Legal
Privacy Policy
Effective: July 27, 2026
1. Who this policy covers
This policy explains how Individual Entrepreneur Tetiana Holub, trading as MerchWeave (“MerchWeave”, “we”, “us”), handles personal data through MW ReorderFlow: Buy Again (the “App”). It applies to merchants and their staff who install or manage the App, and to customers who use its reorder features.
Merchants generally decide why and how their customers’ personal data is used. For that data, the merchant is the controller and MerchWeave acts as its processor or service provider. MerchWeave is an independent controller where we process merchant, staff, support, security, billing, or compliance data for our own legitimate purposes.
2. Data we process and where it comes from
The App requests Shopify permissions to read orders and products, read public product listings and inventory, and provide the App's storefront proxy route. We use those permissions only for the App functions described in this policy.
Depending on how the App is used, we process:
- Merchant and staff data: shop domain, Shopify identifiers and access session, plan status, name, email address, locale, and App settings.
- Customer and order data: Shopify customer identifier, paid-order identifier and number, order date, currency, order note, and order-line details and properties. Shopify treats customer-linked order data as protected customer data even when it does not include direct contact details. The App does not query or persist Shopify's dedicated customer name, email, phone, or postal-address fields. Order notes or line properties can contain personal data if a merchant or customer entered it there.
- Product and reorder data: product and variant identifiers, titles, prices, images, inventory and availability, selected quantities, unavailable-item replacements, upsells, rule-based recommendations, reorder links, and completion data.
- Analytics data: reorder attribution, reorder amounts, and aggregated performance metrics.
- Technical data: webhook receipt identifiers, request and error logs, request metadata such as IP address and browser user agent, and support correspondence.
We receive this data from Shopify's APIs and webhooks, merchants and their staff, and customers' actions in the reorder flow. Shopify order webhooks may contain additional fields during delivery; the App does not use or persist customer name, email, phone, or postal-address fields from those payloads. We do not receive or store payment-card details.
3. Why we use data
We use personal data to:
- authenticate shops and staff, provide the App, and maintain merchant settings;
- display eligible order lines, preflight current product availability, pricing, inventory, replacements, and quantities, then add selected lines without clearing an existing cart;
- create rule-based product recommendations, attribute completed reorders, and provide merchant analytics;
- respond to support requests, protect the App, prevent duplicate webhook processing, enforce our terms, and meet legal obligations.
For merchant and staff data, our legal bases, where applicable, are performance of a contract, compliance with law, and our legitimate interests in operating and securing the App. We process customer data on the merchant's instructions to provide the reorder service. The merchant is responsible for establishing a valid legal basis for those instructions.
Shopify account, store, order, and product data is required to provide the core service; without it, the App cannot authenticate the shop or build a reorder.
The App does not use customer data to send email or SMS reminders, create marketing audiences, or provide behavioral advertising. It does not add third-party advertising or analytics trackers to the customer reorder flow.
Recommendations are generated from merchant-configured rules and order or product data. The App does not make solely automated decisions that produce legal or similarly significant effects on a person.
4. Service providers and disclosures
We disclose data only as needed to operate the App, including to:
- Shopify, which provides the commerce platform, authentication, APIs, app billing, and customer-account surfaces;
- Hosting Ukraine LLC (ТОВ «Хостінг Україна»), which provides the virtual server and PostgreSQL infrastructure used by the App in Ukraine.
We may also disclose information when required by law, to protect rights or security, or in connection with a business transfer subject to appropriate confidentiality and data-protection obligations.
We do not sell personal data and do not use it for third-party advertising.
5. Processing locations and transfers
The App’s production server and PostgreSQL database are hosted in Ukraine. Shopify may process data in other countries under its own documented infrastructure and contractual safeguards. Where a transfer requires additional protection, we and the merchant use the measures required by applicable data-protection law.
6. Retention and deletion
We retain merchant settings, paid-order snapshots, customer and order identifiers, reorder records, and App analytics while a shop uses the App. Reorder links and their associated sessions expire after 90 days. We retain security, support, billing, or legal records only as long as needed for those purposes.
The App processes Shopify’s mandatory privacy webhooks. A customer redaction request deletes data associated with that customer. Shop redaction and App-uninstall processing delete the shop’s App data, subject to data that must be retained by law and the finite lifecycle of infrastructure backups.
Hosting Ukraine documents that PostgreSQL backups are created nightly and retain the last seven days plus the first day of the current month. Deleted information may therefore remain in a restricted backup until that backup expires and is not restored except for disaster recovery. See the provider’s PostgreSQL documentation.
7. Security
We use administrative, technical, and organizational safeguards appropriate to the data and risk, including access restrictions and transport encryption. No internet service can guarantee absolute security.
8. Your choices and rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or receive your personal data; object to certain processing; withdraw consent; and complain to a supervisory authority. These rights may be limited by law.
Customers should normally submit requests to the merchant whose store they used because that merchant controls the customer relationship. Merchants and staff, or customers who cannot reach a merchant, may contact us. We may need to verify identity and coordinate with the relevant merchant before acting.
9. Changes and contact
We may update this policy when the App, our providers, or legal requirements change. We will post the revised policy here with a new effective date and provide additional notice when required.
For privacy questions or requests, email support@merchweave.net, or write to Individual Entrepreneur Tetiana Holub, trading as MerchWeave, Svobody 4, Kropyvnytskyi, 25020, Ukraine.