TrackFlow

Legal

Privacy Policy

Last updated: July 28, 2026

1. Scope and roles

This policy explains how TrackFlow processes information when a Shopify merchant installs the app and when a customer uses a TrackFlow tracking page or support assistant.

The merchant is generally the data controller for customer and order data. TrackFlow processes that data on the merchant’s instructions to provide the service. TrackFlow is the controller for account administration, billing status, security, and direct support communications.

2. Information we process

  • Merchant and app data: shop domain, Shopify shop identifier, app session credentials, plan status, configuration, brand name, contact and reply addresses.
  • Order and customer data: customer name and email, Shopify order identifier and name, order date, order status, internal tracking token, parcel number, carrier, tracking events, and notification history.
  • Assistant data: customer email when required, conversation messages, feedback, linked order, sources used in answers, token usage, and estimated AI cost.
  • Merchant knowledge: approved FAQs, product and page content, imported URLs, CSV or PDF content, and vector representations used for retrieval.
  • Technical data: request metadata, delivery identifiers, failure logs, security or rate-limit data, and protected-data access records containing a hashed actor identifier, purpose, action, internal resource reference, and timestamp. These audit records do not copy customer names or email addresses.

TrackFlow does not need payment card data. Product checkout and subscription billing are handled by Shopify.

3. Why we use the information

  • Authenticate merchants and operate the Shopify app.
  • Create order timelines and secure customer tracking links.
  • Schedule and send transactional order updates.
  • Answer support questions using merchant-approved knowledge.
  • Apply plan limits, maintain service reliability, and prevent abuse.
  • Handle access, export, redaction, and deletion requests.

4. Service providers

TrackFlow relies on the following providers to operate the service:

  • Shopify for commerce data, authentication, app proxy requests, webhooks, and managed billing.
  • Fly.io for application hosting and operational infrastructure.
  • Neon for managed PostgreSQL database hosting.
  • Resend for transactional email delivery and verified sending domains.
  • OpenAI for assistant responses, document processing, and knowledge embeddings when the AI features are enabled.

These providers process data under their own security and data processing terms. Data may be processed in countries other than the merchant or customer’s country, subject to applicable transfer safeguards.

5. Retention and deletion

In public app mode, order and tracking records are kept for the configured retention period, normally up to 730 days. Assistant conversations are retained for the merchant-configured period, limited by the service to 7 through 90 days.

Data may be deleted earlier after a verified request, Shopify customer or shop redaction webhook, or app uninstall. Some minimal logs may remain for a limited period where needed for security, fraud prevention, or legal obligations. Protected-data access records are retained for up to 365 days.

6. Security

TrackFlow uses HTTPS in transit, managed infrastructure controls, signed Shopify requests, opaque tracking access tokens, role-limited operational access, application-level protected-data access logs, and database constraints intended to prevent duplicate processing. No internet service can guarantee absolute security.

7. Your choices and rights

Depending on applicable law, a person may request access, correction, export, restriction, objection, or deletion. Customers should normally contact the merchant that collected their order information. Merchants can contact TrackFlow for assistance.

Privacy requests and questions can be sent to contact.amhook@gmail.com.

8. Changes

We may update this policy as the service, providers, or legal requirements change. The date above identifies the current version.