Privacy Policy
Last updated: June 13, 2026
Altvary ("Altvary," "we," "us") provides retention-intelligence software for Shopify merchants. This policy explains what data the app accesses, how we use it, and the choices you and your customers have. It applies to the Altvary app installed on a Shopify store.
Who controls the data
The merchant who installs Altvary is the data controller of their store and customer data. Altvary acts as a data processoron the merchant's behalf — we process store data only to provide the app's features, never for our own purposes.
What we access
When you install Altvary, you grant read access to the following, via Shopify's API scopes:
- Customers (
read_customers) — name, email, order count, total spend, and engagement timestamps, used to compute retention (RFME) scores and segments. - Orders (
read_orders) — order totals, dates, channel, and refund status, used to measure recency, frequency, and monetary value. - Products (
read_products) — titles, SKUs, price, and inventory levels, used for inventory-aware recommendations.
Altvary requests read-only access. We do not request write access to your store, and we do not access payment card numbers, passwords, or checkout credentials.
How we use it
- To compute per-customer retention scores and segments (VIP, returning, at-risk, churning, lost).
- To generate recommended retention actions and exportable customer lists for the merchant.
- To display dashboards, analytics, and reports inside the app to the merchant's team.
We do not sell or rent personal data, we do not use it for advertising, and we do not share it with third parties except the infrastructure providers listed below.
Where data is stored
Store data is held in a managed PostgreSQL database (Supabase) hosted in the Asia-Pacific (Singapore, ap-southeast-1) region, and the application runs on Vercel. Each merchant's data is isolated and scoped to their store; access tokens are encrypted at rest (AES-256-GCM). Data is transmitted over TLS.
Data retention & deletion
We retain store data for as long as the app is installed. We honor Shopify's mandatory privacy webhooks:
- customers/redact — when a customer requests erasure, we delete that customer and all of their associated records (orders, scores, history, actions).
- customers/data_request — we surface the data we hold so the merchant can fulfill the request.
- shop/redact — 48 hours after uninstall, we erase all of the store's data.
Uninstalling the app stops all data access immediately and triggers erasure of the store's data per the above. To request deletion sooner, contact us at the address below.
Sub-processors
- Shopify — source of store data and the platform the app runs within.
- Supabase — database and authentication.
- Vercel — application hosting.
Your rights
Depending on your jurisdiction (including the GDPR and CCPA), you or your customers may have rights to access, correct, or delete personal data. Merchants can exercise these through Shopify's data-request and redaction tools, or by contacting us directly.
Changes
We may update this policy as the app evolves. Material changes will be reflected here with a new "last updated" date.
Contact
Questions or data requests: alextheous@gmail.com.
