APPIFY CREATIONS

Privacy policy

Effective August 28, 2026

This policy explains how Appify COD & Upsell (“the App”), provided by Appify Creations, handles information when a Shopify merchant installs or uses the App.

Information we process

The App receives the merchant’s Shopify store domain, installation authorization, granted scopes, and technical session information needed to authenticate the merchant and provide the service. Shopify session records can include limited staff-account identifiers, such as a user ID, name, email address, locale, and account role. The App does not collect buyer names, addresses, contact details, payment credentials, or order contents.

If a merchant contacts support, we process the email address, store identifier, problem description, and any screenshot the merchant chooses to send. Merchants are asked not to include passwords, payment credentials, or customer personal data.

How information is used

We use installation information only to authenticate the store, display the embedded administration interface, save the merchant’s COD payment customization in Shopify, display the threshold message, prevent abuse, and troubleshoot service errors. The COD minimum is stored in Shopify app data for the merchant’s store.

Shopify and service providers

Checkout, cart, payment-method, and order processing remain hosted by Shopify. The App’s web service is hosted by Fly.io. These providers process technical data under their own privacy and security terms. Support correspondence is processed by our email provider. Information may be processed in countries other than the merchant’s country, subject to appropriate legal safeguards.

Retention and deletion

Installation sessions are retained while the App is installed and are deleted when Shopify notifies us that the App was uninstalled or that the shop must be redacted. Shopify’s mandatory privacy webhooks are authenticated before any request is handled. Support correspondence is retained only as long as reasonably needed to resolve the request, maintain security records, or meet legal obligations, then deleted through routine account cleanup.

Your choices and rights

Depending on applicable law, a merchant may request access, correction, deletion, restriction, portability, or objection. A merchant may also uninstall the App at any time from Shopify Admin. Because the App does not retain customer data, customer export or deletion requests normally contain no App-held customer records.

Security and changes

We use access controls, HTTPS, signed Shopify requests, and data minimization to protect the service. We may update this policy when the App or legal requirements change; the effective date above will be revised.

Contact

Privacy and support requests can be sent to creationsappify@gmail.com.