Legal
Privacy Policy
How Authorizd collects, uses, shares, and protects data when a merchant installs our Shopify app and when shoppers participate in referrals.
Last updated: June 30, 2026
1. Who we are
Authorizd (“we”, “us”) provides a referral and advocacy app for Shopify stores. A shopper shares a personal referral link; their friends receive a discount and the shopper (the “advocate”) earns a commission on the orders they drive. This policy explains what data flows through the app and why. For data we process on a merchant's behalf, the merchant is the data controller and Authorizd is a data processor.
2. Data we collect
From the merchant. Your store domain, contact email, the offer settings you configure (discount and commission rates), payout configuration, and the Shopify API access token issued when you install the app (stored encrypted).
From your Shopify store, via the Shopify Admin API and webhooks. We request the read_orders, read_customers, read_discounts, and write_discounts scopes. Using them we read and store: order identifiers, order and subtotal amounts, currency, financial status, discount codes applied, and the order's timestamp; and, for orders that used a referral discount, the buyer's email, phone, and name. We create and update discount codes for referrals. We do not access payment card data — Shopify never exposes it to apps.
From advocates. Email address and the referral handle they claim. If an advocate withdraws cash earnings, payout and identity-verification (KYC) information is collected and held by our payout processor (Stripe), not by us.
3. Why we use it
We use the data above solely to operate the service: to attribute orders to the referral that produced them, calculate advocate commissions and your platform fee, create and manage referral discount codes, pay advocates, reverse commissions on refunded or fraudulent orders, send transactional notifications (for example, telling an advocate they earned), and provide support. We do not sell personal data, and we do not use buyer personal data for advertising or any purpose beyond referral attribution.
4. Shopify protected customer data
Buyer personal information (email, phone, name) is Shopify “protected customer data.” We apply data minimization: we store this information only for orders connected to a referral, use it only for attribution and the notifications described above, restrict internal access, encrypt it in transit and at rest, and retain it only as long as needed for the service or as required by law. We honor Shopify's mandatory privacy webhooks (see §7).
5. Sharing and subprocessors
We share data only with service providers that help us run the app, each bound to protect it:
- Shopify — the platform the app runs on and the source of order/customer data.
- Stripe — advocate payouts and identity verification (processes payout and KYC data as its own controller).
- PayPal — optional alternative payout method, where an advocate chooses it.
- Email delivery provider — to send transactional referral and account emails.
- Cloud hosting and database providers — to host the application and store data.
We may also disclose data where required by law or to protect against fraud or abuse. We do not sell or rent personal data.
6. Data retention
We keep merchant and referral data while the app is installed and for as long as needed to calculate and pay earnings and meet legal, tax, and accounting obligations. When you uninstall, we disconnect the integration and delete the stored access token immediately, and we delete or anonymize associated store data following Shopify's shop-redaction window (see §7).
7. Your rights and data requests
Depending on your location, you (or a buyer) may have rights to access, correct, delete, or port personal data, or to object to or restrict its processing, under laws such as the GDPR and CCPA/CPRA. Buyers should direct requests to the merchant they purchased from; Authorizd will assist the merchant in fulfilling them. We implement Shopify's mandatory compliance webhooks: on customers/redact we erase the buyer's stored identity for that store; on shop/redact we erase the store's data; and we respond to customers/data_request to help the merchant provide a buyer's data. To exercise a right or ask a question, contact us at the address below.
8. Security
Data is transmitted over TLS. Access tokens are encrypted at rest. All Shopify webhooks are verified with HMAC signatures before processing, and administrative API calls are authenticated with Shopify session tokens. Access to personal data is limited to what is necessary to operate and support the service.
9. International transfers
Our providers may process data in countries other than yours. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.
10. Children
The service is not directed to children and is intended for use by businesses and adult shoppers.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying merchants.
12. Contact
Questions, data requests, or support: noreply@authorizd.io.