NEWFoxr Post Purchase Upsell is live — one-click offers after checkout.
Legal

Privacy policy

Last updated 3 September 2026

This Privacy Policy explains how Foxr (“Foxr”, “we”, “us”) collects, uses, stores, and deletes information when you visit www.foxr.app, contact us, or install a Foxr Shopify app — including Foxr Post Purchase Upsell.

Foxr is a Shopify apps company. We take privacy seriously because merchants only install an upsell app if they can trust how order and customer data is handled.

We do not sell personal information. We do not share shopper contact details with advertisers. Foxr is not an ad network.

Who we are

Foxr provides Shopify applications that show offers after checkout: on Shopify’s native post-purchase page, on the thank-you / order status page, and (on Shopify Plus) in checkout. The merchant installs the app, configures funnels, and we process store data as needed to run those offers and report on them.

For the marketing website, Foxr is the controller of visitor information (for example, an email you send us). For data inside a merchant’s Shopify store, the merchant is the controller and Foxr is a processor acting on the merchant’s instructions, within Shopify’s platform rules. We follow Shopify’s mandatory GDPR / privacy compliance webhooks for every public app.

Contact: hello@foxr.app.

What this policy covers

This policy applies to:

  • Visitors to the Foxr website and people who email or message us
  • Merchants and staff who install or use a Foxr app in Shopify admin
  • Shoppers on a merchant’s store, to the limited extent the app processes their order so an offer can be shown or attributed

This policy does not apply to:

  • Shopify’s own processing (see Shopify’s privacy policy)
  • The merchant’s storefront privacy policy, checkout, or email tools
  • Third-party apps a merchant connects (for example Judge.me), except for the encrypted token we store to talk to that service

What we mean by personal information

“Personal information” means information that identifies, relates to, or could reasonably be linked to a person or household — including contact details, online identifiers, and data that becomes identifying when combined with other data. It includes what privacy laws call “personal data”.

Information we collect

From merchants (when you install or use a Foxr app)

Shopify and the app provide:

  • Shop domain, Shopify plan context, and OAuth session (including staff user id and email required to keep you signed in)
  • Shop owner name, email, phone, and country for billing and support
  • Funnel, offer, widget, translation, and settings you configure
  • Billing and subscription status for your Foxr plan

From the merchant’s store (to run offers and analytics)

We process only what the product needs:

  • Order id, order name, checkout token, line items, tags, discount codes, payment gateway name, and shipping method
  • Minimised shipping location: country, province/state, and city — not street address or postal code
  • Customer id, and, at evaluation time, customer tags and order count (used in memory for triggers such as “first order” or “VIP tag”)
  • Anonymous session id, device class (mobile or desktop), and offer impression / accept / decline events

The shopper’s first name used in merge tags such as {first-name} is read from checkout for that request and substituted into the response. It is not stored in our offer cache.

From shoppers on this website

  • Information you choose to send (name, email, message) if you contact us
  • Standard host logs that Vercel may keep for security and uptime (IP address, user agent, requested path)

The marketing site does not require an account. It does not currently set marketing cookies.

From support chat

If you open Crisp chat inside the Foxr admin, Crisp receives your shop domain and the shop owner email so we can reply. That chat is for merchants, not storefront shoppers.

What we do not collect or store

Foxr apps do not store:

  • Shopper names, email addresses, or phone numbers
  • Street addresses or postal codes
  • Payment card numbers, CVV, or full payment credentials
  • Shopper IP address or raw user agent as personal identifiers
  • The full Shopify webhook payload — it is parsed in memory and discarded

Buyer names, emails, phones, and addresses are not written to application logs. Order ids and shop domains may appear in logs for debugging.

