Privacy policy

Purpose-bound data, explicit choices.

This policy explains how BuyWhen processes data when merchants install the app, shoppers submit requests, and visitors choose public-site analytics. Effective August 17, 2026.

Information we process

We process store and product identifiers, app configuration, conditional purchase requests, decision and audit records, and limited order or refund references needed to operate and measure the service. A shopper request can include contact information and the condition they chose to submit.

Why we process it

We use this information to capture and qualify requests, let the merchant respond, create private checkout offers, reconcile outcomes, prevent abuse, provide support, and meet security and legal obligations. We do not sell personal information.

Protection and access

Direct identifiers and protected checkout links are encrypted. Access is tenant-scoped and role-controlled. Logs redact tokens, contact details, and protected URLs. Service providers receive only the information needed for their contracted function.

Merchant referral attribution

When Shoffi attribution is enabled, BuyWhen sends Shoffi the authenticated merchant's .myshopify.com domain, BuyWhen's Shopify app ID, and the originating merchant IP address when the app opens. This is used only to attribute the install and prevent duplicate merchant registrations. Shopper requests, order details, credentials, and merchant cost data are not sent to Shoffi.

Retention and deletion

We retain data only while needed to provide the service, meet documented merchant settings, resolve disputes, or satisfy legal obligations. Uninstalling stops processing, revokes active offers, removes sessions, and begins retention-aware cleanup. Shopify privacy requests are handled through required privacy webhooks.

Your communication choices

Transactional updates about a specific request are separate from optional marketing. Marketing is never preselected. Channel preferences, revocations, quiet hours, and frequency controls are recorded and enforced.

Optional public-site analytics

If Google Analytics is enabled, its tag loads only after a public website visitor accepts analytics. Advertising storage, advertising user data, and ad personalization remain denied. BuyWhen does not send Shopify admin activity, private offer pages, customer portals, credentials, or direct identifiers to public-site analytics. The choice is stored locally and can be changed through “Analytics choices” in the footer.

Contact

For privacy, access, correction, export, or deletion questions, email a.lebkara@esi-sba.dz. Do not include credentials or unnecessary personal data.