Banify ("Banify," "we," "us," or "our") provides applications and services for Shopify merchants, including loyalty, rewards, referral, customer engagement, and related ecommerce functionality.
This Privacy Policy explains how Banify collects, receives, uses, stores, discloses, protects, and deletes personal information in connection with our applications, websites, services, integrations, and related activities.
Our services may process information belonging to Shopify merchants, merchant users, store customers, referral participants, loyalty-program participants, and other individuals who interact with a merchant’s store through functionality provided by our applications.
We aim to handle personal information transparently and in accordance with applicable privacy and data protection laws.
This Privacy Policy does not replace the privacy policy of a Shopify merchant whose store uses a Banify application. When you interact with a merchant’s store, the merchant may have its own responsibilities regarding your personal information.
This Privacy Policy applies to personal information processed through:
This Policy does not govern the independent privacy practices of Shopify or a merchant using a Banify application.
For purposes of this Privacy Policy:
Personal Information
Information that identifies, relates to, describes, or can reasonably be associated with an identifiable individual, or information otherwise treated as personal data under applicable law.
Merchant
A Shopify store owner or business using a Banify application.
Customer
An individual who interacts with or purchases from a merchant’s Shopify store.
Shopify Data
Information Banify receives through Shopify APIs, webhooks, or other authorized Shopify mechanisms.
Application
A Banify application or service installed or used by a merchant.
Services
Banify’s applications, websites, integrations, support, and related services.
Depending on the application, configuration, and functionality used by a merchant, Banify may process the following categories of information.
We do not intentionally collect categories of sensitive or special-category personal information unless a merchant or individual provides such information through a service in circumstances where processing is permitted by applicable law.
Merchants are responsible for configuring their loyalty and referral programs appropriately and should not use Banify functionality to process information in ways that violate applicable law.
Banify is a Shopify application and receives information through Shopify’s APIs and other authorized mechanisms according to the permissions granted to the application and the functionality used by merchants.
These permissions may allow Banify to access or modify information necessary to provide the application’s functionality.
Depending on the feature being used, Shopify information may include customer information, order information, product information, discount information, theme/store information, and related identifiers.
We use Shopify information only for purposes connected with providing, operating, securing, supporting, and administering the application and its merchant-configured functionality, subject to applicable law and Shopify requirements.
We may process information relating to merchants and merchant users, including:
We use this information to:
Banify may process information about customers of merchants using our applications. Depending on the functionality enabled by the merchant, this may include:
The merchant generally determines how its loyalty and referral program operates, including which activities receive points, what rewards are offered, how customers qualify for tiers, and which customer-facing features are enabled.
For example, merchants may configure points for actions such as purchases, sign-up, referrals, reviews, newsletter subscriptions, or other engagement activities.
We may process personal information for the following purposes:
We do not use personal information for purposes materially incompatible with those described in this Privacy Policy without providing appropriate notice or obtaining consent where required.
The legal role of Banify may differ depending on the information and processing activity.
For customer information processed to provide a merchant’s loyalty, referral, rewards, and related services, Banify may process information on behalf of the merchant.
In such circumstances, the merchant generally determines the purposes and configuration of the customer-facing loyalty or referral program, while Banify provides the technical service used to operate that program.
Banify may also act as an independent controller for information necessary to operate and administer its own business, including information relating to merchants, support communications, security, fraud prevention, legal compliance, and administration.
The precise controller/processor relationship may depend on the applicable law, the nature of the processing, contractual arrangements, and the particular Banify service involved.
Where the GDPR or UK GDPR applies, Banify will process personal information on an appropriate lawful basis. Depending on the circumstances, potential lawful bases may include:
Contract
Where processing is necessary to provide Services requested by a merchant or user or to perform an agreement.
Legitimate Interests
Where processing is reasonably necessary for legitimate business interests, such as security, fraud prevention, service administration, support, and improvement, provided those interests are not overridden by applicable individual rights.
Legal Obligation
Where processing is necessary to comply with applicable legal obligations.
Consent
Where consent is required and obtained, including in circumstances where applicable law requires consent for a particular processing activity.
The applicable legal basis depends on the specific processing activity and circumstances. We do not rely on consent where another lawful basis is appropriate merely for convenience. Where we rely on consent, individuals may withdraw consent where applicable.
Banify does not intentionally sell customer personal information to data brokers.
Banify also does not use customer personal information for cross-context behavioral advertising based on the information currently provided to us.
Merchant-selected integrations may transmit information to the third-party service selected by the merchant. Such transmission is part of providing the requested integration and is not, by itself, a sale of personal information.
If our practices materially change, we will update this Privacy Policy and implement any legally required opt-out mechanisms.
Because Banify and/or third-party services used in connection with the Services may operate internationally, personal information may be processed in countries other than the country where the individual resides.
Where applicable law requires safeguards for international transfers, Banify will use an appropriate legally recognized transfer mechanism. Depending on the circumstances, this may include:
The precise countries and transfer mechanisms depend on the infrastructure and third-party services actually used. We will not claim that a particular transfer mechanism applies where it has not been established.
Banify currently does not publish fixed retention periods for every category of personal information.
Instead, personal information should be retained only for as long as reasonably necessary for the purpose for which it was collected or processed, including to:
When personal information is no longer reasonably required, it should be deleted, anonymized, or otherwise appropriately disposed of, subject to legal requirements and legitimate retention needs.
