Privacy policy
Last updated 3 September 2026
This Privacy Policy explains how Foxr (“Foxr”, “we”, “us”) collects, uses, stores, and deletes information when you visit www.foxr.app, contact us, or install a Foxr Shopify app — including Foxr Post Purchase Upsell.
Foxr is a Shopify apps company. We take privacy seriously because merchants only install an upsell app if they can trust how order and customer data is handled.
We do not sell personal information. We do not share shopper contact details with advertisers. Foxr is not an ad network.
Who we are
Foxr provides Shopify applications that show offers after checkout: on Shopify’s native post-purchase page, on the thank-you / order status page, and (on Shopify Plus) in checkout. The merchant installs the app, configures funnels, and we process store data as needed to run those offers and report on them.
For the marketing website, Foxr is the controller of visitor information (for example, an email you send us). For data inside a merchant’s Shopify store, the merchant is the controller and Foxr is a processor acting on the merchant’s instructions, within Shopify’s platform rules. We follow Shopify’s mandatory GDPR / privacy compliance webhooks for every public app.
Contact: hello@foxr.app.
What this policy covers
This policy applies to:
- Visitors to the Foxr website and people who email or message us
- Merchants and staff who install or use a Foxr app in Shopify admin
- Shoppers on a merchant’s store, to the limited extent the app processes their order so an offer can be shown or attributed
This policy does not apply to:
- Shopify’s own processing (see Shopify’s privacy policy)
- The merchant’s storefront privacy policy, checkout, or email tools
- Third-party apps a merchant connects (for example Judge.me), except for the encrypted token we store to talk to that service
What we mean by personal information
“Personal information” means information that identifies, relates to, or could reasonably be linked to a person or household — including contact details, online identifiers, and data that becomes identifying when combined with other data. It includes what privacy laws call “personal data”.
Information we collect
From merchants (when you install or use a Foxr app)
Shopify and the app provide:
- Shop domain, Shopify plan context, and OAuth session (including staff user id and email required to keep you signed in)
- Shop owner name, email, phone, and country for billing and support
- Funnel, offer, widget, translation, and settings you configure
- Billing and subscription status for your Foxr plan
From the merchant’s store (to run offers and analytics)
We process only what the product needs:
- Order id, order name, checkout token, line items, tags, discount codes, payment gateway name, and shipping method
- Minimised shipping location: country, province/state, and city — not street address or postal code
- Customer id, and, at evaluation time, customer tags and order count (used in memory for triggers such as “first order” or “VIP tag”)
- Anonymous session id, device class (mobile or desktop), and offer impression / accept / decline events
The shopper’s first name used in merge tags such as {first-name} is read from checkout for that request and substituted into the response. It is not stored in our offer cache.
From shoppers on this website
- Information you choose to send (name, email, message) if you contact us
- Standard host logs that Vercel may keep for security and uptime (IP address, user agent, requested path)
The marketing site does not require an account. It does not currently set marketing cookies.
From support chat
If you open Crisp chat inside the Foxr admin, Crisp receives your shop domain and the shop owner email so we can reply. That chat is for merchants, not storefront shoppers.
What we do not collect or store
Foxr apps do not store:
- Shopper names, email addresses, or phone numbers
- Street addresses or postal codes
- Payment card numbers, CVV, or full payment credentials
- Shopper IP address or raw user agent as personal identifiers
- The full Shopify webhook payload — it is parsed in memory and discarded
Buyer names, emails, phones, and addresses are not written to application logs. Order ids and shop domains may appear in logs for debugging.
How we use information
We use information to:
- Authenticate the app, keep your admin session, and honour Shopify OAuth
- Match the right funnel (product, cart, customer, market, shipping, UTM, and similar rules you configure)
- Render post-purchase, thank-you, and checkout offers
- Add accepted upsell items to the order through Shopify APIs
- Show analytics (impressions, accepts, revenue) and an order-level attribution browser
- Bill your plan and provide merchant support
- Detect abuse, keep the service secure, and comply with law (including Shopify’s mandatory privacy webhooks)
- Improve the product using aggregated, non-identifying metrics
We do not use shopper data to advertise Foxr to those shoppers. We do not sell or rent merchant or shopper lists.
