Draft pending legal review. This policy describes how the app works today, but it has not yet been reviewed by a lawyer and some details are still to be completed (highlighted).

Privacy policy

Last updated: 26 September 2026

1. Who we are

Shuntflow is an app for Shopify stores that monitors payment risk factors (chargebacks, refunds, order value and volume, international payments) and alerts the merchant when one of them changes level. This policy covers the Shuntflow app and this website, shuntflow.com.

Controller: [TO COMPLETE: legal name, address and tax ID of the company or person responsible]. Contact: [email protected].

We play two roles under the GDPR:

2. What data we process

2.1 From your Shopify store

The app only has read access to your store (Shopify permissions read_orders, read_shopify_payments_disputes and read_shopify_payments_accounts). It never writes to your store. When you install it, it imports the last 60 days; after that, Shopify notifies it of new orders, refunds and disputes.

SourceWhat we store
OrdersShopify's internal order ID, total amount, currency, the date the order was processed, and the two-letter country code of the billing address (or of the shipping address if there is no billing address), with whether it differs from your store's country.
RefundsShopify's refund ID, amount refunded, currency and date.
Disputes (Shopify Payments only)Shopify's dispute ID, amount, currency, date opened, type (chargeback or inquiry) and whether you won it.
Your storeStore domain (.myshopify.com), store name, the store owner's email address as provided by Shopify, the store's country, whether it uses Shopify Payments, and your Shuntflow plan and subscription ID.

2.2 What you enter in the app

2.3 What the app generates

2.4 Technical data

3. What we do not store

When Shopify notifies the app of a new order, the notification contains the full order, including your customer's name, email, phone number, addresses and the items bought. The app reads only the fields listed in section 2.1 and discards the rest: it is not saved in the database or written to the logs.

We do not store your customers' names, email addresses, phone numbers, postal addresses, IP addresses or payment card details. Card payments are handled by Shopify; we never see card data. The only identifiers related to your customers that we keep are Shopify's internal IDs of orders, refunds and disputes, which only have meaning inside your Shopify admin, and the country code of each order. Analyses, alerts and alert emails contain only store-level figures.

4. Why we use it and on what legal basis

PurposeLegal basis (GDPR)
Providing the service: monitoring, alerts in the app, alert emails, thresholds and appeal dossiersPerformance of our contract with the merchant (Art. 6(1)(b)); for order data, processing on the merchant's behalf
Plans and billing, which Shopify handlesPerformance of contract (Art. 6(1)(b))
Answering support requestsPerformance of contract and legitimate interest (Art. 6(1)(b) and (f))
Security, error diagnosis and abuse prevention (logs)Legitimate interest in keeping the service secure and working (Art. 6(1)(f))

We do not sell data, use it for advertising, profile your customers or use it to train machine-learning models. Alerts are informative: no decision with legal or similar effects is made automatically about you or your customers.

5. Emails we send

Only risk alert emails, and only to stores on a plan that includes them (Pro) that have alerts turned on. They go to the store owner's email address or to the address you set in Settings, with at most one email per analysis. You can turn them off at any time in Shuntflow → Settings. We do not send marketing emails.

6. Service providers

We use these providers to run Shuntflow. Each one only processes the data it needs for its task.

ProviderWhat forData involvedLocation
ShopifyPlatform the app runs in; source of the store data; billing of plansEverything described in section 2.1As set out in Shopify's privacy policy
NeonDatabaseAll stored dataAWS eu-central-1 (Frankfurt, Germany) [TO CONFIRM for the production database]
RailwayHosting of the app and server logsAll data while it is processed; logs[TO COMPLETE: Railway region]
ResendSending alert emailsRecipient address and email content (store name, signals and figures)Sent from its EU region (Ireland); the company is based in the United States
CloudflareDNS and hosting of this websiteTechnical data of website visits, such as IP addressesGlobal network
Apple (iCloud Mail)Support inboxMessages you send to [email protected]As set out in Apple's privacy policy

Some of these providers are based outside the European Economic Area. Where data leaves it, the transfer relies on [TO COMPLETE: the safeguard for each provider, e.g. the European Commission's standard contractual clauses in its data processing agreement, or the EU-US Data Privacy Framework].

7. How long we keep it

DataHow long
Orders, refunds and disputes90 days from the date of each order, refund or dispute. The app only uses the last 60 days; older records are deleted automatically every day.
Alert email records90 days after the email is sent, then deleted automatically.
Analyses and alerts13 months, then deleted automatically.
Store data, settings, thresholds and appeal dossiersWhile the app is installed.
All of the aboveDeleted when Shopify asks us to erase your store's data, 48 hours after you uninstall (see below), even if the periods above have not ended.
Shopify access token and sessionDeleted as soon as you uninstall the app.
Database backupsDeleted data stays in the provider's backups for [TO COMPLETE: Neon history retention, in days], and then disappears.
Server logs7 days (hosting provider Railway, Hobby plan).
Email delivery logs at Resend[TO COMPLETE: Resend retention for the plan in use]
Support emailsAs long as needed to resolve your request [TO COMPLETE: maximum period]

When you uninstall

The access token is deleted straight away. 48 hours later, Shopify sends us a request to erase your store's data (shop/redact) and we delete everything we hold about your store from the database: orders, refunds and disputes, analyses, alerts, thresholds, dossiers, settings and alert email records.

Requests about your customers

When one of your customers asks Shopify for their data or for its erasure, Shopify forwards the request to us (customers/data_request and customers/redact). Because we hold no data that identifies your customers (section 3), there is nothing to export or delete. We record the request, with the customer and order IDs it contains, in our logs.

8. Your rights

Under the GDPR you can ask for access to your data, its rectification or erasure, restriction of processing, portability, and object to processing based on legitimate interest. Write to [email protected]; we answer within one month. You can also lodge a complaint with a data protection authority [TO COMPLETE: the competent authority, e.g. the Spanish AEPD if the controller is established in Spain].

Uninstalling the app deletes all your store's data as described in section 7.

If you are a customer of a store that uses Shuntflow, the store is the controller of your data: contact it directly. We will help it answer your request.

9. Security

All connections use HTTPS. The app only asks Shopify for read permissions, keeps its credentials out of the code, and never shows technical error details to users. Access to the database is restricted to the app and to the people who operate it.

10. Cookies

This website uses no cookies, analytics or third-party resources. The app runs inside the Shopify admin and uses Shopify's session mechanism; it sets no advertising or analytics cookies.

11. Children

Shuntflow is a service for businesses and is not aimed at children.

12. Changes

If we change this policy, we will update the date at the top. If the change is significant, we will also let merchants know in the app or by email.

13. Contact

[email protected]