Privacy Policy

Last updated: July 2, 2026

1. Overview

Buy It Again ("the App," "we," "us," or "our") is a Shopify application published by Delightify that helps merchants surface personalised repurchase suggestions to their customers. This Privacy Policy explains what information we collect, why we collect it, and how we use and protect it.

By installing the App on your Shopify store, or by using a storefront where the App is active, you agree to the practices described in this Policy. We may update this Policy from time to time; we will notify affected parties by updating the "Last updated" date above.

This Policy applies to:

  • Merchants — Shopify store owners and their staff who install and configure the App.
  • End Customers — shoppers who visit a Shopify store where the App is installed.

2. Information We Collect

2.1 Information from Merchants (via Shopify OAuth)

When a merchant installs the App, Shopify grants us an access token that allows us to read the following data from the merchant's store:

  • Store identity — shop domain, shop GID, contact email, and storefront URL.
  • Order history — order IDs, line items (product ID, variant ID, quantity, price), order dates, and the customer ID associated with each order. We do not store payment card data or full billing addresses.
  • Product catalogue — product and variant IDs, titles, images, prices, and availability, so we can display accurate "buy it again" snapshots to customers.
  • Customer IDs — Shopify's internal numeric customer identifier, used to associate past orders with the right shopper session.

We do not collect merchants' personal banking details, passwords, or any data outside the scopes granted during OAuth installation.

2.2 Information from End Customers

When a logged-in shopper views a widget powered by the App (homepage or product page), we receive:

  • The customer ID passed by Shopify's App Proxy signature, which allows us to retrieve that customer's purchase history from our database.
  • Add-to-cart interactions — variant IDs and quantities added when a shopper uses the "Buy It Again" button. We do not process the payment ourselves.

We do not directly collect names, email addresses, phone numbers, or shipping addresses from end customers.

2.3 Automatically Collected Technical Data

When any browser or server communicates with our backend, our infrastructure may automatically log:

  • IP addresses and approximate geolocation (country/region level)
  • HTTP request metadata (timestamp, endpoint, response code, latency)
  • Browser and device type (from the User-Agent header)

This data is used solely for security monitoring, debugging, and capacity planning. It is not linked to individual shopper identities.

2.4 Shopify Webhook Data

We subscribe to the following Shopify webhooks:

  • orders/create — to record new purchases and update repurchase suggestions in real time.
  • app/uninstalled — to stop data collection and cancel active subscriptions when a merchant removes the App.
  • customers/redact and shop/redact — to permanently delete customer and shop data when Shopify requests it.
  • app_subscriptions/update — to keep subscription status in sync with Shopify's billing system.

3. How We Use Information

We use the information described above exclusively to:

  • Power the App's core functionality — building and displaying personalised "buy it again" lists on each shopper's session.
  • Sync order history — importing past orders during the initial setup (bulk backfill) and keeping records current via webhooks.
  • Manage subscriptions & billing — recording plan activations, cancellations, and usage-based overage charges via Shopify's billing API.
  • Provide merchant dashboard features — showing merchants aggregate usage metrics and allowing them to configure widget settings.
  • Ensure security and prevent fraud — verifying all requests using Shopify's HMAC or JWT signatures before processing them.
  • Improve the App — analysing aggregate, anonymised usage patterns to identify bugs and improve performance.
  • Comply with legal obligations — responding to lawful requests from authorities when required.

We do not sell personal information, use it for cross-site advertising, or share it with data brokers.

4. Sharing & Disclosure

We may share information in the following limited circumstances:

4.1 Service Providers

We engage trusted third-party vendors who process data on our behalf under strict data-processing agreements:

  • Cloud infrastructure — servers and databases hosted on cloud platforms (e.g., AWS, GCP, or equivalent) located within the EEA or US with appropriate safeguards.
  • Monitoring & error tracking — tools used to detect and diagnose application errors (logs do not include personal end-customer data).