Legal bases (EEA, UK, and similar laws)
Where GDPR or UK GDPR applies:
- Contract. Processing needed to provide the app you installed (offers, analytics, billing).
- Legitimate interests. Security, fraud prevention, product reliability, and answering support — balanced against people’s rights.
- Legal obligation. Shopify privacy webhooks, tax or accounting records, and enforceable legal process.
- Consent. Only where we ask for it (for example if we later add optional marketing cookies on this website).
When we process shopper data as a processor, the merchant’s legal basis (typically performance of their checkout contract and legitimate interests in offering a relevant add-on) sits with the merchant.
How we share information
We disclose information only:
- To Shopify, as required to run checkout, post-purchase, order edits, and app billing
- To the sub-processors listed below, under contract, to host and operate the app
- To a merchant’s connected integration (for example Judge.me) when the merchant turns that connection on
- If required by law, subpoena, or to protect Foxr, merchants, or shoppers from fraud or harm
- As part of a merger, acquisition, or sale of assets, with the same protections continuing or notice given
We do not disclose shopper contact details to advertisers so they can send email or SMS. Foxr does not operate a third-party offer network of that kind.
Sub-processors
These providers process data on our behalf for the Shopify apps. The marketing website is hosted separately on Vercel.
| Provider | Purpose | Data |
|---|---|---|
| MongoDB Atlas | Primary database | App data described in this policy |
| Fly.io | Application hosting for Foxr apps | Request traffic and application logs |
| Vercel | Hosting for this website | Site requests and host logs |
| Shopify | Commerce platform, App Bridge, billing | Admin session and store APIs |
| Crisp | Merchant support chat in admin | Shop domain, shop owner email |
| Judge.me | Reviews, only if the merchant connects it | Product ids; merchant token stored encrypted |
Third-party tokens (such as Judge.me) are encrypted at rest with AES-256-GCM. Encryption in transit is TLS. Database encryption at rest is provided by MongoDB Atlas.
International transfers
We and our sub-processors may process information in the United States and other countries. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the provider’s standard contractual clauses or an adequacy decision, as applicable.
How long we keep information
| Data | Retention |
|---|---|
| Raw offer impressions | 400 days (automatic TTL) |
| Offer cache | Until the row’s expiry (short-lived) |
| Order records, events, analytics | For the life of the install; deleted on uninstall redact or a customer redact |
| Sessions and shop settings | Until uninstall |
| GDPR fulfilment audit | 400 days — a minimal record that a specific erasure request was completed |
| Website contact emails | As long as needed to reply and keep a support record |
When you uninstall a Foxr app, Shopify sends a shop redaction request (typically 48 hours later). We then delete shop-scoped data. Customer data-access and erasure requests that Shopify sends us are honoured automatically.
Shopify GDPR and privacy compliance
Foxr follows Shopify’s privacy requirements for App Store apps. Shopify requires the same data-subject rights for all personal data, regardless of where the individual is located. We subscribe to and verify Shopify’s mandatory compliance webhooks, respond to valid deliveries with a 200-series status, and reject invalid HMAC signatures with 401 Unauthorized.
