Built for Shopify merchants Shopify App Store Contact us
Banify

Legal · App policy

Privacy Policy

BA Referral Program & Loyalty Rewards

App coming soon · October 19, 2026

How Banify collects, receives, uses, stores, discloses, protects, and deletes personal information in connection with our applications, websites, services and integrations.

Last updated: September 20, 2026

Translations of this page are provided for convenience. If a translation differs from the English version, the English version applies.

Overview

Banify ("Banify," "we," "us," or "our") provides applications and services for Shopify merchants, including loyalty, rewards, referral, customer engagement, and related ecommerce functionality.

This Privacy Policy explains how Banify collects, receives, uses, stores, discloses, protects, and deletes personal information in connection with our applications, websites, services, integrations, and related activities.

1. Introduction

Our services may process information belonging to Shopify merchants, merchant users, store customers, referral participants, loyalty-program participants, and other individuals who interact with a merchant’s store through functionality provided by our applications.

We aim to handle personal information transparently and in accordance with applicable privacy and data protection laws.

This Privacy Policy does not replace the privacy policy of a Shopify merchant whose store uses a Banify application. When you interact with a merchant’s store, the merchant may have its own responsibilities regarding your personal information.

2. Who We Are

Detail
Value
Company
Banify
Website
https://banifyapps.io/
Privacy inquiries

3. Scope of This Privacy Policy

This Privacy Policy applies to personal information processed through:

  • Banify applications;
  • Banify websites;
  • Shopify APIs and related Shopify services;
  • customer-facing loyalty and referral functionality;
  • merchant-facing application functionality;
  • customer loyalty and rewards functionality;
  • referral programs;
  • integrations that a merchant chooses to connect;
  • support and administrative communications relating to our services.

This Policy does not govern the independent privacy practices of Shopify or a merchant using a Banify application.

4. Definitions

For purposes of this Privacy Policy:

Personal Information

Information that identifies, relates to, describes, or can reasonably be associated with an identifiable individual, or information otherwise treated as personal data under applicable law.

Merchant

A Shopify store owner or business using a Banify application.

Customer

An individual who interacts with or purchases from a merchant’s Shopify store.

Shopify Data

Information Banify receives through Shopify APIs, webhooks, or other authorized Shopify mechanisms.

Application

A Banify application or service installed or used by a merchant.

Services

Banify’s applications, websites, integrations, support, and related services.

5. Personal Information We Process

Depending on the application, configuration, and functionality used by a merchant, Banify may process the following categories of information.

Category
Examples
Source
Purpose
Merchant information
Store name, store identifier, store URL, configuration information
Shopify / Merchant
Providing and administering the application
Customer identification
Name, Shopify customer ID
Shopify
Loyalty, referral, rewards and customer management
Contact information
Email address, phone number
Shopify / Merchant
Customer identification, rewards and referral functionality
Order information
Orders and information associated with purchases
Shopify
Points, rewards, referrals and loyalty calculations
Product information
Product identifiers and product information
Shopify
Rewards, products, loyalty and store functionality
Discount information
Discounts, discount rules and codes
Shopify / Merchant
Referral and rewards functionality
Loyalty information
Points, balances, rewards and redemption history
Banify / Shopify
Operating the loyalty program
Referral information
Referral codes, referral relationships, referral activity
Banify / Store interactions
Operating referral programs
VIP information
Tier, qualification status and related benefits
Banify / Shopify
Operating VIP programs
Spending information
Purchase-related totals used for qualification
Shopify
VIP and loyalty qualification
Program configuration
Reward values, point values, program settings
Merchant
Providing merchant-configured functionality
Integration information
Information required to connect a merchant-selected service
Merchant / integration provider
Providing requested integrations
Technical information
Technical information necessary to operate and secure the service
Service interactions
Security, troubleshooting and operation

We do not intentionally collect categories of sensitive or special-category personal information unless a merchant or individual provides such information through a service in circumstances where processing is permitted by applicable law.

Merchants are responsible for configuring their loyalty and referral programs appropriately and should not use Banify functionality to process information in ways that violate applicable law.

