Zoomifi - Smart Delivery Dates Privacy Policy
Zoomifi - Smart Delivery Dates (“the App”) is provided by Zoomifi to merchants who use Shopify to power their stores. The App computes delivery-promise dates from the merchant's own fulfillment settings and the store's recent order and fulfillment history. This Privacy Policy explains exactly what data we access, how long we keep it, how we protect it, and what happens when a merchant uninstalls.
1. Information we access
From the merchant's Shopify store
Once a merchant installs the App, we access the following data via Shopify's Admin API and via webhook subscriptions:
| Field | Source | Used for |
|---|---|---|
Order ID, order created-at timestamp, shipping country code, shipping method name and carrier code, order language (customer_locale, e.g. "de") |
orders/create webhook |
Logging the delivery promise we made at PDP, and as the cohort axes for delivery-time statistics (delivery times vary by destination country and shipping method). The order language is saved with the delivery-promise record and is used only to write the optional customer-directed early-delivery email in the shopper's language. |
| Fulfillment ID, order ID, fulfillment status and shipment status, fulfillment created-at and updated-at timestamps, tracking carrier name | fulfillments/update webhook |
Recording when each shipment shipped and was delivered, which drives the delivery-date model, and comparing the delivery date with the date we promised. |
| Order history: for each order from the last 60 days (up to 180 days if Shopify has granted the App access to older orders), the order ID, created-at timestamp, shipping country code, and shipping method name; and for each of its fulfillments, the fulfillment ID, created-at and delivered-at timestamps, delivery status events, and tracking carrier name | Admin API, read once when the merchant installs the App | Giving the delivery-date model real delivery times from day one. |
| Customer email address, order number, and the tracking URL of the order's first shipment | Admin GraphQL API (order query), read at send time; only for stores whose merchant has turned on the early delivery email (off by default) |
Addressing and linking to tracking in the customer-directed early-delivery email (the email does not use the customer's name). Read only when an order is delivered at least one day before the date we promised, used for that one email, and never stored in our database. |
| Product and collection handles, IDs, and titles | Admin API | Resource picker — letting the merchant choose which products and collections show the cutoff banner |
| Store's primary language, published languages, and billing country | Admin API | Choosing the default language for storefront text and for the early-delivery email |
| Active theme metadata | Admin API | Detecting whether the merchant has activated our theme app extension |
We do not access or store: customer first or last name, billing address, shipping address (beyond the two-letter country code), payment information, cart line items, SKUs, prices, quantities, phone numbers, note attributes, custom fields, tags, discount codes, browser fingerprint, or geolocation.
Our web server records the IP address and requested URL of each request in access logs kept for 14 days, for security and troubleshooting. The App itself does not store shopper IP addresses. The App's own logs record an IP address only for a few rejected or misconfigured install and app-launch requests (for example, one with an invalid Shopify signature), never for storefront requests.
If the merchant turns on the storefront delivery check, a shopper can type a country and a ZIP or postal code to see the delivery date for that destination. The postal code is sent to the App in the request URL, used only to answer that request (to match the merchant's postal-code delivery rules), and is not stored by the App. Because it is part of the request URL, it may appear in our web server's access logs, which are kept for 14 days.
Why we use order data
We use order and fulfillment data for two purposes only:
- App functionality: calculating the delivery-date promise shown on the storefront, and detecting orders that were delivered early (which is what triggers the optional early-delivery email).
- Analytics: the merchant's delivery-accuracy statistics in the App's admin, which compare each order's delivery date with the date we promised.
We do not use it for advertising, marketing, or profiling shoppers.
From the merchant directly
When a merchant signs up, we receive their store name, email address, and any configuration values they enter in the App's admin (cutoff times, banner copy, email template). This is standard merchant-account information. If the merchant uses the early delivery email, we read the store's contact email from Shopify when it is needed (as the Reply-To, and as the only recipient of a test email the merchant sends to themselves) and do not store it.
2. Data retention
Order and fulfillment data is retained for a maximum of 180
days, then automatically purged. The retention cap is enforced
by a daily scheduled command (qo:purge-old-orders) that
runs at 03:30 UTC on the production server and deletes any rows in
edd_promises or fulfillment_observations
older than the cap.
Webhook data is queued for processing with only the fields listed above; the full order and fulfillment bodies are never queued or kept.
Customer email addresses are never stored or logged.
