Privacy Policy
Last updated: August 4, 2026
1. Introduction
Pay For Me ("App", "we", "us", or "our") is a Shopify application that enables gift purchase flows for merchants and their customers. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
2. Data We Collect
We collect the following categories of data to operate the App:
- Merchant data: Shopify store domain, session tokens, and billing information necessary to run the App.
- Gift intent data: Recipient email address, shipping address, selected product variants, order amounts, and gift card codes generated by Shopify.
- Customer and profile data: Shopify customer IDs, optional public profile content, links, images, and profile visibility settings.
- Email data: Inbound email content processed for gift card code extraction, transactional email delivery data, and customer email addresses used to deliver optional profile verification codes. Cross-store profile matching stores a keyed email hash and masked hint rather than the raw verified email.
3. How We Use Your Data
- Facilitating gift purchase flows between payers and recipients.
- Sending transactional emails (payment links, gift card codes, reminders) to the provided email addresses.
- Processing Shopify order webhooks to update gift intent status.
- Providing merchants with a dashboard overview of gift intents.
- Billing merchants for app usage via Shopify's billing API.
- Publishing profiles and active gift request links when a customer explicitly enables a public profile.
- Verifying profile email ownership and creating an optional shared gift request list for store profiles that independently verify the same email.
4. Data Sharing
We do not sell your personal data. We share data only with the following service providers strictly necessary to operate the App:
- Shopify – for order management, customer lookup, draft order creation, billing, and required privacy webhooks.
- Postmark – for sending and receiving transactional emails, including delivery/open activity where enabled by the merchant's configuration.
- Klaviyo, Omnisend, or Mailchimp – only when a merchant connects that provider; the selected transactional event can include recipient email, checkout URL, and gift-card code.
- Redis and BullMQ – for short-lived background-job processing.
- Database, hosting, and logging providers – for persistent storage, application hosting, operational diagnostics, and security monitoring.
- Telegram – only for merchant-configured operational alerts; alerts are deliberately minimized and do not include recipient addresses, gift-card codes, or raw message bodies.
When a customer enables a public profile, the profile content and active gift request payment links selected by the App's publication rules are publicly accessible to anyone who has the profile or shared-list URL.
5. Data Retention
Gift intent, delivery, billing, profile, and integration records are retained while needed to operate the App. Verification codes expire after ten minutes and are stored only as keyed hashes; expired verification records are removed after a short operational retention period. A customer data export is encrypted at rest and inaccessible after 24 hours. When a merchant uninstalls the App, local store data is scheduled for deletion after 29 days so that a reinstall can preserve history; a reinstall cancels that pending deletion. Customer redaction requests delete the relevant local data for that store. You may request deletion of your store's data by uninstalling the App or contacting us directly.
6. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, or request deletion of personal data we hold. To exercise these rights, contact us at the address below.
7. Cookies
The App itself does not set cookies in end-customer browsers. Shopify's checkout and storefront may use cookies subject to Shopify's own privacy policy.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
9. Contact
For privacy-related inquiries, please contact us at: support@pay-for-me.app