6. Information We Receive Through Shopify

Banify is a Shopify application and receives information through Shopify’s APIs and other authorized mechanisms according to the permissions granted to the application and the functionality used by merchants.

Our current Shopify API permissions

  • read_customers
  • read_discounts
  • read_orders
  • read_products
  • read_themes
  • write_discounts
  • write_price_rules

These permissions may allow Banify to access or modify information necessary to provide the application’s functionality.

Depending on the feature being used, Shopify information may include customer information, order information, product information, discount information, theme/store information, and related identifiers.

We use Shopify information only for purposes connected with providing, operating, securing, supporting, and administering the application and its merchant-configured functionality, subject to applicable law and Shopify requirements.

7. Merchant Information

We may process information relating to merchants and merchant users, including:

  • Shopify store information;
  • store identifiers;
  • store configuration;
  • application settings;
  • loyalty and referral program settings;
  • reward configurations;
  • discount configurations;
  • VIP-tier configurations;
  • integration settings;
  • information submitted when contacting support;
  • information necessary to administer the merchant’s use of the application.

We use this information to:

  • provide the application;
  • configure merchant programs;
  • maintain the merchant’s account and settings;
  • provide support;
  • communicate about the service;
  • maintain security;
  • troubleshoot problems;
  • comply with legal obligations;
  • enforce our agreements.

8. Customer and End-User Information

Banify may process information about customers of merchants using our applications. Depending on the functionality enabled by the merchant, this may include:

  • name;
  • email address;
  • phone number;
  • Shopify customer identifier;
  • order information;
  • purchase-related information;
  • points earned;
  • points redeemed;
  • available points;
  • rewards;
  • referral information;
  • referral codes;
  • VIP tier;
  • loyalty status;
  • reward redemption information;
  • spending information used to calculate loyalty or VIP status;
  • other information necessary to provide the merchant’s configured loyalty and referral program.

The merchant generally determines how its loyalty and referral program operates, including which activities receive points, what rewards are offered, how customers qualify for tiers, and which customer-facing features are enabled.

For example, merchants may configure points for actions such as purchases, sign-up, referrals, reviews, newsletter subscriptions, or other engagement activities.

9. How We Use Personal Information

We may process personal information for the following purposes:

Purpose
Information used
Provide the application
Merchant, store, customer, order, product and configuration information
Operate loyalty programs
Customer, order, points, reward and program information
Operate referral programs
Customer, referral and order information
Calculate rewards
Customer, purchase, points and reward information
Calculate VIP status
Points and spending information
Create and manage discounts
Discount, order and program information
Display customer loyalty information
Customer, points, rewards and tier information
Provide customer-facing functionality
Relevant customer and loyalty information
Provide merchant support
Merchant and support information
Maintain application security
Relevant account, technical and service information
Prevent misuse and fraud
Relevant technical and transactional information
Maintain and improve the Services
Service and technical information
Communicate with merchants
Merchant contact and account information
Process privacy requests
Information necessary to identify and fulfill the request
Comply with legal requirements
Information required by applicable law
Manage connected integrations
Information necessary to provide an integration requested by the merchant

We do not use personal information for purposes materially incompatible with those described in this Privacy Policy without providing appropriate notice or obtaining consent where required.

10. Controller and Processor Relationships

The legal role of Banify may differ depending on the information and processing activity.

For customer information processed to provide a merchant’s loyalty, referral, rewards, and related services, Banify may process information on behalf of the merchant.

In such circumstances, the merchant generally determines the purposes and configuration of the customer-facing loyalty or referral program, while Banify provides the technical service used to operate that program.

Banify may also act as an independent controller for information necessary to operate and administer its own business, including information relating to merchants, support communications, security, fraud prevention, legal compliance, and administration.

The precise controller/processor relationship may depend on the applicable law, the nature of the processing, contractual arrangements, and the particular Banify service involved.

12. How We Share Personal Information

We may disclose personal information in the following circumstances:

Shopify

We exchange information with Shopify as necessary to operate the application and comply with Shopify’s platform requirements.

Merchant-Selected Integrations

Banify may integrate with third-party services that a merchant explicitly chooses to connect. Examples may include email and marketing platforms such as Klaviyo and SendGrid.

