Privacy policy
Purpose-bound data, explicit choices.
This policy explains how BuyWhen processes data when merchants install the app, shoppers submit requests, and visitors choose public-site analytics. Effective August 17, 2026.
Information we process
We process store and product identifiers, app configuration, conditional purchase requests, decision and audit records, and limited order or refund references needed to operate and measure the service. A shopper request can include contact information and the condition they chose to submit.
Why we process it
We use this information to capture and qualify requests, let the merchant respond, create private checkout offers, reconcile outcomes, prevent abuse, provide support, and meet security and legal obligations. We do not sell personal information.
Protection and access
Direct identifiers and protected checkout links are encrypted. Access is tenant-scoped and role-controlled. Logs redact tokens, contact details, and protected URLs. Service providers receive only the information needed for their contracted function.
Merchant referral attribution
When Shoffi attribution is enabled, BuyWhen sends Shoffi the authenticated merchant's .myshopify.com domain, BuyWhen's Shopify app ID, and the originating merchant IP address when the app opens. This is used only to attribute the install and prevent duplicate merchant registrations. Shopper requests, order details, credentials, and merchant cost data are not sent to Shoffi.
Retention and deletion
We retain data only while needed to provide the service, meet documented merchant settings, resolve disputes, or satisfy legal obligations. Uninstalling stops processing, revokes active offers, removes sessions, and begins retention-aware cleanup. Shopify privacy requests are handled through required privacy webhooks.
Your communication choices
Transactional updates about a specific request are separate from optional marketing. Marketing is never preselected. Channel preferences, revocations, quiet hours, and frequency controls are recorded and enforced.
Optional public-site analytics
If Google Analytics is enabled, its tag loads only after a public website visitor accepts analytics. Advertising storage, advertising user data, and ad personalization remain denied. BuyWhen does not send Shopify admin activity, private offer pages, customer portals, credentials, or direct identifiers to public-site analytics. The choice is stored locally and can be changed through “Analytics choices” in the footer.
Contact
For privacy, access, correction, export, or deletion questions, email a.lebkara@esi-sba.dz. Do not include credentials or unnecessary personal data.