Legal
Privacy Policy
This Privacy Policy explains how Email Marketing tool (“we”, “us”, or “our”), a Shopify application available at https://email-campaign-liart.vercel.app, collects, uses, stores, and shares information when merchants install and use our email campaign services, and when emails are sent to their contacts (“subscribers” or “recipients”).
We designed this policy for transparency and for Shopify App Store review. By installing or using the App, the merchant (“you”) agrees to this Policy. If you do not agree, do not install or use the App.
1. Who we are
Email Marketing tool is a Shopify embedded app that helps merchants design, send, and track email marketing campaigns to their own audiences (for example, contacts imported from a customer CSV or managed in audience lists within the App).
Primary service URL: https://email-campaign-liart.vercel.app
2. Scope of this Policy
This Policy covers:
- Data processed when a Shopify merchant installs, configures, or uses the App inside Shopify Admin;
- Merchant account and shop identifiers we receive from Shopify;
- Contact and campaign data the merchant uploads or creates in the App (including email addresses, names, list membership, subscription status, and campaign content);
- Technical and delivery data generated when campaigns are sent (for example delivery, bounce, open, and click events, where enabled);
- Limited information collected if you contact us for support (including via our in-app chat widget).
This Policy does not govern Shopify’s own processing of merchant or customer data under Shopify’s privacy terms, or the merchant’s own privacy practices toward their storefront customers. Merchants remain responsible for their storefront privacy notices and for lawful collection of marketing consent from recipients.
3. Roles: merchant vs. us
For subscriber and campaign content data that merchants upload or generate in the App, we typically act as a service provider / data processor on behalf of the merchant (the controller). The merchant decides what contacts to import, which audiences to target, what emails to send, and how consent was obtained.
For App account, billing-related identifiers (if any), security logs, and our own support operations, we act as an independent controller of that limited business data.
4. Information we collect
4.1 From Shopify (merchant / shop data)
When you install the App, Shopify provides information needed to authenticate and operate the App, which may include:
- Shop domain and shop identifiers;
- Offline access token (stored securely to call Shopify APIs as permitted by the scopes you approve);
- Information associated with App installation, uninstallation, and scope updates via Shopify webhooks.
Current App scopes are limited to what is declared in our Shopify app configuration (for example product/metaobject-related scopes where used). We do not request access we do not need for stated features.
4.2 Contact and audience data (provided by the merchant)
Merchants may import or manage contacts used for email campaigns, including:
- Email address (required);
- First name and last name (if provided);
- Subscription / unsubscribe status and list (audience) membership;
- Metadata related to import source (for example CSV file contents the merchant uploads).
We expect merchants to import only contacts they are legally permitted to email, and to honor applicable marketing laws (including CAN-SPAM, CASL, GDPR, and similar rules).
4.3 Campaign and sending data
- Campaign name, subject line, preview text, from name, from email, reply-to address, and email template/HTML content;
- Selected audience lists and recipient counts at send time;
- Sending domain configuration and DNS verification status (for example domain identity records used with our email delivery provider);
- Message identifiers and delivery-related events (sent, delivered, bounced, complained, opened, clicked — where tracking is enabled and available).
4.4 Usage and technical data
- App usage logs (for example errors, authentication events, and operational telemetry needed to keep the service reliable);
- Standard server logs (IP address, user agent, timestamps) when you access public pages such as this Privacy Policy or our login landing page;
- Support chat metadata if you contact us through our chat widget (message content you choose to send, timestamps, and basic device/browser information processed by our chat provider).
4.5 Data we do not intentionally collect
We do not knowingly collect government ID numbers, payment card PAN data, or sensitive special-category data through the App’s email-campaign features. Please do not upload such data in CSV imports or campaign content.