These integrations are not enabled by default merely because they exist as available integrations. They are used when the merchant chooses to connect and use the applicable integration.

Information transmitted through an integration depends on the integration and the merchant’s configuration. Merchants are responsible for reviewing the privacy practices of third-party services they choose to connect.

Service Providers

Where applicable, we may use service providers that assist us with operating the Services, security, support, infrastructure, communications, or other business functions.

We do not list a service provider as a Banify processor merely because the service exists; disclosures should reflect services actually used by Banify.

Legal Requirements

We may disclose information where reasonably necessary to:

  • comply with applicable law;
  • respond to lawful requests;
  • comply with legal process;
  • protect rights, safety, or property;
  • investigate fraud or security incidents;
  • enforce agreements.

Business Transfers

If Banify is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar transaction, personal information may be transferred as part of that transaction, subject to applicable law.

13. Sale and Sharing of Personal Information

Banify does not intentionally sell customer personal information to data brokers.

Banify also does not use customer personal information for cross-context behavioral advertising based on the information currently provided to us.

Merchant-selected integrations may transmit information to the third-party service selected by the merchant. Such transmission is part of providing the requested integration and is not, by itself, a sale of personal information.

If our practices materially change, we will update this Privacy Policy and implement any legally required opt-out mechanisms.

14. International Data Transfers

Because Banify and/or third-party services used in connection with the Services may operate internationally, personal information may be processed in countries other than the country where the individual resides.

Where applicable law requires safeguards for international transfers, Banify will use an appropriate legally recognized transfer mechanism. Depending on the circumstances, this may include:

  • an applicable adequacy decision;
  • Standard Contractual Clauses;
  • the UK International Data Transfer Agreement or Addendum;
  • another legally recognized transfer mechanism.

The precise countries and transfer mechanisms depend on the infrastructure and third-party services actually used. We will not claim that a particular transfer mechanism applies where it has not been established.

15. Data Retention

Banify currently does not publish fixed retention periods for every category of personal information.

Instead, personal information should be retained only for as long as reasonably necessary for the purpose for which it was collected or processed, including to:

  • provide the Services;
  • maintain merchant configuration;
  • provide loyalty and referral functionality;
  • comply with legal obligations;
  • resolve disputes;
  • enforce agreements;
  • maintain security;
  • investigate misuse or fraud;
  • complete privacy requests;
  • satisfy applicable Shopify requirements.

When personal information is no longer reasonably required, it should be deleted, anonymized, or otherwise appropriately disposed of, subject to legal requirements and legitimate retention needs.

Banify is working toward maintaining documented retention periods for different categories of information.

16. Data Deletion and Shopify Compliance

Banify has implemented Shopify’s mandatory privacy compliance mechanisms:

  • customers/data_request
  • customers/redact
  • shop/redact

These mechanisms support Shopify’s processes for customer-data access requests and deletion/redaction requests.

When Shopify sends a customer data request, Banify processes the request in accordance with the applicable Shopify requirements and applicable law.

When Shopify sends a customer redaction request, Banify processes the relevant customer information for deletion or redaction as required.

When Shopify sends a shop redaction request following an app uninstallation, Banify processes the shop’s information for deletion or redaction as required.

Shopify states that shop/redact is sent 48 hours after an app is uninstalled and provides the shop identifier needed to erase the store’s data.

Banify’s actual deletion procedures remain subject to applicable legal retention requirements.

17. Your Privacy Rights

Depending on where you live and the law applicable to you, you may have rights including:

  • access to personal information;
  • correction of inaccurate personal information;
  • deletion of personal information;
  • restriction of processing;
  • objection to processing;
  • data portability;
  • withdrawal of consent;
  • information about processing;
  • rights concerning certain automated decision-making or profiling;
  • rights concerning marketing communications;
  • rights to opt out of certain processing activities;
  • rights available under applicable U.S. state privacy laws.

These rights are subject to applicable legal exceptions.

To submit a privacy request, contact [email protected]. We may need to verify your identity before completing a request.

