Privacy Policy
Subflow ("we", "the app") is a subscriptions app for Shopify stores. This policy explains what data the app stores, why, and how long for.
What we store
When a merchant installs Subflow, we store:
- Shop and session data — your
myshopify.comdomain, the access token that lets the app call Shopify on your behalf, and the shop owner's name and email address. - Subscription contracts — for each subscription created in your store: the Shopify contract ID, status, billing frequency, next billing date, recurring total, the products on it, and the subscriber's Shopify customer ID, name and email address.
- Subscriber imports — if you migrate subscribers from another subscriptions app, we store the file you upload and one row per subscriber: the raw line from your export, their email address and delivery address, the product and price, and a description of the card already saved in your store, such as "Visa •••• 4242". This is how the import shows you exactly who will move before anything is created.
- Billing attempts — the outcome of each charge (success, decline reason, retry schedule) and the resulting order ID.
- Subscription history — a log of changes such as skips, pauses, frequency changes and cancellations, and whether the customer or the merchant made them.
- Emails we send — a record of subscription confirmations, payment-failure notices and merchant alerts, including the recipient address and the message content.
Marketing website measurements
Only after you select “Allow Subflow website analytics” and save your choices, we use a random browser identifier and campaign labels in local storage to measure page visits, demo and calculator use, and install-link clicks. The identifier expires after 30 days on your next visit. If local storage is unavailable, measurement uses an in-memory identifier for that page only. We respect browser Do Not Track and Global Privacy Control signals for this optional event collection. Declining does not affect installation or use of the site. Use “Analytics preferences” at the bottom of the page to change your choice; declining removes the saved analytics identifiers and stops new optional events. Your preference is stored for up to 180 days. Clearing site storage also removes it. Events contain the page path and referring site, not payment details.
Submitting the install form records the store domain and any available campaign attribution to connect the handoff with a completed Shopify installation. A click or form submission is not treated as a completed installation. These first-party website events are not sent to Google Ads or other advertising networks. Contact us to request removal of website or install-attribution records.
Optional Google Ads installation measurement
This is a separate, initially unchecked choice from Subflow website analytics. Only after you select “Allow Google Ads installation measurement” and save, we may store a Google click identifier from the page address, a secure first-party cookie, and a record of your consent (time and disclosure version). After Shopify confirms a new installation, we may share that click identifier, the installation time and an anonymous installation reference with Google to measure advertising results. We do not send your store domain, name, email, customer records or payment details. The installation is not reported as a paid purchase, and advertising personalization is disabled in these reports. How Google uses data.
The Google measurement choice and click linkage expire after 30 days; expired server records are removed by the next daily cleanup. You can withdraw using “Analytics preferences”, by unchecking Google measurement and saving, or rejecting optional measurements. Withdrawal stops future exports, removes our stored click identifier for that browser and clears its measurement cookie. Data already received by Google is not automatically erased by withdrawing here; contact us for a removal request, and see Google’s privacy policy. Do Not Track and Global Privacy Control disable this measurement.
Payment details
We never receive or store payment card numbers or bank details. All charges are executed by Shopify against the payment method the customer already gave your store; Subflow only asks Shopify to create the charge and records the result.
Why we store it
Service data is used to operate the service: to charge subscriptions on schedule, to show you your subscribers, to let your customers manage their own subscriptions, and to notify you and them when a payment fails. We do not sell this data, do not share service or customer data with advertisers, and do not use it to train models. Optional website and Google installation measurement are limited to the separately consented purposes described above.
Who we share it with
- Shopify — the source of, and system of record for, all subscription and customer data.
- Resend (email delivery) — recipient address and message content, only for messages the app sends on your behalf.
- Fly.io (hosting) — data is stored in a Postgres database in the United States (
iad).
How long we keep it
- Email bodies are cleared after 30 days; the send record after 90 days.
- Raw marketing events and install-form handoff records are deleted after 90 days by our daily cleanup. Completed installation records are retained separately to operate and measure the service.
- Subscription history is kept for 12 months.
- A finished subscriber import is deleted after 12 months, along with every row in it. An import you have not finished is kept until you do, however old it is — deleting it would leave the subscribers in it stranded halfway.
- Subscription contracts and billing records are kept for as long as the app is installed, as they are the financial record of what was charged.
- When you uninstall, Shopify sends a shop-redaction request 48 hours later and we delete all of your shop's data.
Your customers' rights
We implement Shopify's mandatory privacy webhooks. When a customer asks your store for their data, we compile everything Subflow holds about them and send it to you. When a customer asks to be erased, we delete their personal data from our records. You do not need to contact us for either — Shopify triggers both automatically.
Security
All traffic is served over HTTPS. Data is isolated per shop: every query is scoped to the shop it belongs to, and the customer portal additionally verifies that a subscription belongs to the logged-in customer before showing or changing anything. Application secrets are stored in the hosting platform's encrypted secret store. Shopify access and refresh tokens are stored in the application database with access restricted to the running service and database operators; database connections and all network traffic are encrypted in transit.
Contact
Questions, data requests or complaints: privacy@subflow.store. We respond within 30 days.