Privacy Policy
Last updated: 2026-06-02
This Privacy Policy describes how the Dualflow Shopify application (“Dualflow”, “the app”, “we”, “us”) collects, uses, and discloses information when you install and use it on your Shopify store. It applies both to merchants who install the app and to the buyers who interact with the pre-order checkout flows the app powers.
If you have questions about this policy, contact us at the support address in the App Store listing.
1. Information we collect
1.1 From the merchant
When a merchant installs Dualflow we receive, from Shopify, the information required to operate the app:
- The shop’s myshopify domain (e.g.
your-store.myshopify.com). - The OAuth access token Shopify issues for the granted API scopes.
- The Shopify-assigned shop ID and the merchant’s plan status (used to scope billing).
- Configuration the merchant enters in the app: pre-order listings, ship dates, discount amounts, SKU/barcode format defaults, button label and subtext copy, and Klaviyo connection state.
- Billing state Shopify returns for the active app subscription (plan name, trial end date, usage charges).
1.2 From the merchant’s buyers
When a buyer places a pre-order on the merchant’s storefront we store the minimum information required to track and release the fulfillment hold:
- The Shopify order ID and order name (e.g.
#1042). - The line items in that order that contain pre-order variants, including the variant ID, quantity, price, and the ship-date line item property.
- The fulfillment order IDs created for the pre-order line items and the status of any holds placed against them.
We do not persistently store buyer names, email addresses, billing addresses, shipping addresses, or payment information in our database. Buyer-identifying fields are forwarded to Klaviyo when (and only when) the merchant has connected their Klaviyo account — see Section 3.
1.3 From Klaviyo (if connected)
If the merchant connects Klaviyo via OAuth from the app’s
Settings screen, we store the access token, refresh token, and
granted scopes for that connection. We use these credentials only to
dispatch the Deferred Order Placed metric event for
orders the merchant’s customers place through the app.
1.4 Technical telemetry
We collect standard server-side request logs (timestamp, request path, HTTP status, response duration) for operational debugging. These logs do not include the bodies of merchant or buyer requests.
2. How we use information
We use the information collected above to:
- Create and update Shopify resources (pre-order variants, product metafields, order tags) on the merchant’s behalf.
- Place and release fulfillment holds for pre-order orders.
- Calculate plan usage and report it to Shopify’s billing API.
- Render the pre-order button on the merchant’s storefront via the Shopify theme app extension.
-
Send the
Deferred Order Placedevent into the merchant’s connected Klaviyo account, including the buyer’s email and ship date, so the merchant can build pre-order email flows.
We do not sell or rent any data we collect. We do not use buyer data for advertising or for any purpose unrelated to operating the pre-order workflow.
3. Third-party processors
The app relies on the following sub-processors. Their handling of data is governed by their own privacy policies.
| Processor | Purpose | Data shared |
|---|---|---|
| Shopify | Hosts the merchant’s store, issues OAuth tokens, sends order webhooks. | All app/merchant data flows via Shopify by design. |
Fly.io (US East — iad) |
Hosts the Dualflow application server and managed Postgres database. | All persistent data referenced in Section 1 is stored here at rest. |
| Klaviyo |
Receives the Deferred Order Placed event when the
merchant connects their account.
|
Buyer email, ship date, order name, item prices, and item titles, dispatched in real time per pre-order. |
4. Data retention
-
Merchant configuration: retained while the app is
installed. Deleted within 48 hours of uninstall via the
app/uninstalledwebhook, or immediately on a verifiedshop/redactGDPR request. - Pre-order order rows: retained for the lifetime of the fulfillment hold plus 30 days for post-release reconciliation, then automatically deleted on the next scheduled job run.
- Klaviyo OAuth tokens: retained until the merchant disconnects Klaviyo from the app Settings screen, or until the app is uninstalled.
- Server-side request logs: retained for 7 days at Fly.io, then rotated.
5. GDPR and CCPA compliance
The app implements Shopify’s mandatory privacy webhooks:
-
customers/data_request— returns the pre-order order records we hold for the requested customer’s order IDs. -
customers/redact— deletes the pre-order order records associated with the requested customer’s order IDs. -
shop/redact— deletes all stored shop sessions, settings, listings, generated variant rows, order rows, scheduled job state, hold-failure records, and webhook idempotency entries for the shop.
Buyers who wish to exercise GDPR or CCPA rights should contact the merchant they purchased from. The merchant initiates the request through Shopify, and Shopify forwards the request to us via the webhooks above.
6. Security
- All data is transmitted over TLS.
- The application server is single-tenant per shop and tokens are scoped per shop. There is no cross-shop data access path.
- Access to the production database is restricted to the Wait & Save operators. We do not export merchant or buyer data to third-party analytics platforms.
7. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app’s Settings page banner before they take effect. The “Last updated” date at the top reflects the most recent revision.
8. Contact
For privacy questions, data subject requests, or any other inquiries about this policy, contact us at the support email address listed on the app’s Shopify App Store page.