Qpushly ("we", "the app") is a Shopify application that sends web push notifications on behalf of the merchant who installs it. This policy explains what the app collects, why, and when it is deleted.
Two relationships matter here. The merchant installs Qpushly and decides what messages to send; in data-protection terms the merchant is the controller of their shoppers' data and we act as their processor. If you are a shopper who subscribed to notifications from a store, the store you subscribed to is your first point of contact — but you can also write to us directly at support@qpushly.com.
What we collect from merchants
- Your shop domain and the Shopify access token issued when you install the app. The token is what lets us read the products and orders you granted access to.
- The store name, contact email, logo, default notification icon and default click URL you enter in Settings.
- The campaigns and automations you create, including their copy, images, schedules and performance counters.
- A web push signing keypair generated for your store, so notifications from your store are verifiably from your store.
What we collect about shoppers
Only for shoppers who have explicitly allowed notifications in their browser. Visitors who decline, or who never see the prompt, are not recorded.
- Push subscription — the endpoint URL issued by the shopper's browser vendor and the two cryptographic keys needed to encrypt a message to it. This is the address we send to; it identifies a browser installation, not a person.
- Device and locale — browser, operating system, device type, user agent, language and timezone. These let the merchant see the makeup of their list and let us stop sending to browsers that no longer support delivery.
- Contact details, where the store provides them — email address and phone number, and city and country. These are populated from the merchant's own Shopify order data, not collected from the shopper by us.
- Cart activity — a snapshot of cart contents, value and currency, so an abandoned-cart reminder can reference what was in the cart.
- Product activity — which products and variants a subscriber viewed, whether they were in stock, and the price at the time, so back-in-stock and price-drop alerts can be sent to the right people.
- Notification activity — which notifications were delivered, clicked and converted.
- Attributed orders — when a notification click leads to an order, we record that order: its id, total, currency, the customer's email and first name, and for each line item the title, quantity, price and product/variant id. Only orders we can attribute to a notification are recorded — we do not keep a copy of your other orders.
What we deliberately do not do
- We do not use any third-party geolocation, IP-lookup or fingerprinting service. An earlier version of the storefront script called an external geolocation API; that was removed.
- We do not sell, rent or share shopper data with advertisers or data brokers.
- We do not use one merchant's data to serve another merchant. Every record is scoped to the shop it belongs to.
- We do not load fonts, scripts or images from third-party origins onto your storefront.
- We do not track visitors who have not subscribed to notifications.
Legal basis
For shoppers, the basis is consent — a browser push subscription cannot exist without the shopper actively allowing notifications, and the subscription can be revoked at any time from the browser's own site settings. For merchant account data, the basis is performance of a contract: we cannot run the app for you without it.
How a shopper unsubscribes
Blocking notifications for a site in the browser's settings stops delivery immediately and permanently — it does not depend on us. Shoppers can also ask the merchant to remove their record, which the merchant can do from the subscriber list in the app.
Retention and deletion
- On uninstall — the access tokens for your store are deleted immediately, so no credentials for your store remain usable.
- On shop redaction — Shopify sends a shop-redaction request after an uninstall. On receipt we delete every record belonging to your store: subscribers, campaigns, automations, notification logs, tracked products, carts, attributed orders, settings and sessions.
- On customer redaction — when Shopify sends a customer-redaction request, we delete that customer's subscriber record, cart history and attributed order rows, matched on the email address and phone number Shopify supplies.
- On customer data request — when Shopify sends a data-access request on behalf of a customer, we provide the merchant with the records we hold for that person so the merchant can respond.
Where data is processed
The application and its PostgreSQL database run on infrastructure operated by our hosting provider. Notifications are delivered through the push services operated by the shopper's own browser vendor (for example Google, Mozilla or Apple) — that delivery hop is inherent to the Web Push standard, and the message body is encrypted so that only the shopper's browser can read it.
Sub-processors
- Shopify — the platform the app is installed on; source of product, order and customer data, and the payment processor for the app's own subscription.
- Our application host — runs the app server and its database.
- Browser push services — deliver the encrypted notification to the shopper's device.
Security
All traffic is served over HTTPS. Storefront requests reach the app through Shopify's app proxy and are rejected unless Shopify's signature verifies. Webhook deliveries are rejected unless their HMAC verifies. Access is scoped to the minimum Shopify permissions the app needs to work.
Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, and to withdraw consent. Shoppers should contact the store they subscribed to; merchants and shoppers can also reach us at support@qpushly.com. We respond within 30 days.
Changes
If we change what the app collects, we update this page and move the date at the top. Material changes affecting merchants are also announced in the app.