We complete each request within 30 days of receiving it, unless we are legally required to retain a specific record.
| Shopify topic | When it is sent | What Foxr does |
|---|---|---|
customers/data_request | A customer asks the store owner for their data. Shopify sends the customer id, email, phone, and related order ids to installed apps that have customer or order access. | We look up what we store for that customer and those orders, and provide it to the store owner. This app does not store shopper email or phone; the merchant already has those in Shopify. |
customers/redact | The store owner requests deletion on behalf of a customer. If the customer has ordered in the last six months, Shopify may delay the payload until six months have passed; otherwise it is sent after 10 days. | We delete or redact customer-keyed and order-keyed rows for the listed customer id and orders_to_redact. |
shop/redact | 48 hours after the merchant uninstalls the app, Shopify sends the shop id and shop domain. | We erase all data for that shop from our database. |
Learn more in Shopify’s documentation on privacy law compliance and Shopify’s privacy policy.
Security
We take technical and organisational measures including:
- TLS for data in transit
- Encryption at rest at the database provider
- Additional encryption for third-party integration tokens
- Minimising stored fields (no full shipping address, no shopper email)
- Access limited to staff who need it to operate or support the product
- HMAC verification of Shopify webhooks before we act on them
No method of storage or transmission is 100% secure. If we become aware of a breach that requires notice, we will notify affected merchants and regulators as the law requires.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or restrict personal information we hold; to object to certain processing; to portability; and to withdraw consent where we rely on it. You may also complain to a data protection authority.
Shoppers. Start with the store you bought from. The merchant is the controller of their checkout. You can also use Shopify’s tools. If we receive a verified request through Shopify webhooks, we fulfil it as described above.
Merchants and website visitors. Email hello@foxr.app with enough detail for us to find your shop or message. We will take reasonable steps to verify the request. We will not discriminate against you for exercising privacy rights.
We may deny or limit a request where the law allows — for example to keep a fraud or GDPR-fulfilment audit, or if we cannot verify who you are.
Additional disclosures for California residents
If you are a California resident, this section supplements the rest of this policy under the CCPA/CPRA.
Categories we may collect, depending on how you interact with Foxr:
- Identifiers — merchant staff email, shop domain, shopper customer id (not shopper email)
- Commercial information — orders, line items, offer accepts, plan and billing status
- Internet activity — admin use of the app; anonymous offer impressions on the storefront
- Approximate location — shipping country / province / city for an order
Sources: you, Shopify APIs and webhooks, and the sub-processors above. Business purposes: providing the app, security, analytics for the merchant, and legal compliance.
We do not sell personal information and we do not share it for cross-context behavioural advertising. Foxr does not run third-party ad pixels on the storefront for our own advertising. We do not knowingly sell or share the personal information of people under 16.
We do not use or disclose sensitive personal information to infer characteristics about shoppers. Merchant login credentials for Shopify are handled through Shopify OAuth.
To request access or deletion, email hello@foxr.app. You may use an authorised agent; we will still need to verify the request. We will respond within the time the law requires.
Children
Foxr apps are for merchants. They are not directed at children under 13 (or 16 where that is the relevant age). We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
Cookies and tracking
This website. We do not currently set marketing or advertising cookies. If we add analytics later, we will name the tool here and, where required, ask for consent.
Foxr apps. The admin runs inside Shopify and uses Shopify App Bridge. Storefront offer pages may set an anonymous session identifier so we can attribute an impression or accept to a funnel — not to profile shoppers for ads. We do not use session-replay tools on the admin.
Shopify and the merchant’s theme may set their own cookies. Those are governed by Shopify and the merchant, not by this policy.
What this policy does not cover
If a shopper accepts an offer, the product they buy is the merchant’s product, fulfilled on Shopify. The merchant’s privacy policy governs how that merchant uses customer information beyond Foxr. We are not responsible for other organisations we do not control.
Changes
We may update this policy when the apps or this website change. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of the website or apps after an update means the new policy applies to that use.
Whom to contact
Privacy questions, access, and deletion requests: hello@foxr.app.
Shoppers should start with the merchant they purchased from, or use Shopify’s tools. Customer access and erasure for store data are processed through Shopify’s GDPR webhooks as described above.
Public policy URL for Shopify App Store listing and app privacy settings: https://www.foxr.app/policies/privacy-policy.