How we use information

We use information to:

  • Authenticate the app, keep your admin session, and honour Shopify OAuth
  • Match the right funnel (product, cart, customer, market, shipping, UTM, and similar rules you configure)
  • Render post-purchase, thank-you, and checkout offers
  • Add accepted upsell items to the order through Shopify APIs
  • Show analytics (impressions, accepts, revenue) and an order-level attribution browser
  • Bill your plan and provide merchant support
  • Detect abuse, keep the service secure, and comply with law (including Shopify’s mandatory privacy webhooks)
  • Improve the product using aggregated, non-identifying metrics

We do not use shopper data to advertise Foxr to those shoppers. We do not sell or rent merchant or shopper lists.

Where GDPR or UK GDPR applies:

  • Contract. Processing needed to provide the app you installed (offers, analytics, billing).
  • Legitimate interests. Security, fraud prevention, product reliability, and answering support — balanced against people’s rights.
  • Legal obligation. Shopify privacy webhooks, tax or accounting records, and enforceable legal process.
  • Consent. Only where we ask for it (for example if we later add optional marketing cookies on this website).

When we process shopper data as a processor, the merchant’s legal basis (typically performance of their checkout contract and legitimate interests in offering a relevant add-on) sits with the merchant.

How we share information

We disclose information only:

  • To Shopify, as required to run checkout, post-purchase, order edits, and app billing
  • To the sub-processors listed below, under contract, to host and operate the app
  • To a merchant’s connected integration (for example Judge.me) when the merchant turns that connection on
  • If required by law, subpoena, or to protect Foxr, merchants, or shoppers from fraud or harm
  • As part of a merger, acquisition, or sale of assets, with the same protections continuing or notice given

We do not disclose shopper contact details to advertisers so they can send email or SMS. Foxr does not operate a third-party offer network of that kind.

Sub-processors

These providers process data on our behalf for the Shopify apps. The marketing website is hosted separately on Vercel.

ProviderPurposeData
MongoDB AtlasPrimary databaseApp data described in this policy
Fly.ioApplication hosting for Foxr appsRequest traffic and application logs
VercelHosting for this websiteSite requests and host logs
ShopifyCommerce platform, App Bridge, billingAdmin session and store APIs
CrispMerchant support chat in adminShop domain, shop owner email
Judge.meReviews, only if the merchant connects itProduct ids; merchant token stored encrypted

Third-party tokens (such as Judge.me) are encrypted at rest with AES-256-GCM. Encryption in transit is TLS. Database encryption at rest is provided by MongoDB Atlas.

International transfers

We and our sub-processors may process information in the United States and other countries. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the provider’s standard contractual clauses or an adequacy decision, as applicable.

How long we keep information

DataRetention
Raw offer impressions400 days (automatic TTL)
Offer cacheUntil the row’s expiry (short-lived)
Order records, events, analyticsFor the life of the install; deleted on uninstall redact or a customer redact
Sessions and shop settingsUntil uninstall
GDPR fulfilment audit400 days — a minimal record that a specific erasure request was completed
Website contact emailsAs long as needed to reply and keep a support record

When you uninstall a Foxr app, Shopify sends a shop redaction request (typically 48 hours later). We then delete shop-scoped data. Customer data-access and erasure requests that Shopify sends us are honoured automatically.

Shopify GDPR and privacy compliance

Foxr follows Shopify’s privacy requirements for App Store apps. Shopify requires the same data-subject rights for all personal data, regardless of where the individual is located. We subscribe to and verify Shopify’s mandatory compliance webhooks, respond to valid deliveries with a 200-series status, and reject invalid HMAC signatures with 401 Unauthorized.

We complete each request within 30 days of receiving it, unless we are legally required to retain a specific record.

Shopify topicWhen it is sentWhat Foxr does
customers/data_requestA customer asks the store owner for their data. Shopify sends the customer id, email, phone, and related order ids to installed apps that have customer or order access.We look up what we store for that customer and those orders, and provide it to the store owner. This app does not store shopper email or phone; the merchant already has those in Shopify.
customers/redactThe store owner requests deletion on behalf of a customer. If the customer has ordered in the last six months, Shopify may delay the payload until six months have passed; otherwise it is sent after 10 days.We delete or redact customer-keyed and order-keyed rows for the listed customer id and orders_to_redact.
shop/redact48 hours after the merchant uninstalls the app, Shopify sends the shop id and shop domain.We erase all data for that shop from our database.