The customer-directed early-delivery email is off for every store by
default and is sent only for stores whose merchant has turned it on in the
App's settings (we record when the merchant turns it on and off). For those
stores, we read the customer's email address from Shopify's
Admin GraphQL API only when an order is delivered at least one day before
the date we promised, use it for that one email, and then discard it.
We use the email address only: we do not read the customer's name, and
the email greets the customer without one.
There is no customer-email table in the App's database.
The order language (customer_locale) is saved with the
delivery-promise record and is deleted with it under the 180-day cap
above. The email is sent on the
merchant's behalf, in the store's name, with replies going to the store's
contact email; the App adds no open or click tracking. If a store has no
contact email, the email is not sent.
Aggregate statistics derived from the data (e.g. the per-cohort 95th- percentile delivery interval) contain no personally identifiable information and are retained for the lifetime of the App installation.
3. How we protect data
- In transit: All Shopify API traffic uses TLS 1.3. Inbound webhooks are HMAC-verified against the Partner App secret before any payload is parsed; invalid signatures return 401. Outbound email is sent through Amazon SES over TLS.
- At rest: Database storage is on AWS EBS volumes encrypted with AES-256 using AWS KMS-managed keys. Shopify access tokens are kept in the application database, on that encrypted storage.
- Access control: The application database is on a private subnet with no public IP and no public database port. SSH access is restricted to a single IAM-bounded operator account. All merchant-facing admin actions are gated by Shopify session-token verification — only an authenticated merchant admin session can invoke them.
4. Data residency and support
The App is hosted on Amazon Web Services in the United States, primarily
in the AWS US East (N. Virginia) region, also known as us-east-1.
Merchant configuration, delivery-promise records, fulfillment observations,
encrypted Shopify access tokens, and operational logs are stored or
processed in that region unless Shopify or a required infrastructure
provider routes traffic differently for resiliency.
Support is provided by Zoomifi at [email protected]. Support requests may include merchant contact details, store domain, screenshots, and diagnostic context shared by the merchant. Support conversations are handled only for troubleshooting, account, billing, and app-operation purposes.
A short public data and support FAQ is available at https://quickorder.zoomifi.com/data-and-support.
5. What happens when a merchant uninstalls
When a merchant uninstalls the App, we stop accessing their store straight away and delete their store data about 48 hours later:
- When Shopify sends the
app/uninstalledwebhook, we delete the store's access and refresh tokens, end the App subscription, and mark the store as uninstalled. The App can no longer access the store. We keep the store's settings and delivery data for now, so a merchant who reinstalls before the store-erasure request arrives keeps their setup. - About 48 hours after uninstall, Shopify sends the
shop/redactwebhook. We then delete, in a single database transaction, the store record, its cutoff settings and their product and collection selections, all delivery-promise records, all fulfillment observations, and any user accounts not linked to another store. We also ask the Zoomifi merchant portal, which receives install and uninstall events, to erase its copy of the store's data. - When Shopify sends the
customers/redactwebhook for a customer, we delete the delivery-promise records and fulfillment observations for that customer's orders. We log that we handled the request, with the Shopify customer ID from the request. - When Shopify sends the
customers/data_requestwebhook, we return a JSON response listing the requested orders and how many delivery records we hold for them. This is usually zero for orders older than the retention cap in section 2. We log that we handled the request, with the Shopify customer ID from the request.
6. Sharing of data
We do not sell, rent, or share merchant or customer data with third parties for advertising or marketing purposes. The only third parties that touch the data are infrastructure providers necessary to operate the service:
- Amazon Web Services (compute, database, email delivery) — covered by AWS's data-processing addendum.
- Shopify (the platform the App is built on) — covered by Shopify's Partner Program data-handling terms.
- Cloudflare (our content delivery and security network) — handles all traffic to the App's domain and, like any CDN, processes IP addresses and request URLs to deliver and protect the service.
We may also disclose information when required to do so by law, subpoena, court order, or other legal process, or to protect our legal rights.
7. Your rights
If you are a resident of the European Economic Area, the United Kingdom, California, or another jurisdiction with data-protection rights, you have the right to request access to, correction of, or deletion of personal data we hold about you. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Data may be stored or processed outside your country of residence, including in the United States.
8. Changes to this policy
We may update this policy from time to time to reflect changes to our practices or to legal or regulatory requirements. The "Last updated" date at the top of the page reflects the most recent revision.
9. Contact
For any privacy-related question or request, contact us at [email protected].