18. European Economic Area Privacy Rights

If the GDPR applies to your personal information, you may have the right to:

  • obtain confirmation of whether we process your personal information;
  • access your personal information;
  • correct inaccurate or incomplete information;
  • request deletion;
  • request restriction of processing;
  • object to processing;
  • receive certain information in a portable format;
  • withdraw consent where processing is based on consent;
  • object to certain direct marketing;
  • lodge a complaint with a competent data protection supervisory authority.

The availability of each right depends on the applicable legal basis and circumstances.

If Banify processes information on behalf of a Shopify merchant, certain requests may need to be directed to the merchant as the relevant controller.

19. United Kingdom Privacy Rights

Where the UK GDPR and applicable UK data protection legislation applies, individuals may have rights including access, correction, deletion, restriction, objection, portability, and withdrawal of consent where applicable.

Individuals may also complain to the UK’s Information Commissioner’s Office where they believe their data protection rights have been infringed.

Banify’s privacy contact is [email protected].

20. United States Privacy Rights

U.S. privacy rights vary by state and may depend on whether a particular state law applies to Banify and the individual. Where applicable, individuals may have rights such as:

  • right to know/access;
  • right to delete;
  • right to correct;
  • right to opt out of sale;
  • right to opt out of targeted or cross-context behavioral advertising;
  • right to limit certain uses of sensitive personal information;
  • right to data portability;
  • right against unlawful discrimination for exercising privacy rights.

California residents may have rights under the CCPA/CPRA, subject to applicable exceptions and thresholds. Banify will honor rights required by applicable U.S. privacy laws.

To submit a request, email [email protected]. We may request information reasonably necessary to verify a request.

21. California Privacy Rights

Where the CCPA/CPRA applies, California residents may have rights including the right to know, delete, correct, opt out of certain sale or sharing activities, limit certain uses of sensitive personal information, and receive equal treatment for exercising privacy rights.

Based on Banify’s current practices as described in this Privacy Policy, Banify does not intentionally sell customer personal information to data brokers or use customer information for cross-context behavioral advertising.

If this changes, Banify will update this Policy and provide legally required opt-out mechanisms.

22. Other U.S. State Privacy Laws

A number of U.S. states have comprehensive privacy laws. Applicability depends on factors such as the nature and volume of processing, revenue, thresholds, exemptions, and the individual’s location.

Banify does not claim that every U.S. state privacy law applies to it. Where a state privacy law applies, Banify will provide the rights and disclosures required by that law.

23. Australia

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply to Banify’s activities, Banify will handle personal information in accordance with applicable requirements. These may include requirements relating to:

  • transparent privacy practices;
  • collection and use;
  • disclosure;
  • access;
  • correction;
  • direct marketing;
  • overseas disclosures;
  • security;
  • destruction or de-identification when information is no longer required;
  • complaints.

Where personal information is likely to be disclosed to overseas recipients, Banify will provide information required by applicable Australian privacy law.

Australian privacy requests may be submitted to [email protected].

24. Canada

Where Canadian privacy legislation applies to Banify’s processing, Banify will provide applicable privacy rights and protections. Depending on the applicable jurisdiction and circumstances, these may include rights relating to:

  • access;
  • correction;
  • consent;
  • withdrawal of consent;
  • safeguards;
  • retention;
  • accountability;
  • complaints.

Individuals may contact [email protected].

25. Cookies and Similar Technologies

Banify may use cookies or similar technologies where necessary to provide specific application functionality.

For example, referral functionality may require information that allows a referral relationship or attribution event to be maintained. The precise cookies and technologies used depend on the application and configuration.

Banify does not currently report using analytics or advertising tracking technologies as part of its default application configuration.

Where a merchant connects a third-party marketing or analytics integration, the applicable third-party service may use its own technologies subject to its own privacy practices.

26. Marketing Communications

Banify may communicate with merchants regarding:

  • application operation;
  • support;
  • account or service matters;
  • important service notices;
  • security;
  • changes to the Services;
  • privacy or legal matters.

Where Banify sends optional marketing communications, individuals may unsubscribe using the available unsubscribe mechanism or by contacting us.