4.2 Shopify

The App operates inside Shopify's ecosystem. Shopify's own Privacy Policy governs how Shopify handles store and customer data independently of our App.

4.3 Business Transfers

If Delightify is acquired, merges with another company, or undergoes a similar corporate transaction, merchant and customer data may be transferred as part of that transaction. We will notify affected merchants in advance.

4.4 Legal Requirements

We may disclose information when required by law, court order, or governmental authority, or to protect the safety, rights, or property of Delightify, merchants, customers, or the public.

5. Data Retention

We retain merchant and customer data only while the App remains installed on the merchant's store. When a merchant uninstalls the App:

  • The store record (store_channels) is marked as uninstalled and all active subscriptions are cancelled.
  • We stop collecting new data immediately.
  • When Shopify sends a shop/redact request, we permanently delete the store record, order-history records, local subscription records, related audit records, and matching application logs.

Technical logs (IP addresses, request metadata) are retained for up to 90 days for security and debugging purposes, then deleted.

6. Security

We implement industry-standard measures to protect the data we hold:

  • Encryption in transit — all data transmitted between browsers, the Shopify platform, and our servers uses TLS 1.2 or higher.
  • Restricted data access — production data is accessible only to the application services and authorised engineers.
  • Request authentication — every inbound request is verified using Shopify's HMAC or JWT signature before any data is accessed or modified.
  • Access controls — production databases are accessible only to application services and authorised engineers via secure bastion access.

No method of transmission or storage is 100% secure. If you discover a potential security vulnerability, please contact us at security@delightify.app.

7. Your Choices

7.1 Merchants

  • Uninstall the App — removing the App from your Shopify admin stops all data collection immediately. Shopify's mandatory redaction workflow then triggers permanent deletion of store data.
  • Data export or deletion requests — contact privacy@delightify.app to request a copy or deletion of your store's data prior to uninstalling.
  • Widget configuration — you can disable the homepage and product-page widgets at any time from the App settings dashboard.

7.2 End Customers

End customers who wish to have their purchase-history data removed from our system should contact the merchant (Shopify store) directly, as the data originates from that merchant's orders. Merchants can submit a deletion request on behalf of their customers to privacy@delightify.app.

8. Shopify Merchants — Additional Notes

As a Shopify Partner, we follow Shopify's Partner Program Agreement and API Terms of Service. This means:

  • We only request the minimum Shopify API scopes necessary to operate the App.
  • We do not use Shopify customer data for purposes unrelated to providing the App's features to that specific store.
  • We cooperate with Shopify's mandatory data deletion webhooks (customers/redact, shop/redact) to honour end-customer and merchant deletion requests.

9. End Customers — Your Rights

Depending on your location, you may have the right to:

  • Access the personal data held about you
  • Correct inaccurate personal data
  • Request deletion of your personal data
  • Object to or restrict certain processing activities
  • Data portability (receive your data in a machine-readable format)

Because we hold customer data as a data processor on behalf of the merchant (data controller), please direct these requests to the merchant's store first. We will cooperate fully with merchants to honour verified requests within the legally required timeframes.

10. California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA:

  • Right to Know — you may request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete — you may request deletion of personal information we hold about you, subject to certain exceptions.
  • Right to Correct — you may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale — we do not sell personal information, so no opt-out is required.
  • Right to Non-Discrimination — we will not discriminate against you for exercising your CCPA rights.

To submit a verifiable request, contact us at privacy@delightify.app. We will respond within 45 days, with a possible 45-day extension where permitted.

11. Children's Privacy

The App is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child under 13 has provided us with personal information, please contact us at privacy@delightify.app and we will delete it promptly.

13. Policy Changes

We reserve the right to amend this Policy at any time. Material changes will be communicated to merchants via email or an in-app notification at least 14 days before they take effect. Continued use of the App after the effective date constitutes acceptance of the revised Policy.

14. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy, please reach out to us:

We aim to respond to all privacy-related enquiries within 5 business days.