Privacy policy
Last updated: 26 September 2026
1. Who we are
Shuntflow is an app for Shopify stores that monitors payment risk factors (chargebacks, refunds, order value and volume, international payments) and alerts the merchant when one of them changes level. This policy covers the Shuntflow app and this website, shuntflow.com.
Controller: [TO COMPLETE: legal name, address and tax ID of the company or person responsible]. Contact: [email protected].
We play two roles under the GDPR:
- Controller for the data of the merchant as our customer: the store's details, the alert email address, settings and support messages.
- Processor, on behalf of the merchant, for the data we read from the store's orders, refunds and disputes. The merchant is the controller of their customers' data.
2. What data we process
2.1 From your Shopify store
The app only has read access to your store (Shopify permissions
read_orders, read_shopify_payments_disputes and
read_shopify_payments_accounts). It never writes to your store. When you
install it, it imports the last 60 days; after that, Shopify notifies it of new
orders, refunds and disputes.
| Source | What we store |
|---|---|
| Orders | Shopify's internal order ID, total amount, currency, the date the order was processed, and the two-letter country code of the billing address (or of the shipping address if there is no billing address), with whether it differs from your store's country. |
| Refunds | Shopify's refund ID, amount refunded, currency and date. |
| Disputes (Shopify Payments only) | Shopify's dispute ID, amount, currency, date opened, type (chargeback or inquiry) and whether you won it. |
| Your store | Store domain (.myshopify.com), store name,
the store owner's email address as provided by Shopify, the store's country,
whether it uses Shopify Payments, and your Shuntflow plan and subscription
ID. |
2.2 What you enter in the app
- The email address for risk alerts, if you choose a different one from the store owner's, and whether alerts are on or off.
- Custom alert thresholds (Pro plan).
- Appeal dossiers: titles, the status of each checklist item and your notes. This is free text you write; please do not put your customers' personal data in it.
- Which alerts you have marked as seen.
2.3 What the app generates
- Analyses: store-level rates and totals for each signal, and the alerts created when a signal changes level.
- A record of each alert email: recipient, date, language, number of alerts and delivery status.
- The language of your last visit to the app (English or Spanish), used to write your alert emails.
- Usage counters for your plan's limits.
2.4 Technical data
- The access token Shopify issues so the app can read your store's data, and the session data needed to keep you signed in to the app.
- Server logs: your store's domain, the IDs of the orders, refunds and disputes processed, errors and support reference codes. Our hosting provider may also record the IP addresses of requests.
3. What we do not store
When Shopify notifies the app of a new order, the notification contains the full order, including your customer's name, email, phone number, addresses and the items bought. The app reads only the fields listed in section 2.1 and discards the rest: it is not saved in the database or written to the logs.
We do not store your customers' names, email addresses, phone numbers, postal addresses, IP addresses or payment card details. Card payments are handled by Shopify; we never see card data. The only identifiers related to your customers that we keep are Shopify's internal IDs of orders, refunds and disputes, which only have meaning inside your Shopify admin, and the country code of each order. Analyses, alerts and alert emails contain only store-level figures.
4. Why we use it and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the service: monitoring, alerts in the app, alert emails, thresholds and appeal dossiers | Performance of our contract with the merchant (Art. 6(1)(b)); for order data, processing on the merchant's behalf |
| Plans and billing, which Shopify handles | Performance of contract (Art. 6(1)(b)) |
| Answering support requests | Performance of contract and legitimate interest (Art. 6(1)(b) and (f)) |
| Security, error diagnosis and abuse prevention (logs) | Legitimate interest in keeping the service secure and working (Art. 6(1)(f)) |
We do not sell data, use it for advertising, profile your customers or use it to train machine-learning models. Alerts are informative: no decision with legal or similar effects is made automatically about you or your customers.