5. How we use information
We use information to:
- Provide, operate, and improve the App’s email campaign features (import contacts, manage audiences, design templates, queue and send campaigns, show send status and basic analytics);
- Authenticate merchants via Shopify and maintain App sessions;
- Configure and verify sending domains and deliver mail through our email infrastructure partners;
- Enforce anti-abuse and fair-use controls (for example trial sending limits or temporary freezes) to protect deliverability and reduce spam risk;
- Respond to support requests and diagnose technical issues;
- Comply with law, enforce terms, and protect the security and integrity of the App, merchants, and recipients;
- Meet Shopify App Store and platform requirements, including responding to uninstall and data-deletion obligations.
We do not sell personal information. We do not use merchant subscriber lists to market our own products to those subscribers, and we do not rent or trade subscriber lists.
6. Consent, opt-in, and unsubscribe
Email Marketing tool is built for permission-based email marketing. Merchants are responsible for ensuring that each recipient has provided appropriate consent (opt-in) or another lawful basis before campaigns are sent, and for keeping consent records.
- Merchant responsibility. You must only import and target contacts you are allowed to email. CSV imports and audience tools do not by themselves create legal consent.
- Subscription status. The App supports subscribed / unsubscribed flags so merchants can exclude recipients who should not receive marketing mail.
- Unsubscribe. Merchants must provide a clear unsubscribe mechanism in marketing messages as required by law. When an unsubscribe is recorded in the App (or processed via supported complaint/unsubscribe signals from the mail provider), we use that status to help suppress future sends to that contact within the App.
- Transactional vs. marketing. This App is primarily for marketing campaigns. Do not use it to circumvent consent requirements.
If you are a recipient and believe you received email in error, use the message’s unsubscribe link or contact the merchant who sent the campaign. You may also contact us (Section 14) and we will help route the request to the relevant merchant where feasible.
8. Retention and deletion
We retain information only as long as needed for:
- Providing the App to the merchant;
- Legitimate security, abuse-prevention, and audit needs;
- Legal compliance and dispute resolution.
Uninstall. When a merchant uninstalls the App, we receive an uninstall webhook from Shopify. We then delete or de-identify shop-associated App data (including contacts, lists, campaigns, and related records) within a reasonable period, except where we must retain limited records for legal, security, or accounting reasons (for example proof of deletion requests or fraud prevention logs).
Merchant-initiated deletion. Merchants may request deletion of their App data by contacting us (Section 14). We will verify the request and delete or anonymize personal data we hold for that shop, subject to legal exceptions.
9. Security
We implement administrative, technical, and organizational measures designed to protect personal data, including encrypted transport (HTTPS), access controls, and least-privilege handling of Shopify tokens and database credentials. No method of transmission or storage is 100% secure; we work to continually improve our safeguards.
Merchants should also protect their Shopify Admin accounts (strong passwords, two-factor authentication) and avoid uploading unnecessary personal data.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, or restrict certain personal data, or to object to certain processing. Merchants can often manage contact and campaign data directly in the App. For other requests, contact us (Section 14).
If you are a subscriber of a merchant, please contact that merchant first — they control the marketing relationship. We will assist merchants in fulfilling verified requests that relate to data stored in our systems.
Where required, you may also lodge a complaint with your local data protection authority.
11. International transfers
We may process and store information in the United States and other countries where we or our providers operate. Those locations may have different data-protection laws than your jurisdiction. Where required, we use appropriate transfer mechanisms and contractual protections with processors.
12. Children’s privacy
The App is intended for use by businesses and is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal data through the App, contact us and we will take appropriate steps.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL and revise the “Last updated” date above. Material changes may also be communicated through the App or Shopify’s usual App channels where appropriate. Continued use of the App after an update constitutes acceptance of the revised Policy.
14. Contact us
For privacy questions, data requests, or concerns about this Policy, contact us:
- In-app: Open Email Marketing tool in Shopify Admin and use Contact support (chat) from Settings or the support widget.
- App URL: https://email-campaign-liart.vercel.app
- This Policy: https://email-campaign-liart.vercel.app/privacy
Please include your shop domain (for example your-store.myshopify.com) so we can locate the correct records.