app | order id, order number, cart token, source and app id, test flag, creation time, currency, total, and the shopper's first name | to confirm the order to the device that placed it, and to greet the shopper by first name |
| A fulfillment of such an order | order id, fulfillment id, status, shipment status, carrier, tracking number, tracking link, time | to tell the shopper the parcel shipped, is out for delivery, or was delivered |
| A checkout started in the app | checkout token, cart token, times, completion time, the checkout's recovery link, source | to remind the shopper of a checkout they did not finish, and to cancel that reminder when they did |
The first name is the only field Shopify classifies as protected customer data at Level 2 that Shoplix stores. It is stored in one column of one table, used only inside the text of that shopper's own order confirmation and shipping notifications, and never for anything else. The last name is never requested.
Shoplix has asked Shopify for access to four protected fields: name, email, phone and address. Email, phone and address are requested for features that do not exist yet (email campaigns, a messaging channel, country-based content). Until those features exist and this policy names them, Shoplix does not receive, read or store email, phone or address from any order, checkout or customer. Shoplix asks Shopify to send only the fields listed above.
Shoplix does not read line items, notes, billing or shipping addresses, IP addresses or browser details from any order.
2.3 Device data from the merchant's app
When a shopper allows notifications, the app registers the device with Shoplix: an installation identifier created by the app, the device platform, the app identifier, the push token issued by Apple or Google, and the app's language. When the shopper opens or completes a checkout in the app, the app reports the cart token and, on completion, the order reference, so Shoplix can match the order to the device. None of these hold the shopper's name or contact details.
Shoplix records each notification it sends: which flow and step, which device, which order or checkout, the template version and language, and whether it was sent and tapped. It never keeps the rendered text of a notification.
The app also reports diagnostic counters about itself. Shoppers can turn diagnostics off in the app's account screen. Turning them off does not stop notifications; the device's notification permission does.
2.4 Merchant account data
To operate the dashboard Shoplix processes the names and email addresses of the merchant's staff who sign in, their password (stored as a hash), their sessions, invitations they send, and, for staff who sign in from the Shopify admin, the link between their Shopify staff account and their Shoplix account.
3. Why, and on what basis
- To provide the service the merchant installed: building and serving the app, sending the three notifications. Basis: the merchant agreement (contract) and, for the merchant's shoppers, the merchant's own basis as controller.
- Notifications reach a device only after the shopper allowed them in the device's operating system. Revoking that permission stops every notification. There is no other channel: Shoplix never emails, calls or messages a shopper.
- Security, fraud prevention and legal duties: keeping the delivery trail of Shopify webhooks and the record of privacy demands. Basis: legal obligation and legitimate interest.
Shoplix does not sell personal data, does not share it for advertising, does not profile shoppers, and makes no automated decision with legal or similar effect about anyone.
4. How long
| Data | Kept for |
|---|---|
| Order data and its fulfillments, notifications and matching record | 90 days after the order was created; 24 hours if the order was not placed through the app |
| Checkout data | 24 hours if no device matches; 7 days from the last activity when one does; then with the order |
| Device registration | erased as soon as the token is invalid, the permission is revoked, the device has been silent for 90 days, or the app was reinstalled; the record is removed 30 days after that |
| Notification counts per store | kept, as totals with no personal data |
| Record of a privacy demand from Shopify | kept, as proof it was answered; it holds order references, never contact details |
| Merchant account data | until the account is deleted or the store's data is erased |
| Everything about a store | erased 48 hours after the merchant uninstalls Shoplix, when Shopify sends the erasure demand |
Deletion runs automatically every hour. A deleted row can remain in an encrypted platform backup for up to three months more; backups are restored only to recover from failure, and a restore is followed by the same deletion.
5. Where, and who else
Shoplix runs on Railway (hosting; the services and the database are in Railway's EU West region, Amsterdam; Railway itself is a US company operating under the EU-US Data Privacy Framework, and its own sub-processors are listed on its trust center). Push notifications are delivered by Apple Push Notification service and Firebase Cloud Messaging (Google); they receive the device token and the notification text and nothing else. Merchant media is stored on Cloudflare R2. Emails to merchant staff (account verification, invitations, password reset) are sent by Resend. Shopify is the source of store data and the recipient of nothing beyond what its API requires.
These are Shoplix's sub-processors. A new one is announced to merchants thirty days before it processes any data, and merchants may object as set out in the merchant agreement.
6. Security
Data is encrypted in transit and at rest. Shopify credentials are additionally encrypted in the application. Access to production systems is limited to the Shoplix team with two-factor authentication, human access to the database is logged, and a written incident response policy commits Shoplix to notify Shopify within twenty-four hours, and affected merchants without undue delay, of any breach of merchant data. The controls are described in Shoplix's data protection documentation, available to merchants on request.
7. Rights
Shoppers exercise their rights (access, correction, erasure, objection, portability) with the merchant whose store they bought from. Shopify passes the merchant's requests to Shoplix as privacy webhooks: on a customer data request Shoplix gives the merchant a machine-readable copy of the rows it holds for that customer; on a customer erasure request Shoplix deletes them and records the count; on a store erasure request Shoplix erases the store's data. Revoking notification permission on the device stops notifications at once.
Merchant staff can change their name, email and password in the dashboard, sign out of every session, and ask for their account to be deleted at support@shoplix.ai.
Anyone may complain to their supervisory authority.
8. Children
The merchant's app is the merchant's store; Shoplix does not knowingly process data about children and holds no age data.
9. Changes
Changes are posted at this address with the date. A change that widens the data processed, adds a protected field or a sub-processor is announced to merchants before it takes effect.