Privacy Policy
This Privacy Policy explains what data PocketFront ("PocketFront", "we", "us") collects when a Shopify merchant installs and uses our sales-channel and mobile-app-builder service, how we use it, and who we share it with.
1. Data we collect
- Store & catalog data — via the Shopify permissions you grant on install (products, collections, inventory, publications, and store settings), used to run the sales channel and build your mobile app.
- Order data — the value and status of orders, used to calculate the 1% usage fee on orders placed through the app and to show you sales analytics (including what share of your total sales the app drives).
- Push notification tokens — anonymous device tokens for shoppers who opt in to notifications, used solely to deliver the notifications you send from the app.
- Anonymized usage analytics — app events keyed to an anonymous device identifier (not to a named person), used to power your analytics dashboard.
We do not sell your data or your customers' data, and we do not use it for advertising.
2. How we use data
We use the data above only to provide and operate the service: syncing your catalog, rendering your app, delivering notifications, metering and reconciling billing, and producing your analytics. We do not use it for any unrelated purpose.
3. Service providers (subprocessors)
We rely on a small number of providers to run the service:
- Shopify — the platform your store and checkout run on, and the source of the store data we access.
- Railway — cloud hosting for our application and database.
- Google Firebase Cloud Messaging — delivery of push notifications to Android devices.
- Apple Push Notification service — delivery of push notifications to iOS devices.
4. Data retention and deletion
We keep your data only while PocketFront is installed. When you uninstall the app, we delete your store's configuration and associated records, and we honor Shopify's mandatory data-erasure requests. Specifically, we respond to the customers/data_request, customers/redact, and shop/redact compliance webhooks: on redaction requests we purge the relevant customer records (such as any wishlist or app-login identity keyed to a customer email) and, on shop redaction, we delete the store's data from our systems.
5. Your rights
Merchants and their customers may request access to, or deletion of, personal data. Customer requests are normally initiated through the store owner in the Shopify admin, which triggers the compliance webhooks above. You can also contact us directly using the details below.
6. Security
Data is transmitted over encrypted connections (TLS) and access to production systems is restricted. No system is perfectly secure, but we take reasonable measures to protect the data we hold.
7. Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the app or by email.
8. Contact
Privacy questions or data requests? Email support@pocketfront.app.
This document is a general template provided for transparency and to satisfy platform requirements. It is not legal advice — have it reviewed by qualified counsel before relying on it for your business.