Skip to content
  • Demo
  • Pricing
  • FAQ
  • Contact
Start your trial
Demo Pricing FAQ Contact
Start your trial

Legal

Privacy Policy

Effective date: 17 July 2026 · Last updated: 16 September 2026

On this page

  1. Who we are
  2. Scope
  3. Data we collect
  4. Purposes & lawful bases
  5. Cookies & advertising
  6. Sharing & processors
  7. International transfers
  8. Retention
  9. Your rights
  10. Security
  11. Children
  12. Changes
  13. Contact & complaints

This Privacy Policy explains how Xirvy collects, uses, stores, and shares personal data when you use our website and related services. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

1. Who we are

The data controller is Xirvy. For our privacy contact email, see Contact and complaints.

2. Scope

This policy covers:

  • Visitors to our marketing website (including pages such as Product, Pricing, Contact, and legal pages)
  • People who contact us by email or via our contact form
  • Merchants and store staff who install or use the Xirvy Shopify application (to the extent we process personal data as an independent controller or as a processor on your behalf, as described below)

If you use Xirvy through Shopify, Shopify’s own privacy terms also apply to data Shopify processes as a platform. Where we process store or customer data solely to provide the app to a merchant, we typically act as a processor (or sub-processor under Shopify’s ecosystem) on the merchant’s documented instructions. Where we decide how and why to process data for our own purposes (for example, website analytics, billing relationship records, or support tickets), we act as a controller.

The App does not set advertising or analytics cookies on a merchant’s storefront, and we do not use storefront-customer or order-related data for advertising, retargeting, or sale. We do not carry out processing that would require a storefront customer’s marketing consent. Merchants remain responsible for their own storefront privacy notices and for obtaining any consents their storefront, cookies, or marketing require. We honour Shopify’s mandatory customer privacy compliance webhooks (including customer data requests and redaction).

Merchants who process customer personal data through Xirvy should also review our Data Processing Agreement, which governs our role as a processor under Article 28 UK GDPR.

3. Personal data we collect

Website & communications

  • Identity & contact data: name, email address, company/store name (optional), and message content submitted via our contact form or email
  • Technical data: IP address, browser type, device type, approximate location derived from IP, pages viewed, referring URL, and similar diagnostics
  • Marketing & advertising data: cookie identifiers, ad click IDs, and interaction data from Google Analytics and Meta (Facebook) advertising technologies, where you have consented

Shopify app (merchants)

  • Account & shop data: Shopify shop domain, shop identifiers, installation status, plan/subscription status, and configuration of offers you create in Xirvy
  • Merchant staff identity: name and email address of store staff who log in to the App via Shopify (from the Shopify session), used to authenticate the embedded admin. If you use optional in-app roadmap or feedback features, we may also store the author’s name, email, and Shopify user identifier on those posts
  • Operational data: analytics aggregates related to offer performance (for example attributed revenue and order counts) derived from Shopify webhooks and app discounts
  • Limited order-related data: as needed to apply discounts and attribute performance (for example order identifiers and aggregates). We design attribution to minimise personal data and do not require customer names, email addresses, phone numbers, or payment card details for core app operation

We do not intentionally collect special category data. Please do not submit sensitive personal data through our contact form.

4. Purposes and lawful bases

Purpose Examples Lawful basis (UK GDPR)
Provide and operate the website Serving pages, security, fraud prevention Legitimate interests (running a secure site); Contract where you use paid services
Respond to enquiries Contact form and email support Legitimate interests; Contract where pre-contract steps apply
Provide the Shopify app Install, configure offers, apply discounts, show widgets, attribute offer performance, billing via Shopify Contract (merchant agreement / Shopify subscription)
Analytics Google Analytics to understand site usage Consent (PECR / UK GDPR) for analytics cookies and identifiers. Before you consent, the Google Analytics script loads in a cookieless mode that stores nothing on your device and sets no identifiers; we rely on legitimate interests (measuring aggregate site performance) for those cookieless signals
Advertising Meta/Facebook ads measurement and retargeting Consent (PECR / UK GDPR)
Legal & compliance Tax, accounting, responding to lawful requests Legal obligation; Legitimate interests

We limit our use of personal data to the purposes described in this table. In particular, we do not use storefront-customer or order-related data for advertising, retargeting, or our own independent marketing.

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to processing based on legitimate interests as described in “Your rights”.

5. Cookies, analytics, and advertising

We use cookies and similar technologies. Strictly necessary cookies may be set to make the site work (including remembering your cookie preferences). Analytics and advertising cookies are not set until you give consent via our cookie banner.

We use or intend to use:

  • Google Analytics — to measure traffic and improve the website
  • Meta (Facebook) Pixel / ads tools — to measure ad performance and, where enabled, deliver relevant advertising

Google Analytics before you answer the banner. The Google Analytics script itself loads on every page, including before you make a cookie choice, in Google Consent Mode with analytics and advertising storage denied. In that state it stores nothing on your device and sets no identifiers, but Google does receive your IP address, browser type, and the page you are viewing as aggregate, cookieless signals. We rely on legitimate interests for this limited measurement. Analytics cookies and identifiers are only set once you consent to the Analytics category, and the Meta pixel does not load at all until you consent to the Advertising category.

