Last updated: July 30, 2025
Privacy Policy
This Privacy Policy describes how Boostify ("we", "our", or "the app") collects, uses, and protects information when you install and use our Shopify app.
1. Information We Collect
When you install Boostify, we collect the following information through the Shopify API:
- Shop domain and store information — your myshopify.com domain, store name, and timezone.
- Access tokens — OAuth tokens issued by Shopify that allow the app to interact with your store on your behalf. These are stored securely in our database.
- Product data — for the Social Proof Popup widget, the app reads product titles and images from your catalog to display real (non-fake) items in popups. No product data is stored by the app.
We do not collect personal information about your customers (shoppers), their names, email addresses, payment details, or purchase history.
2. How We Use the Information
- To authenticate your store and maintain a secure session with the Shopify Admin.
- To render the app dashboard inside the Shopify Admin.
- To power the theme extension widgets (Announcement Bar, Countdown Timer, Trust Badges, Sticky Add to Cart, Social Proof Popup) on your storefront.
- To process billing via Shopify's native billing API.
We do not sell, rent, or share your data with third parties for marketing purposes.
3. Data Storage
Session data (shop domain and access token) is stored in a SQLite database hosted on Railway (railway.app), a U.S.-based cloud platform. Data is encrypted at rest and in transit via HTTPS/TLS.
Storefront widget settings are stored as theme extension settings within your Shopify theme — directly on Shopify's infrastructure. We have no copy of those settings.
4. Data Retention
Session data is retained for as long as the app is installed on your store. When you uninstall the app, the app/uninstalled webhook is triggered and your session record is automatically deleted from our database.
5. Third-Party Services
- Shopify — the app operates within the Shopify platform. Shopify's own privacy policy applies to data held within Shopify.
- Railway — our hosting provider. See Railway's privacy policy.
6. GDPR / Merchant Data Requests
We support Shopify's mandatory GDPR webhooks:
- customers/data_request — we do not store any customer personal data, so there is nothing to return.
- customers/redact — no customer data is held by us; no action is required.
- shop/redact — upon receiving this webhook, all shop session data is deleted from our database.
7. Cookies
The app does not set cookies on your storefront visitors' browsers. The embedded admin dashboard may use session cookies set by Shopify's App Bridge, which are governed by Shopify's cookie policy.
8. Security
All communication between your browser, the Shopify Admin, and our servers uses HTTPS/TLS encryption. Access tokens are stored server-side and never exposed to the browser.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted at this URL with an updated "Last updated" date. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this Privacy Policy or want to request data deletion, please contact us at: viraninayan518@gmail.com.
© 2026 Boostify. All rights reserved.