Dualflow

Privacy Policy

Last updated: 2026-06-02

This Privacy Policy describes how the Dualflow Shopify application (“Dualflow”, “the app”, “we”, “us”) collects, uses, and discloses information when you install and use it on your Shopify store. It applies both to merchants who install the app and to the buyers who interact with the pre-order checkout flows the app powers.

If you have questions about this policy, contact us at the support address in the App Store listing.

1. Information we collect

1.1 From the merchant

When a merchant installs Dualflow we receive, from Shopify, the information required to operate the app:

1.2 From the merchant’s buyers

When a buyer places a pre-order on the merchant’s storefront we store the minimum information required to track and release the fulfillment hold:

We do not persistently store buyer names, email addresses, billing addresses, shipping addresses, or payment information in our database. Buyer-identifying fields are forwarded to Klaviyo when (and only when) the merchant has connected their Klaviyo account — see Section 3.

1.3 From Klaviyo (if connected)

If the merchant connects Klaviyo via OAuth from the app’s Settings screen, we store the access token, refresh token, and granted scopes for that connection. We use these credentials only to dispatch the Deferred Order Placed metric event for orders the merchant’s customers place through the app.

1.4 Technical telemetry

We collect standard server-side request logs (timestamp, request path, HTTP status, response duration) for operational debugging. These logs do not include the bodies of merchant or buyer requests.

2. How we use information

We use the information collected above to:

We do not sell or rent any data we collect. We do not use buyer data for advertising or for any purpose unrelated to operating the pre-order workflow.

3. Third-party processors

The app relies on the following sub-processors. Their handling of data is governed by their own privacy policies.

Processor Purpose Data shared
Shopify Hosts the merchant’s store, issues OAuth tokens, sends order webhooks. All app/merchant data flows via Shopify by design.
Fly.io (US East — iad) Hosts the Dualflow application server and managed Postgres database. All persistent data referenced in Section 1 is stored here at rest.
Klaviyo Receives the Deferred Order Placed event when the merchant connects their account. Buyer email, ship date, order name, item prices, and item titles, dispatched in real time per pre-order.

4. Data retention

5. GDPR and CCPA compliance

The app implements Shopify’s mandatory privacy webhooks:

Buyers who wish to exercise GDPR or CCPA rights should contact the merchant they purchased from. The merchant initiates the request through Shopify, and Shopify forwards the request to us via the webhooks above.

6. Security

7. Changes to this policy

We may update this policy from time to time. Material changes will be announced in the app’s Settings page banner before they take effect. The “Last updated” date at the top reflects the most recent revision.

8. Contact

For privacy questions, data subject requests, or any other inquiries about this policy, contact us at the support email address listed on the app’s Shopify App Store page.