Learn more in Shopify’s documentation on privacy law compliance and Shopify’s privacy policy.

Security

We take technical and organisational measures including:

  • TLS for data in transit
  • Encryption at rest at the database provider
  • Additional encryption for third-party integration tokens
  • Minimising stored fields (no full shipping address, no shopper email)
  • Access limited to staff who need it to operate or support the product
  • HMAC verification of Shopify webhooks before we act on them

No method of storage or transmission is 100% secure. If we become aware of a breach that requires notice, we will notify affected merchants and regulators as the law requires.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or restrict personal information we hold; to object to certain processing; to portability; and to withdraw consent where we rely on it. You may also complain to a data protection authority.

Shoppers. Start with the store you bought from. The merchant is the controller of their checkout. You can also use Shopify’s tools. If we receive a verified request through Shopify webhooks, we fulfil it as described above.

Merchants and website visitors. Email hello@foxr.app with enough detail for us to find your shop or message. We will take reasonable steps to verify the request. We will not discriminate against you for exercising privacy rights.

We may deny or limit a request where the law allows — for example to keep a fraud or GDPR-fulfilment audit, or if we cannot verify who you are.

Additional disclosures for California residents

If you are a California resident, this section supplements the rest of this policy under the CCPA/CPRA.

Categories we may collect, depending on how you interact with Foxr:

  • Identifiers — merchant staff email, shop domain, shopper customer id (not shopper email)
  • Commercial information — orders, line items, offer accepts, plan and billing status
  • Internet activity — admin use of the app; anonymous offer impressions on the storefront
  • Approximate location — shipping country / province / city for an order

Sources: you, Shopify APIs and webhooks, and the sub-processors above. Business purposes: providing the app, security, analytics for the merchant, and legal compliance.

We do not sell personal information and we do not share it for cross-context behavioural advertising. Foxr does not run third-party ad pixels on the storefront for our own advertising. We do not knowingly sell or share the personal information of people under 16.

We do not use or disclose sensitive personal information to infer characteristics about shoppers. Merchant login credentials for Shopify are handled through Shopify OAuth.

To request access or deletion, email hello@foxr.app. You may use an authorised agent; we will still need to verify the request. We will respond within the time the law requires.

Children

Foxr apps are for merchants. They are not directed at children under 13 (or 16 where that is the relevant age). We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

Cookies and tracking

This website. We do not currently set marketing or advertising cookies. If we add analytics later, we will name the tool here and, where required, ask for consent.

Foxr apps. The admin runs inside Shopify and uses Shopify App Bridge. Storefront offer pages may set an anonymous session identifier so we can attribute an impression or accept to a funnel — not to profile shoppers for ads. We do not use session-replay tools on the admin.

Shopify and the merchant’s theme may set their own cookies. Those are governed by Shopify and the merchant, not by this policy.

What this policy does not cover

If a shopper accepts an offer, the product they buy is the merchant’s product, fulfilled on Shopify. The merchant’s privacy policy governs how that merchant uses customer information beyond Foxr. We are not responsible for other organisations we do not control.

Changes

We may update this policy when the apps or this website change. The “Last updated” date at the top will change. Material changes will be posted on this page. Continued use of the website or apps after an update means the new policy applies to that use.

Whom to contact

Privacy questions, access, and deletion requests: hello@foxr.app.

Shoppers should start with the merchant they purchased from, or use Shopify’s tools. Customer access and erasure for store data are processed through Shopify’s GDPR webhooks as described above.

Public policy URL for Shopify App Store listing and app privacy settings: https://www.foxr.app/policies/privacy-policy.