Last updated: July 2, 2026
Promptly ("we", "our", "us") is a Shopify application that helps merchants capture email and SMS subscribers through popup experiences. This privacy policy explains how we collect, use, and protect information.
When a merchant installs Promptly, we access limited Shopify store data as authorized through the Shopify OAuth process. This includes:
We do not sell, rent, or share personal data with third parties for their marketing purposes. Data may be shared with:
We retain merchant and subscriber data for as long as the app is installed, or for a shorter retention window the merchant selects in the app's settings (90 days to 2 years) — older subscriber and analytics records are then permanently deleted by an automated daily process. When a merchant uninstalls the app, or on a shop data-erasure request, we delete all associated store data within 30 days (the app's data-erasure webhook deletes it promptly on receipt, and an automated backstop purges any store that remains uninstalled). On an individual customer erasure request we erase that customer's personal data and instruct the merchant's connected marketing platforms to do the same. Aggregated, anonymized analytics data may be retained. Merchants can also disable Shopify customer sync at any time in the app settings.
We use industry-standard security measures including encrypted connections (TLS/SSL), encryption of data at rest and of backups, secure authentication via Shopify OAuth, AES-256 application-layer encryption of stored credentials and of subscriber contact details (email addresses and phone numbers), least-privilege access, separation of test and production environments, and an auditable log of access to personal data. Full detail is in our Security & Incident Response Policy. Our data-processing terms with merchants are set out in our Data Processing Agreement.
We comply with GDPR and respond to data access, correction, and deletion requests. Merchants and their customers can contact us to exercise their data rights. We support Shopify's mandatory GDPR webhooks for customer data requests, customer data erasure, and shop data erasure. If we become aware of a personal data breach, we notify affected merchants without undue delay (see our Security & Incident Response Policy).
Promptly uses session cookies for authentication within the Shopify admin. Our storefront widget uses a localStorage identifier to track anonymous visitor sessions for popup targeting. No third-party tracking cookies are used.
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date.
If you have questions about this privacy policy or your data, contact us at: support@promptlyapp.co