This Policy is designed to align with the EU/EEA and UK GDPR, the EU ePrivacy Directive (as implemented by Member States), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), other applicable US state privacy laws with similar frameworks, and Shopify App Store privacy requirements. It is not legal advice. Merchants remain responsible for their own storefront disclosures and lawful basis toward shoppers.
This Privacy Policy describes how Fixiby processes personal data when:
| Category | Examples | Typical source |
|---|---|---|
| Merchant / shop identifiers | Shop domain, Shopify shop ID, OAuth session tokens, plan flags, admin language, accent and placement settings | Shopify OAuth / App APIs; merchant input |
| Offer & catalog configuration | Product/variant GIDs, offer rules, discount metadata, A/B labels | Merchant configuration; Shopify Admin API |
| Performance analytics (privacy-first) | Offer views, clicks, conversions, attributed revenue counters; optional order IDs for deduplication | Storefront / checkout extension events; Shopify order webhooks when enabled |
| Shopper PII | Core App flows are designed not to store shopper name, email, phone, address, or payment card data in App databases | N/A for core upsell delivery |
| Technical / security data | IP address (approx.), user-agent, timestamps, error logs, request paths | Automatic when using App / site |
| Support content | Messages and attachments sent to info@fixiby.com | You |
Subscription payments are processed by Shopify App Billing. We do not store full payment card numbers.
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provide, authenticate, and bill the App; maintain merchant sessions | Contract (Art. 6(1)(b)) with the merchant |
| Security, fraud/abuse prevention, debugging | Legitimate interests (Art. 6(1)(f)) — secure SaaS operation |
| Respond to GDPR webhooks and legal requests | Legal obligation (Art. 6(1)(c)) |
| Product improvement using aggregated metrics | Legitimate interests (Art. 6(1)(f)), balanced against rights |
| Support communications | Contract and/or legitimate interests |
| Non-essential cookies on marketing pages (if used) | Consent (Art. 6(1)(a)) where required — see Cookie Policy |
Where we act as processor, the merchant determines the purpose and lawful basis toward shoppers (often contract or legitimate interests for on-site product recommendations). Merchants must provide required notices and, where needed, obtain consent for non-essential cookies/trackers on their storefront.
For personal information of California residents that we control:
If you are a shopper, please contact the merchant first; we will assist the merchant as their service provider.
See our dedicated Cookie Policy. Essential storage may be required for Shopify admin sessions and App Bridge. We do not use advertising pixels in the core App. Merchants must configure their own storefront consent banners under ePrivacy / GDPR.
We share data only as needed with:
A current high-level list of infrastructure categories is maintained in the DPA. We do not permit subprocessors to use merchant personal data for their own marketing.
Personal data may be processed in the United States, the European Economic Area, the United Kingdom, and other regions where our providers operate. Where GDPR/UK GDPR requires a transfer mechanism, we rely on adequacy decisions and/or Standard Contractual Clauses (SCCs) / UK IDTA or Addendum offered by providers, plus supplementary measures where appropriate.
We apply reasonable technical and organizational measures including TLS in transit, access controls, least-privilege Shopify scopes, and separation of environments. No method of transmission or storage is completely secure. Merchants must protect Shopify admin credentials and enable available platform security features.
Subject to applicable law, you may have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent where processing is consent-based. You may lodge a complaint with your local supervisory authority (for example, an EU Member State DPA or the UK ICO).
Requests: info@fixiby.com. Shoppers should contact the merchant; we support mandatory Shopify privacy webhooks (customers/data_request, customers/redact, shop/redact).
The App may recommend products using rules and/or algorithmic ranking configured by the merchant. These features are intended to assist shopping decisions on the merchant’s storefront and are not used by Fixiby to make legal or similarly significant decisions about individuals solely by automated means without human involvement on Fixiby’s side.
The App is directed to business users (merchants). It is not intended for children under 16 (or under 13 where US COPPA applies to Fixiby-controlled properties). We do not knowingly collect children’s data via the App.
Because we do not sell or share personal information for cross-context behavioral advertising, we treat GPC signals as confirming our existing non-sale / non-share practice for Fixiby-controlled properties.
We may update this Policy by posting a revised version at this URL and updating the “Last updated” date. Material changes affecting merchants will be highlighted via App listing / admin notice where reasonably practicable.
Fixiby Software Technologies (independent developer)
Email: info@fixiby.com
Web: https://fixibay.com · https://fixibay.vercel.app