Priceflag Back to site

Privacy Policy

Drafted · Effective [EFFECTIVE DATE] · Not yet in force

Draft — five items to complete, then legal review

This is a researched template, not finished legal copy. It was written against Shopify's published requirements for App Store apps, the EU/UK GDPR, and the CCPA as amended by the CPRA. It has not been reviewed by a lawyer, and it must be before Priceflag accepts its first merchant.

Counsel should also confirm the legal bases in section 5, whether an EU or UK Article 27 representative is required, and whether analytics cookies need consent in the markets Priceflag sells into.

Five facts cannot be determined from research. They are marked like this in the text below and listed here:

1. Who we are and what this covers

Priceflag is a pricing tool for Shopify merchants. It forecasts the likely effect of a price change, releases that change to a growing share of your store's traffic in stages, watches profit-per-visitor against a guardrail you set, and reverts the price automatically if the guardrail is breached.

This policy covers the Priceflag Shopify app, the Priceflag web application, and the priceflag.com marketing site. The company behind them is [COMPANY LEGAL NAME], established in [HOME JURISDICTION] at [REGISTERED ADDRESS].

In this policy, "you" means the merchant, or the person using Priceflag on a merchant's behalf. "Your customers" means the shoppers who buy from your store. Priceflag is a business tool. We do not build shopper profiles, we do not advertise to your customers, and we do not sell data to anyone.

2. Two different roles

Which privacy rules apply to a given piece of data depends on whose data it is, so it is worth separating the two cases up front.

Shopify itself is a separate party with its own agreements with you, including Shopify's own data processing addendum. Nothing in this policy changes those.

3. What we collect

Account and billing information

Store data read from Shopify

Protected customer data

Shopify classifies order data as protected customer data, because an order relates to an identifiable person even when no name is attached. Shopify treats name, address, email and phone as a further tier — protected customer fields — that an app has to request individually and justify.

Priceflag's arithmetic works on quantities, prices, margins and counts. It does not need to know who bought anything. Our design intent is therefore to read order data without requesting the protected customer fields. The scopes the app actually asks for are shown to you on Shopify's install screen before you approve anything, and that screen — not this page — is the authoritative record of what we can see.

Usage and technical data

4. What we do with it

We do not use one merchant's store data to produce forecasts for a different merchant, and we do not train shared models on your data, unless you separately and explicitly opt in. We do not use protected customer data for advertising, profiling, or anything other than delivering the features you switched on — Shopify's API terms forbid it, and so does this policy.

5. Legal bases

Where the GDPR or UK GDPR applies to data we control, we rely on the following bases.

For data inside your store, the lawful basis is yours to determine as controller. We process it on your instructions.

6. Shopify access and price writes

Priceflag connects through Shopify's standard OAuth install flow. You see the exact permissions before you grant them, and you can revoke them at any time from your Shopify admin. Shopify requires apps to ask only for the access they genuinely need, and we ask on that basis.

7. Shopify's privacy webhooks

Every app in the Shopify App Store has to answer three mandatory compliance webhooks. We verify the HMAC signature on each one and reject anything that fails verification. Here is what each does and what we do about it.

Separately, Shopify's API License and Terms of Use require an app to delete every copy of a merchant's data within 30 days of uninstall or termination, except where the law requires us to keep something. We treat that as a hard obligation, not an aspiration.

8. Who else sees it

We use a small number of vendors to run the service. Each is bound by contract to process data only on our instructions and only to provide their service to us, with terms that meet Article 28 of the GDPR.

Beyond those, we disclose data only where the law compels it, to establish or defend legal claims, to protect the rights and safety of our users or the public, or in a merger, acquisition or sale of assets — in which case we will tell you before your data becomes subject to a different policy, so you can leave first.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We have never done so.

9. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for.

Backups expire on their own rotation, so data removed from live systems can persist in backups for a short period afterwards before being overwritten.

10. Security

Shopify's protected customer data requirements set a floor that every app handling order data has to meet: encryption in transit and at rest, encrypted backups, defined retention periods, separated test and production environments, staff access limited to those who need it, logging of access to protected customer data, strong authentication on staff accounts, and a written incident response process. Those are the controls we are required to operate and are committed to operating.

We hold no third-party security certification. We are not SOC 2 audited and not ISO 27001 certified, and we will not claim either until it is true. If a certification matters to your procurement process, ask us where we actually stand before you install.

No system is perfectly secure. If a breach affects personal data we hold, we will notify you without undue delay so you can meet your own obligations as controller, and we will notify regulators where the law requires it — under the GDPR that means within 72 hours of becoming aware, where the breach is notifiable.

11. International transfers

Our infrastructure runs in [HOSTING PROVIDER AND REGION], and the company is established in [HOME JURISDICTION]. If you or your customers are elsewhere, personal data will be transferred to and processed in those places, where privacy law may give weaker protection than your own.

For transfers of EEA, UK or Swiss personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where UK data is involved, plus a transfer risk assessment and supplementary technical measures. You can request a copy of the clauses we rely on.

12. Your rights

If the GDPR or UK GDPR applies to you, you have the right to access the personal data we hold about you, correct it, delete it, receive it in a portable machine-readable format, restrict or object to processing, object to direct marketing at any time, and withdraw consent you previously gave.

We will not discriminate against you, degrade your service, or charge you more for exercising any of these rights.

13. California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we have collected and where it came from, to access and delete it, to correct inaccuracies, to receive it in a portable form, and to limit the use of sensitive personal information. Since 2023 these rights cover personal information collected in a business-to-business context too, so they apply to you as a merchant, not only to consumers.

14. Cookies

The marketing site and the app use a small number of cookies and similar technologies.

We do not use advertising cookies, cross-site tracking pixels, or any cookie that follows you off our own properties. You can block or clear cookies in your browser; the app will not function properly without the necessary ones.

15. Children

Priceflag is a business tool sold to merchants. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

16. Changes and contact

We will update this policy as the product changes and as the law does. The date at the top always reflects the current version. For changes that materially affect how we handle your data we will give notice by email or in the app before they take effect, and where the law requires consent we will ask for it rather than assume it.

Questions, requests, or anything on this page that looks wrong: hello@priceflag.com. We read every message that arrives there.

Postal mail: [COMPANY LEGAL NAME], [REGISTERED ADDRESS]. If you need a signed data processing agreement, a copy of our Standard Contractual Clauses, or the current sub-processor list, ask at the same address.


See also the Agreements governing use of Priceflag.