Legal
Privacy Policy
Effective date: August 22, 2026
This policy explains how Siftfy ("we", "us") processes personal data when you use our website (siftfy.com) and the Siftfy Shopify app, and how we honour the privacy choices of merchants and their customers.
Who we are
Siftfy operates the Siftfy website and the Siftfy app for Shopify merchants (product sourcing, order sync, product publication and fulfillment updates). For data protection matters, contact us at [email protected].
Data we process
Store and account data: merchant name, email, display name and preferences; store domain, installation details, granted scopes and encrypted OAuth credentials. Order and customer data (only after a merchant enables order sync): order totals, status, line items, and the customer name, shipping address, email and phone needed to display and fulfill orders. Sourcing data: product links, target prices and notes submitted through quote requests. Interaction data: language, dark-mode and currency preferences stored on your device, and limited technical logs.
Why we use it
We process data to provide the services merchants request (order sync, fulfillment updates, product publication, quotes), to secure the platform and prevent abuse, to comply with Shopify and legal obligations, and to improve the product. We do not use personal data for automated decisions with legal or similarly significant effects, and we do not sell it. Preferences you choose (language, timezone, currency) are applied at your direction.
Shopify protected customer data
The Siftfy app requests the minimum Shopify scopes and protected customer data fields required to sync and fulfill merchant orders (such as read_orders and merchant-managed fulfillment). Protected customer data is used only for those purposes and is never used for our own marketing, profiling or resale.
How long we keep it
Merchant and store data is kept while the store connection and app installation remain active. Technical diagnostic logs are kept for 30 days; business operation logs for 365 days. Privacy compliance records are kept only as long as needed to prove compliance, containing stable internal identifiers, hashes and status markers. One-time data exports are destroyed within 15 minutes of download. When a merchant uninstalls the app, store-scoped data for that installation is deleted or minimised.
Privacy requests and deletion
The app honours Shopify privacy compliance webhooks: customers/data_request (deliver a copy of that customer data), customers/redact (erase the customer data, keeping only an irreversible, store-scoped suppression hash so erased records cannot be resurrected) and shop/redact (minimise or delete the store data for the affected installation). Requests are completed within the required 30-day window. You can also ask us directly at [email protected] to export or erase your data.
Sharing
We share personal data only with processors strictly necessary to run the service: hosting and cloud providers (including Cloudflare R2 for product images), payment processors (Stripe, PayPal) and the Shopify platform, each under contractual data protection commitments. We do not sell or rent personal data.
Security
Personal data is encrypted in transit and at rest. Store credentials are stored encrypted with rotation support. Access to merchant data is limited to authorised staff under role-based access control, sensitive administrative actions are audit-logged, and test and production environments are kept separate.
Your rights
Merchants and their customers may request access, correction, export or erasure of their personal data, and may object to processing where we rely on legitimate interest. To exercise these rights, contact [email protected]. If you are in the EU or UK, you may also lodge a complaint with your local supervisory authority.
Cookies on this website
The Siftfy website stores only local preferences such as language, dark mode and currency in your browser. We do not use third-party advertising cookies and do not build visitor profiles.