This policy covers this website and every Shopyra app for Shopify. It replaces the separate policies previously published for Slidify — Shoppable Sliders and TapTalk — Multi Agent WhatsApp, which were issued while those apps ran under an individual developer account. Consolidating them has not loosened anything about how your data is handled.
By installing a Shopyra app or using this site, you agree to what is described here. If you do not, uninstall the app and stop using the site — and email us first if you want your data removed.
1. Who we are
Shopyra builds and operates apps for the Shopify platform. The operator and data controller is Zakaria Binsaifullah, trading as Shopyra, who leads a team of 3. Shopyra is a small independent product team, not a large company — the people who decide what happens to your data are the same people who write the code and answer your support email.
Contact for anything in this policy, including data requests: [email protected]. A postal address is available on request to the same address.
Which role we play matters. For data collected through this website we are the controller — we decide what is collected and why. For data inside your store that our apps read or store, you are the controller and we are a processor acting on your instructions. That distinction decides who answers a shopper’s request: you do, and we will help you do it.
2. What this website collects
- No analytics, no advertising, no third-party trackers. This site runs no analytics product of any kind. Nobody is profiled and nothing is shared with an ad network.
- Your theme preference is written to your own browser’s local storage. It never reaches our servers.
- Contact form. We receive the name, email address, optional store URL, topic and message you type, plus the country the request came from. It is delivered to us as email rather than stored in a database.
- Newsletter. If you subscribe we store your email address, the date, and the country the signup came from, until you ask to be removed.
- Bot protection. The contact form uses Cloudflare Turnstile to check that a submission comes from a person. Turnstile receives your IP address for that check. It sets no advertising cookie and does not track you across sites.
- Abuse prevention. Both forms are rate limited by IP address. The address is used for that check and for standard server logs, not to build a profile of you.
3. What our apps collect
Every app requests the minimum Shopify API scopes it needs, and Shopify shows you those scopes before you approve the install. Across all apps we handle your store’s domain and ID, the access token Shopify issues, the configuration you create, and your subscription status. Card details are handled by Shopify Billing and never reach us.
Slidify — Shoppable Sliders
- Product data read from your store — titles, images, prices, variants, collections and availability — used solely to render sliders on your storefront.
- The slider configuration you create: layouts, content, ordering and styling choices.
- Aggregated storefront interaction counts such as slider impressions, clicks and hotspot taps, used to populate your dashboard.
- A small amount of local storage on the storefront to remember a visitor’s position in a story slider. It holds no identifying information.
TapTalk — Multi Agent WhatsApp
- The agent profiles you enter: names, role labels, WhatsApp numbers and avatars.
- Your widget configuration: colours, business hours, routing rules and message templates.
- Lead form submissions from shoppers who choose to complete the after-hours form — name, the contact detail they provide, and an optional order number.
- Aggregated widget analytics: open counts, click counts, page URLs and timestamps, not linked to individual shoppers.
- Order numbers are verified against your store only when the Order Lookup feature is used.
- Chats happen on WhatsApp via a standard wa.me link. We send no data to Meta ourselves; once the shopper arrives on WhatsApp, Meta’s own policy governs the conversation.
- If you configure a Slack webhook or notification email, lead submissions are delivered there. You control whether that is switched on.
- One session-level cookie or local storage entry recording whether a shopper dismissed the consent overlay, so they are not asked twice.
Tabilo — Ultimate Table Builder
- Product data read from your store — titles, descriptions, images and handles, variants and options, prices and compare-at prices, inventory levels and availability, and collection names with their product membership — used solely to build your tables and keep them accurate.
- Product metafields, but only the ones a table you have built actually draws on.
- The tables you create: layouts, patterns, styling, column selections, measurement values and assignment rules.
- Any table content you type in yourself or import from a CSV.
- Nothing about your shoppers. Tables render through a Shopify theme app extension, and the app collects no personal information about the people who view them.
Our apps do not collect shopper names, email addresses, payment details or browsing history beyond what is described above, do not track shoppers between websites, and do not build shopper profiles.
4. Why we process it
- To make the apps work — rendering your content on your storefront.
- To show you your own analytics inside the app admin.
- To process billing through Shopify.
- To answer your support messages and send service or security notices.
- To fix bugs, watch performance, and decide what to build next.
- To detect and stop abuse.
- To meet legal obligations where we are lawfully required to.
We do not sell your data or your shoppers’ data, and we do not use it to train AI models — ours or anyone else’s.