A merchant’s decision to connect an email or marketing integration does not mean that Banify independently uses the merchant’s customer data for its own marketing purposes.

27. Third-Party Integrations

Banify may provide optional integrations with third-party services. Examples may include email and marketing platforms such as:

  • Klaviyo;
  • SendGrid;
  • other integrations made available through the application.

These integrations are merchant-controlled and are not automatically activated merely because they are available.

When a merchant connects an integration, information may be transferred to the selected provider as necessary to provide the requested functionality.

The merchant should review the applicable third party’s privacy policy and configure the integration in accordance with applicable law.

28. Security

Banify takes reasonable measures designed to protect personal information against unauthorized access, alteration, disclosure, misuse, and loss.

Depending on the nature of the information and service, security measures may include access controls, authentication controls, application security measures, monitoring, and other technical and organizational safeguards.

However, no method of transmission or storage can be guaranteed to be completely secure. We therefore do not claim that personal information can never be accessed, disclosed, altered, or destroyed as a result of security incidents.

29. Data Breach and Security Incidents

If Banify becomes aware of a security incident involving personal information, we will assess the incident and take reasonable steps appropriate to the circumstances.

Where applicable law requires notification to affected individuals, merchants, Shopify, regulators, or other parties, Banify will provide such notification in accordance with applicable requirements.

30. Children’s Privacy

The Services are intended for businesses and ecommerce activities and are not designed specifically for children.

Banify does not knowingly seek to collect personal information directly from children for purposes unrelated to the services configured by a merchant.

If you believe a child has provided personal information directly to Banify in circumstances where this was not appropriate, contact [email protected].

31. Automated Decision-Making and Profiling

Banify’s loyalty functionality may perform calculations based on information such as points earned or customer spending to determine a customer’s loyalty or VIP status according to rules configured by the merchant.

For example, merchants may configure VIP tiers based on all-time points earned or all-time spending. These calculations are used to operate the merchant’s loyalty program.

Banify does not currently represent that it makes decisions producing legal or similarly significant effects on individuals through automated decision-making. If this changes, Banify will update its privacy information as required by applicable law.

32. Merchant Responsibilities

Merchants using Banify are responsible for:

  • determining appropriate purposes for their loyalty and referral programs;
  • configuring rewards and customer-facing functionality lawfully;
  • providing appropriate privacy notices to their customers;
  • obtaining consent where required;
  • ensuring marketing activities comply with applicable laws;
  • ensuring connected integrations are used lawfully;
  • responding appropriately to customer privacy requests;
  • avoiding collection of unnecessary personal information;
  • ensuring that rewards, promotions, referrals, and loyalty programs comply with applicable laws.

Banify provides technical functionality but does not determine a merchant’s independent legal obligations.

33. Data Access and Correction Requests

If you believe Banify holds personal information about you and would like to access or correct it, contact [email protected]. Please include sufficient information for us to understand your request.

Where the information is processed on behalf of a Shopify merchant, we may direct the request to the relevant merchant or assist the merchant in responding to the request.

We may take reasonable steps to verify identity before disclosing or changing personal information.

34. Data Deletion Requests

You may request deletion of personal information where applicable law provides such a right. Requests may be submitted to [email protected].

Deletion may be subject to legal exceptions, technical limitations, legitimate retention requirements, or information that Banify is required to retain.

For Shopify customer and shop data, Banify also follows the applicable Shopify privacy and redaction mechanisms.

35. Complaints

If you have concerns about how Banify handles your personal information, please contact [email protected].

We will review privacy complaints and take reasonable steps to address them.

Depending on your jurisdiction, you may also have the right to complain to the applicable data protection or privacy regulator.

36. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to our Services;
  • changes to our data practices;
  • changes to integrations;
  • changes in applicable law;
  • changes to Shopify requirements;
  • security or operational changes.

When we make material changes, we will update the "Last Updated" date and provide additional notice where required.

37. Contact Us

For privacy questions, requests, or concerns:

Privacy & Admin

[email protected]

Website: https://banifyapps.io/

Questions about your data?

Write to [email protected] to exercise a privacy right. We respond to requests within 30 days.

Contact us