Draft. This page states honestly what the platform does with data, and it is the text the Shopify App Store listing points at — but it has not been reviewed by a lawyer. Have it reviewed before the first merchant who is not Koshindo installs the app.
1. Who this covers
There are two kinds of people in this policy and it matters which one you are.
- Merchants — Shopify store owners who install Bunyawi. We are the data controller for what we hold about you.
- Shoppers — people who download a merchant's app and buy from it. For that data the merchant is the controller and we are their processor. We only ever handle it on their instructions, and if they leave us it goes with them.
2. What we collect from merchants
- Your Shopify store domain, store name, plan, country, currency and timezone — read from Shopify when you install.
- Your contact email and, if you give it, a WhatsApp number for support.
- The app you design: colours, logo, home sections, tabs, strings, push campaigns.
- Credentials you upload so we can publish on your behalf: your App Store Connect API key, your Google Play service-account key, your Apple push key. These are encrypted at rest with AES-256-GCM, are never shown back to you or to anyone else, are never written to a log, and are deleted when you uninstall or when you revoke them — whichever comes first.
- An audit trail of changes made in the dashboard: who changed what, and when.
3. What the merchant's app collects from shoppers
On the merchant's behalf, and only to make their store work:
- An anonymous account identifier created on first launch, so a cart survives closing the app.
- Name, phone, email and delivery address — only when the shopper types them into an order.
- Order history and delivery status, so the shopper can track a parcel.
- A push notification token, so order updates can be delivered. It is deleted when the app is uninstalled or the token stops working.
- Crash reports and basic usage analytics, so a broken screen is noticed before customers report it.
We do not collect precise location, contacts, photos, microphone or advertising identifiers, and we do not sell, rent or share any of it with advertisers or data brokers. Payment card details are handled by the payment provider and never reach our servers.
4. Where it is stored
Merchant and shopper records live in a managed PostgreSQL database hosted in the European Union (Frankfurt). Push delivery goes through Google Firebase Cloud Messaging for Android and directly to Apple Push Notification service for iOS. Product and order data also lives in the merchant's own Shopify store, under Shopify's terms. Build artefacts live with our CI provider and are deleted on a rolling 30-day schedule.
5. How long we keep it
- While you are a customer: for as long as the app is installed.
- After you uninstall: 30 days, so you can change your mind, then deleted. Your uploaded credentials are deleted immediately on uninstall, not after 30 days.
- On a deletion request: within 30 days, as Shopify's privacy requirements oblige us.
6. Shopify's mandatory privacy requests
Bunyawi implements the three privacy webhooks every Shopify app must implement:
customers/data_request, customers/redact and shop/redact.
In practice: if a shopper asks a merchant for their data, or asks to be erased, the request reaches
us automatically and we act on it within 30 days. A merchant does not have to email us to make that
happen.
7. Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to a particular use. Write to [email protected] and we will answer within 30 days. If you are in the EU or the UK you have these rights under the GDPR; we extend the same handling to everyone regardless of where they are.
8. Sub-processors
The third parties that necessarily see some of this data, and why:
- Shopify — your store's products, orders and customers. You are already their customer.
- Supabase (EU) — the database.
- DigitalOcean (Frankfurt) — the server that runs the API.
- Google Firebase — Android push delivery, crash reporting.
- Apple — iOS push delivery, App Store distribution.
- Codemagic — builds the iOS app; sees your App Store Connect key for the duration of a build.
- Cloudflare — sits in front of our servers and terminates TLS.
9. Security
Everything travels over TLS. Secrets are encrypted at rest with a key that is not stored beside them. Access to production is limited to the people who operate the platform. We will tell affected merchants within 72 hours of becoming aware of a breach that affects their data, and we will tell them what we know even when what we know is incomplete.
10. Changes
If this policy changes in a way that affects what we do with your data, we will email every merchant before the change takes effect rather than quietly updating the date at the top.