5. Emails we send
Only risk alert emails, and only to stores on a plan that includes them (Pro) that have alerts turned on. They go to the store owner's email address or to the address you set in Settings, with at most one email per analysis. You can turn them off at any time in Shuntflow → Settings. We do not send marketing emails.
6. Service providers
We use these providers to run Shuntflow. Each one only processes the data it needs for its task.
| Provider | What for | Data involved | Location |
|---|---|---|---|
| Shopify | Platform the app runs in; source of the store data; billing of plans | Everything described in section 2.1 | As set out in Shopify's privacy policy |
| Neon | Database | All stored data | AWS eu-central-1 (Frankfurt, Germany) [TO CONFIRM for the production database] |
| Railway | Hosting of the app and server logs | All data while it is processed; logs | [TO COMPLETE: Railway region] |
| Resend | Sending alert emails | Recipient address and email content (store name, signals and figures) | Sent from its EU region (Ireland); the company is based in the United States |
| Cloudflare | DNS and hosting of this website | Technical data of website visits, such as IP addresses | Global network |
| Apple (iCloud Mail) | Support inbox | Messages you send to [email protected] | As set out in Apple's privacy policy |
Some of these providers are based outside the European Economic Area. Where data leaves it, the transfer relies on [TO COMPLETE: the safeguard for each provider, e.g. the European Commission's standard contractual clauses in its data processing agreement, or the EU-US Data Privacy Framework].
7. How long we keep it
| Data | How long |
|---|---|
| Orders, refunds and disputes | 90 days from the date of each order, refund or dispute. The app only uses the last 60 days; older records are deleted automatically every day. |
| Alert email records | 90 days after the email is sent, then deleted automatically. |
| Analyses and alerts | 13 months, then deleted automatically. |
| Store data, settings, thresholds and appeal dossiers | While the app is installed. |
| All of the above | Deleted when Shopify asks us to erase your store's data, 48 hours after you uninstall (see below), even if the periods above have not ended. |
| Shopify access token and session | Deleted as soon as you uninstall the app. |
| Database backups | Deleted data stays in the provider's backups for [TO COMPLETE: Neon history retention, in days], and then disappears. |
| Server logs | 7 days (hosting provider Railway, Hobby plan). |
| Email delivery logs at Resend | [TO COMPLETE: Resend retention for the plan in use] |
| Support emails | As long as needed to resolve your request [TO COMPLETE: maximum period] |
When you uninstall
The access token is deleted straight away. 48 hours later, Shopify sends us a
request to erase your store's data (shop/redact) and we delete
everything we hold about your store from the database: orders, refunds and disputes,
analyses, alerts, thresholds, dossiers, settings and alert email records.
Requests about your customers
When one of your customers asks Shopify for their data or for its erasure, Shopify
forwards the request to us (customers/data_request and
customers/redact). Because we hold no data that identifies your
customers (section 3), there is nothing to export or delete. We record the request,
with the customer and order IDs it contains, in our logs.
8. Your rights
Under the GDPR you can ask for access to your data, its rectification or erasure, restriction of processing, portability, and object to processing based on legitimate interest. Write to [email protected]; we answer within one month. You can also lodge a complaint with a data protection authority [TO COMPLETE: the competent authority, e.g. the Spanish AEPD if the controller is established in Spain].
Uninstalling the app deletes all your store's data as described in section 7.
If you are a customer of a store that uses Shuntflow, the store is the controller of your data: contact it directly. We will help it answer your request.
9. Security
All connections use HTTPS. The app only asks Shopify for read permissions, keeps its credentials out of the code, and never shows technical error details to users. Access to the database is restricted to the app and to the people who operate it.
10. Cookies
This website uses no cookies, analytics or third-party resources. The app runs inside the Shopify admin and uses Shopify's session mechanism; it sets no advertising or analytics cookies.
11. Children
Shuntflow is a service for businesses and is not aimed at children.
12. Changes
If we change this policy, we will update the date at the top. If the change is significant, we will also let merchants know in the app or by email.