We also use two third-party technologies that set no analytics or advertising cookies, but that do involve data being sent to a provider when a page loads:

  • Google Fonts — the site’s typefaces load from Google’s servers, so Google receives your IP address, browser type, and the page being viewed. This happens on every page, including before you answer the cookie banner, because the fonts are needed to display the site
  • Cloudflare Turnstile — an anti-spam check on our contact form. Cloudflare receives your IP address and browser signals to confirm you are not an automated bot. We rely on legitimate interests (protecting our systems from spam and abuse) for this

These analytics and advertising technologies apply to our marketing website only. The Shopify App does not set advertising or analytics cookies on a merchant’s storefront.

You can accept, reject, or fine-tune non-essential cookies at any time. To change your choice, use the control (also available in the site footer), which reopens the preferences panel so you can withdraw consent as easily as you gave it. See our Cookie Policy for details.

6. Sharing and processors

We share personal data only where needed, including with:

  • Shopify Inc. and Shopify affiliates — platform hosting, authentication, billing, and app distribution
  • Google — analytics (cookies and identifiers with consent; cookieless, aggregate analytics signals on every page load), and Google Fonts on every page load, both as described in section 5
  • Meta Platforms — advertising/measurement (with consent)
  • Cloudflare — Turnstile anti-spam protection on our contact form
  • SMTP2GO — delivery of contact form submissions to our support inbox
  • Crisp — live chat support inside the Xirvy Shopify app; receives your shop domain and the contents of any chat you start with us
  • Hosting, email, and infrastructure providers — to operate the website and communications
  • Professional advisers — lawyers, accountants, insurers where required
  • Authorities — where required by law

We do not sell personal data. We require processors and sub-processors to protect personal data and process it only on our documented instructions (or as otherwise permitted by law), under written contracts that meet Article 28 UK GDPR. Where we act as a processor for merchants, we engage sub-processors under the terms of our Data Processing Agreement. An up-to-date list of our key sub-processors is available on request — see Contact and complaints.

7. International transfers

Some providers (including Google, Meta, and Shopify) may process data outside the United Kingdom. Where we transfer personal data internationally, we use appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision, as applicable.

8. Retention

  • Contact form / support emails: typically up to 24 months after the last meaningful contact, unless a longer period is needed for an ongoing matter or legal claim
  • Analytics & advertising identifiers: according to the provider’s settings and your consent period; consent records retained as needed to demonstrate compliance
  • Merchant app data: retained for the life of the installation (including where you cancel a subscription but keep the App installed). If you uninstall the App, Shopify sends a shop data deletion request (shop/redact) approximately 48 hours later; we then delete your shop’s app data from our systems, unless applicable law requires us to keep specific records

We minimise storefront-customer personal data. Shopify customer data access and deletion requests are handled under Shopify’s mandatory compliance webhooks. We delete or anonymise personal data when it is no longer needed for the purposes above.

9. Your rights

Under UK GDPR, you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data in certain circumstances
  • Restrict or object to processing
  • Data portability (where applicable)
  • Withdraw consent at any time (where processing is based on consent), without affecting prior lawful processing
  • Not be subject to solely automated decisions producing legal or similarly significant effects (we do not use such decision-making on the marketing site)

How to make a request

To exercise any of these rights, email us at the address in Contact and complaints with the words “Data protection request” in the subject line and tell us which right you wish to exercise. When you make a request:

  • Identity verification: we may ask for information to confirm your identity before we act, so that we do not disclose data to the wrong person.
  • Timeframe: we will respond without undue delay and within one month of receiving a valid request. We may extend this by up to two further months for complex or numerous requests, in which case we will tell you within the first month and explain why.
  • Fees: handling requests is normally free of charge. We may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive (for example, repetitive), as permitted by UK GDPR. If we do, we will explain our reasoning.
  • Refusal: if we cannot act on your request, we will explain why and inform you of your right to complain to the ICO and to seek a judicial remedy.

You may also authorise a third party to make a request on your behalf; we may ask for evidence of their authority.

10. Security

We use appropriate technical and organisational measures to protect personal data, including access controls, encrypted transport (HTTPS/TLS), encryption of Shopify access tokens at rest (AES-256-GCM), encryption of production database storage and backups at rest via our hosting providers, and least-privilege practices. No method of transmission or storage is completely secure; please contact us promptly if you suspect a security issue.

11. Children

Our website and services are directed at businesses and are not intended for children under 16. We do not knowingly collect personal data from children. If you believe we have done so, contact us and we will take appropriate steps to delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be highlighted on the website or communicated by email where appropriate.

13. Contact and complaints

For privacy questions, requests or complaints, please email us at: contact@xirvy.com

Volume discounts and upsells for Shopify. Increase AOV with offers that apply automatically at checkout.

Product

  • Features
  • Pricing
  • Demo

Resources

  • FAQ
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
  • Data Processing Agreement
© 2026 Xirvy. All rights reserved.