Our lawful bases under GDPR are: performance of our contract with you when you install an app or contact us; our legitimate interest in operating, securing and improving the service; your consent where you have given it, such as subscribing to the newsletter; and legal obligation where one applies.
5. Who we share it with
We share data only in these situations:
- Subprocessors — the providers listed in section 6.
- Services you switch on yourself — for example a Slack webhook or notification email you configure in TapTalk. That integration runs only because you enabled it.
- When the law requires it — a valid court order or subpoena, or a genuine need to protect someone’s safety.
If Shopyra or any of its apps is ever transferred to another operator or company, affected merchants will be emailed at least 30 days beforehand, with time to uninstall before the transfer takes effect.
6. Subprocessors
Each of these is bound by its own data processing terms:
- Shopify Inc. — App platform, authentication, billing, and the APIs our apps read from. Canada / United States.
- Cloudflare, Inc. — Website hosting and CDN, contact form delivery via Email Routing, newsletter storage, and Turnstile bot protection. Global edge network.
If we add or remove a subprocessor we update this page, and email active merchants when the change affects app data. Ask us at [email protected] for the current list at any time.
7. Storage, security and transfers
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to production systems is limited to the Shopyra team, on a need-to-have basis and protected by two-factor authentication. We request the narrowest Shopify API scopes each app can work with, keep dependencies patched, and monitor for unusual activity.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority promptly, as the law requires.
Our providers operate globally, so data may be processed outside your country, including outside the EEA and UK. Where that happens we rely on the safeguards those providers have in place, such as the European Commission’s Standard Contractual Clauses. Request details at [email protected].
8. How long we keep it
- While an app is installed — for as long as needed to run it.
- After you uninstall — shop data is deleted within 48 hours, triggered by Shopify’s
shop/redactwebhook. Access tokens stop working immediately on uninstall. - Shopper deletion requests — actioned within 30 days of a verified
customers/redactwebhook. - App analytics — deleted automatically 90 days after they are recorded.
- Lead form submissions — kept until you delete them from your app admin, or until you uninstall.
- Newsletter subscriptions — until you ask to be removed.
- Support correspondence — kept so we have context on prior conversations.
- Billing and tax records — for as long as tax law requires.
- Aggregated, anonymised figures — kept indefinitely, because they can no longer be connected to you.
You can ask for earlier deletion at any time.
9. Shopify’s mandatory privacy webhooks
Every Shopyra app implements the three webhooks Shopify requires, and they run automatically:
customers/data_request— we compile everything held about that shopper and provide it within 30 days.customers/redact— we permanently delete everything held about that shopper.shop/redact— sent 48 hours after uninstall; we permanently delete everything held about that shop.
You do not need to do anything to trigger these.
10. Your rights
Wherever you live, email [email protected] and we will action your request. We respond within 30 days, we do not charge, and we will not ask you to justify it.
If you are in the EU, EEA or UK, GDPR gives you the right to access your data, correct it, erase it, restrict or object to how we process it, receive it in a portable format, and withdraw consent at any time. You may also complain to your local data protection authority — the list is at edpb.europa.eu.
If you are a California resident, the CCPA and CPRA give you the right to know what is collected and shared, to delete it, to correct it, to limit the use of sensitive information, and not to be treated differently for exercising those rights. There is no opt-out of sale or sharing to exercise here, because we do not sell or share personal information for cross-context behavioural advertising.
Elsewhere — including under Brazil’s LGPD, Canada’s PIPEDA and Australia’s Privacy Act — we honour the equivalent rights on a verified request.
11. Cookies
This website sets no cookies of its own. Your theme preference lives in local storage on your own device. Cloudflare Turnstile may set a short-lived token on the contact page purely to complete its bot check.
On storefronts, our apps use local storage or a session cookie only for functional purposes — remembering where a visitor got to in a story slider, or that they already dismissed a consent overlay. No advertising or cross-site tracking cookies are set by any Shopyra app.
12. Children
Our apps are business tools sold to merchants and are not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child’s data reached us through one of our apps — for example through a lead form on a storefront — email [email protected] and we will delete it promptly.
13. Links to other sites
Content rendered by our apps may link to products and pages inside the merchant’s own store, and this site links to Shopify and other third parties. Those destinations have their own privacy policies, and we are not responsible for them.
14. Changes to this policy
When this policy changes we update the date at the top of the page. For material changes we email active merchants at least 14 days before the change takes effect, rather than relying on you to re-read this page. Continuing to use the apps or the site after that date means you accept the revised policy. Previous versions are available on request.
15. Contact
Questions, data requests, or anything else about this policy: [email protected]. A real person reads it.