1. Who we are
Profiter is a Shopify app operated by KraftPixel Digital Solutions Pvt Ltd, 416, Dattani Prism 1, Vasai West, Mumbai, Maharashtra 401202, India ("we", "us"). This policy explains how we process personal data for merchants who install the app.
2. Our role
The merchant who installs Profiter is the data controller for their shoppers' data. We act as the data processor, handling that data only to run the app on the merchant's behalf. A Data Processing Addendum is available on request.
3. Data we process
- Shopper leads you collect: email, optional phone, optional first name, and consent state.
- Behavioural events: a pseudonymous visitor id, campaign and experiment ids, event names and timestamps. We do not store payment data or raw personal data in logs.
- Order attribution: order id, order total and discount code, to connect a purchase back to a spin.
- Shop / merchant data: shop domain, contact email, and the access tokens needed to operate, stored server-side and encrypted at rest.
4. How we use it
To render campaigns, allocate rewards, measure incremental profit and provide analytics. We do not sell personal data, and we do not use it to advertise our own products.
5. Consent
Consent boxes are never pre-ticked. Where required we support double opt-in before an email is added to a marketing list.
6. Data minimization & retention
We store the minimum needed. Visitor identifiers are pseudonymous and, where used as keys, hashed. Fixed retention periods are enforced automatically: shopper contact details and consent records are deleted 24 months after capture, and behavioural events after 12 months — earlier if you or the shopper request deletion, which we honour within 30 days. When you uninstall the app, Shopify sends a shop-redact request 48 hours later, and we delete the shop's data on receipt.
7. Sub-processors
We rely on Shopify (the platform), our cloud hosting and database providers, and any integration you connect: Klaviyo, Mailchimp, Omnisend, WhatsApp (Meta), Google Sheets, Zapier, Make.com, or a webhook endpoint you choose. Data goes to an integration only when you enable it. A current list of sub-processors is available on request.
8. Data subject rights
Access, deletion and shop deletion run through Shopify's mandatory webhooks:
customers/data_request, customers/redact and
shop/redact. On a redact request we permanently delete the
matching leads and consent records. On a data-request we compile the data we
hold for that customer so you can respond. To exercise a right, contact the
merchant whose store collected the data, or email us and we will assist.
9. International transfers
Data is primarily stored in India. For shoppers in the EU, EEA, UK or Switzerland, we rely on Standard Contractual Clauses as the transfer mechanism, alongside the data-minimization measures described above.
10. Security
Access tokens are never exposed to the browser. Storefront traffic is authenticated via signed Shopify App Proxy requests. Shopper contact details, API access tokens and integration credentials are encrypted at rest (AES-256-GCM), and all traffic is encrypted in transit (TLS).
11. Governing law
This policy is governed by the laws of India. Any dispute is subject to the exclusive jurisdiction of the courts of Mumbai, Maharashtra.