# Privacy Policy This Privacy Policy describes how ("we," "us," or "our") collects, uses, and discloses information in connection with the XFlow — Back in Stock Automation application ("App," "XFlow," or "Service"), which is available through the Shopify App Store and installed on merchants' Shopify stores. This policy applies to two groups of people: * **Merchants** who install Xflow on their Shopify store ("Merchant," "you"), and * **Shoppers** who visit a Merchant's store and interact with Xflow's back-in-stock notification features ("Shopper," "Customer," "End User"). By installing or using Xflow, you agree to the terms of this Privacy Policy. ## 1. Information We Collect ### 1.1 Information from Merchants When a Merchant installs Xflow, we may collect: * Shopify store name, domain, and store ID * Merchant contact information (name, email address) * App configuration and settings (e.g., notification templates, back-in-stock rules, branding preferences) * Billing and subscription information (processed via Shopify Billing; we do not directly store full payment card details) * Usage data related to how the App is configured and used within the Shopify admin ### 1.2 Information from Shoppers (End Users) When a Shopper signs up to be notified that an out-of-stock product is back in stock, XFlow may collect: * Email address * Phone number (if SMS notifications are enabled) * The product(s), variant(s), and store page the Shopper subscribed to * Timestamp of subscription and notification delivery/open/click status * Basic device and browser information (e.g., IP address, browser type) used for fraud prevention and analytics ### 1.3 Information from Shopify Through the Shopify API, and subject to the access scopes approved by the Merchant at installation, XFlow may access: * Product, variant, and inventory data (titles, images, prices, stock levels) * Store theme data necessary to display the notification opt-in widget * Order data, only if needed to confirm a purchase resulting from a back-in-stock notification (used for analytics/attribution reporting shown to the Merchant) We only request the Shopify API scopes necessary for XFlow's core functionality. ## 2. How We Use Information We use the information described above to: * Provide, operate, and maintain the back-in-stock notification service * Send email and/or SMS alerts to Shoppers when a subscribed product is restocked * Allow Merchants to customize notification content, timing, and branding * Generate analytics and reporting for Merchants (e.g., notification sign-ups, sent notifications, conversion/revenue attribution) * Detect, prevent, and address fraud, abuse, or technical issues * Communicate with Merchants about their account, billing, updates, or support requests * Comply with legal obligations We do **not** sell Shopper personal information to third parties. ## 3. Legal Basis for Processing (GDPR) Where applicable (e.g., for Shoppers in the European Economic Area or UK), we process personal data on the following legal bases: * **Consent** — when a Shopper opts in to receive a back-in-stock notification * **Contractual necessity** — to provide the App's services to the Merchant * **Legitimate interests** — for analytics, fraud prevention, and service improvement * **Legal obligation** — where required by applicable law ## 4. How We Share Information We may share information with: * **The Merchant** whose store the Shopper interacted with (Shoppers' notification sign-up data is visible to the relevant Merchant within the App dashboard) * **Shopify Inc.**, as the platform on which the App operates, in accordance with the [Shopify Terms of Service](https://www.shopify.com/legal/terms) and [Shopify API License and Terms of Use](https://www.shopify.com/legal/api-terms) * **Service providers/subprocessors** who help us deliver the Service, such as: * Email delivery providers (e.g., for transactional notification emails) * SMS gateway providers (e.g., for text message notifications) * Cloud hosting and data storage providers * Analytics providers * **Legal and safety authorities**, where required to comply with law, enforce our terms, or protect rights, property, or safety * **A successor entity**, in the event of a merger, acquisition, or sale of assets All third-party service providers are contractually bound to protect personal information and use it only for the purposes we specify. ## 5. Cookies and Tracking Technologies XFXF;low may use cookies, local storage, or similar technologies on the Merchant's storefront to: * Remember whether a Shopper has already subscribed to a back-in-stock alert for a product * Measure notification performance and attribute resulting purchases * Prevent duplicate or fraudulent sign-ups Shoppers can control cookies through their browser settings; disabling cookies may affect some App functionality. ## 6. Data Retention * **Shopper notification data** (email/phone, product subscribed to) is retained for as long as needed to fulfill the notification purpose, or until the Shopper unsubscribes, the Merchant removes the data, or the Merchant uninstalls the App. * **Merchant account data** is retained for the duration of the App's installation and for a limited period afterward for legal, accounting, or dispute-resolution purposes. * Upon uninstallation, we delete or anonymize store data in accordance with Shopify's data protection requirements, typically within 48 hours to 30 days, except where retention is required by law. ## 7. Shopper Rights Depending on their location, Shoppers may have rights to: * Access the personal information we hold about them * Request correction or deletion of their information * Withdraw consent to receive notifications (e.g., via an "unsubscribe" link in emails or "STOP" reply for SMS) * Object to or restrict certain processing * Request a copy of their data in a portable format To exercise these rights, Shoppers should first contact the Merchant of the store they interacted with, or contact us directly, and we will coordinate with the relevant Merchant as needed. ## 8. Merchant Responsibilities Merchants are responsible for: * Ensuring their own privacy policy discloses the use of XFlow and back-in-stock notification collection to their Shoppers * Obtaining any consents required under applicable law (e.g., SMS consent under TCPA, email consent under CAN-SPAM/GDPR/CASL) before enabling notification channels * Promptly honoring Shopper data requests routed to them ## 9. Data Security We implement industry-standard technical and organizational measures — including encryption in transit, access controls, and regular security review — to protect information against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. ## 10. International Data Transfers Information may be processed and stored in countries other than the Shopper's or Merchant's country of residence. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal data. ## 11. Children's Privacy XFlow is not directed at children under 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected such information, we will take steps to delete it. ## 12. California Privacy Rights (CCPA/CPRA) California residents may have the right to request disclosure of the categories and specific pieces of personal information collected, request deletion, and opt out of certain data sharing. We do not sell personal information as defined under the CCPA/CPRA. ## 13. Changes to This Policy We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated policy with a revised "Last Updated" date. Continued use of the App after changes take effect constitutes acceptance of the revised policy.