This Privacy Policy explains how Xirvy collects, uses, stores, and shares personal data when you use our website and related services. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. Who we are
The data controller is Xirvy. For our privacy contact email, see Contact and complaints.
2. Scope
This policy covers:
- Visitors to our marketing website (including pages such as Product, Pricing, Contact, and legal pages)
- People who contact us by email or via our contact form
- Merchants and store staff who install or use the Xirvy Shopify application (to the extent we process personal data as an independent controller or as a processor on your behalf, as described below)
If you use Xirvy through Shopify, Shopify’s own privacy terms also apply to data Shopify processes as a platform. Where we process store or customer data solely to provide the app to a merchant, we typically act as a processor (or sub-processor under Shopify’s ecosystem) on the merchant’s documented instructions. Where we decide how and why to process data for our own purposes (for example, website analytics, billing relationship records, or support tickets), we act as a controller.
The App does not set advertising or analytics cookies on a merchant’s storefront, and we do not use storefront-customer or order-related data for advertising, retargeting, or sale. We do not carry out processing that would require a storefront customer’s marketing consent. Merchants remain responsible for their own storefront privacy notices and for obtaining any consents their storefront, cookies, or marketing require. We honour Shopify’s mandatory customer privacy compliance webhooks (including customer data requests and redaction).
Merchants who process customer personal data through Xirvy should also review our Data Processing Agreement, which governs our role as a processor under Article 28 UK GDPR.
3. Personal data we collect
Website & communications
- Identity & contact data: name, email address, company/store name (optional), and message content submitted via our contact form or email
- Technical data: IP address, browser type, device type, approximate location derived from IP, pages viewed, referring URL, and similar diagnostics
- Marketing & advertising data: cookie identifiers, ad click IDs, and interaction data from Google Analytics and Meta (Facebook) advertising technologies, where you have consented
Shopify app (merchants)
- Account & shop data: Shopify shop domain, shop identifiers, installation status, plan/subscription status, and configuration of offers you create in Xirvy
- Merchant staff identity: name and email address of store staff who log in to the App via Shopify (from the Shopify session), used to authenticate the embedded admin. If you use optional in-app roadmap or feedback features, we may also store the author’s name, email, and Shopify user identifier on those posts
- Operational data: analytics aggregates related to offer performance (for example attributed revenue and order counts) derived from Shopify webhooks and app discounts
- Limited order-related data: as needed to apply discounts and attribute performance (for example order identifiers and aggregates). We design attribution to minimise personal data and do not require customer names, email addresses, phone numbers, or payment card details for core app operation
We do not intentionally collect special category data. Please do not submit sensitive personal data through our contact form.
4. Purposes and lawful bases
| Purpose | Examples | Lawful basis (UK GDPR) |
|---|---|---|
| Provide and operate the website | Serving pages, security, fraud prevention | Legitimate interests (running a secure site); Contract where you use paid services |
| Respond to enquiries | Contact form and email support | Legitimate interests; Contract where pre-contract steps apply |
| Provide the Shopify app | Install, configure offers, apply discounts, show widgets, attribute offer performance, billing via Shopify | Contract (merchant agreement / Shopify subscription) |
| Analytics | Google Analytics to understand site usage | Consent (PECR / UK GDPR) for analytics cookies and identifiers. Before you consent, the Google Analytics script loads in a cookieless mode that stores nothing on your device and sets no identifiers; we rely on legitimate interests (measuring aggregate site performance) for those cookieless signals |
| Advertising | Meta/Facebook ads measurement and retargeting | Consent (PECR / UK GDPR) |
| Legal & compliance | Tax, accounting, responding to lawful requests | Legal obligation; Legitimate interests |
We limit our use of personal data to the purposes described in this table. In particular, we do not use storefront-customer or order-related data for advertising, retargeting, or our own independent marketing.
Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to processing based on legitimate interests as described in “Your rights”.
7. International transfers
Some providers (including Google, Meta, and Shopify) may process data outside the United Kingdom. Where we transfer personal data internationally, we use appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as applicable.
8. Retention
- Contact form / support emails: typically up to 24 months after the last meaningful contact, unless a longer period is needed for an ongoing matter or legal claim
- Analytics & advertising identifiers: according to the provider’s settings and your consent period; consent records retained as needed to demonstrate compliance
- Merchant app data: retained for the life of the installation (including where you cancel a subscription but keep the App installed). If you uninstall the App, Shopify sends a shop data deletion request (shop/redact) approximately 48 hours later; we then delete your shop’s app data from our systems, unless applicable law requires us to keep specific records
We minimise storefront-customer personal data. Shopify customer data access and deletion requests are handled under Shopify’s mandatory compliance webhooks. We delete or anonymise personal data when it is no longer needed for the purposes above.
9. Your rights
Under UK GDPR, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data in certain circumstances
- Restrict or object to processing
- Data portability (where applicable)
- Withdraw consent at any time (where processing is based on consent), without affecting prior lawful processing
- Not be subject to solely automated decisions producing legal or similarly significant effects (we do not use such decision-making on the marketing site)
How to make a request
To exercise any of these rights, email us at the address in Contact and complaints with the words “Data protection request” in the subject line and tell us which right you wish to exercise. When you make a request:
- Identity verification: we may ask for information to confirm your identity before we act, so that we do not disclose data to the wrong person.
- Timeframe: we will respond without undue delay and within one month of receiving a valid request. We may extend this by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.
- Fees: handling requests is normally free of charge. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive (for example, repetitive), as permitted by UK GDPR. If we do, we will explain our reasoning.
- Refusal: if we cannot act on your request, we will explain why and inform you of your right to complain to the ICO and to seek a judicial remedy.
You may also authorise a third party to make a request on your behalf; we may ask for evidence of their authority.
10. Security
We use appropriate technical and organisational measures to protect personal data, including access controls, encrypted transport (HTTPS/TLS), encryption of Shopify access tokens at rest (AES-256-GCM), encryption of production database storage and backups at rest via our hosting providers, and least-privilege practices. No method of transmission or storage is completely secure; please contact us promptly if you suspect a security issue.
11. Children
Our website and services are directed at businesses and are not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have done so, contact us and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be highlighted on the website or communicated by email where appropriate.
13. Contact and complaints
For privacy questions, requests or complaints, please email us at: contact@xirvy.com