Banify is working toward maintaining documented retention periods for different categories of information.
Banify has implemented Shopify’s mandatory privacy compliance mechanisms:
These mechanisms support Shopify’s processes for customer-data access requests and deletion/redaction requests.
When Shopify sends a customer data request, Banify processes the request in accordance with the applicable Shopify requirements and applicable law.
When Shopify sends a customer redaction request, Banify processes the relevant customer information for deletion or redaction as required.
When Shopify sends a shop redaction request following an app uninstallation, Banify processes the shop’s information for deletion or redaction as required.
Shopify states that shop/redact is sent 48 hours after an app is uninstalled and provides the shop identifier needed to erase the store’s data.
Banify’s actual deletion procedures remain subject to applicable legal retention requirements.
Depending on where you live and the law applicable to you, you may have rights including:
These rights are subject to applicable legal exceptions.
To submit a privacy request, contact [email protected]. We may need to verify your identity before completing a request.
If the GDPR applies to your personal information, you may have the right to:
The availability of each right depends on the applicable legal basis and circumstances.
If Banify processes information on behalf of a Shopify merchant, certain requests may need to be directed to the merchant as the relevant controller.
Where the UK GDPR and applicable UK data protection legislation applies, individuals may have rights including access, correction, deletion, restriction, objection, portability, and withdrawal of consent where applicable.
Individuals may also complain to the UK’s Information Commissioner’s Office where they believe their data protection rights have been infringed.
Banify’s privacy contact is [email protected].
U.S. privacy rights vary by state and may depend on whether a particular state law applies to Banify and the individual. Where applicable, individuals may have rights such as:
California residents may have rights under the CCPA/CPRA, subject to applicable exceptions and thresholds. Banify will honor rights required by applicable U.S. privacy laws.
To submit a request, email [email protected]. We may request information reasonably necessary to verify a request.
Where the CCPA/CPRA applies, California residents may have rights including the right to know, delete, correct, opt out of certain sale or sharing activities, limit certain uses of sensitive personal information, and receive equal treatment for exercising privacy rights.
Based on Banify’s current practices as described in this Privacy Policy, Banify does not intentionally sell customer personal information to data brokers or use customer information for cross-context behavioral advertising.
If this changes, Banify will update this Policy and provide legally required opt-out mechanisms.
A number of U.S. states have comprehensive privacy laws. Applicability depends on factors such as the nature and volume of processing, revenue, thresholds, exemptions, and the individual’s location.
Banify does not claim that every U.S. state privacy law applies to it. Where a state privacy law applies, Banify will provide the rights and disclosures required by that law.
Where the Australian Privacy Act 1988 and Australian Privacy Principles apply to Banify’s activities, Banify will handle personal information in accordance with applicable requirements. These may include requirements relating to:
Where personal information is likely to be disclosed to overseas recipients, Banify will provide information required by applicable Australian privacy law.
Australian privacy requests may be submitted to [email protected].
Where Canadian privacy legislation applies to Banify’s processing, Banify will provide applicable privacy rights and protections. Depending on the applicable jurisdiction and circumstances, these may include rights relating to:
Individuals may contact [email protected].
Banify may communicate with merchants regarding:
Where Banify sends optional marketing communications, individuals may unsubscribe using the available unsubscribe mechanism or by contacting us.
A merchant’s decision to connect an email or marketing integration does not mean that Banify independently uses the merchant’s customer data for its own marketing purposes.
Banify may provide optional integrations with third-party services. Examples may include email and marketing platforms such as:
These integrations are merchant-controlled and are not automatically activated merely because they are available.
When a merchant connects an integration, information may be transferred to the selected provider as necessary to provide the requested functionality.
The merchant should review the applicable third party’s privacy policy and configure the integration in accordance with applicable law.
Banify takes reasonable measures designed to protect personal information against unauthorized access, alteration, disclosure, misuse, and loss.
Depending on the nature of the information and service, security measures may include access controls, authentication controls, application security measures, monitoring, and other technical and organizational safeguards.
However, no method of transmission or storage can be guaranteed to be completely secure. We therefore do not claim that personal information can never be accessed, disclosed, altered, or destroyed as a result of security incidents.
If Banify becomes aware of a security incident involving personal information, we will assess the incident and take reasonable steps appropriate to the circumstances.
Where applicable law requires notification to affected individuals, merchants, Shopify, regulators, or other parties, Banify will provide such notification in accordance with applicable requirements.
The Services are intended for businesses and ecommerce activities and are not designed specifically for children.
Banify does not knowingly seek to collect personal information directly from children for purposes unrelated to the services configured by a merchant.
If you believe a child has provided personal information directly to Banify in circumstances where this was not appropriate, contact [email protected].
Banify’s loyalty functionality may perform calculations based on information such as points earned or customer spending to determine a customer’s loyalty or VIP status according to rules configured by the merchant.
For example, merchants may configure VIP tiers based on all-time points earned or all-time spending. These calculations are used to operate the merchant’s loyalty program.
Banify does not currently represent that it makes decisions producing legal or similarly significant effects on individuals through automated decision-making. If this changes, Banify will update its privacy information as required by applicable law.
Merchants using Banify are responsible for:
Banify provides technical functionality but does not determine a merchant’s independent legal obligations.
If you believe Banify holds personal information about you and would like to access or correct it, contact [email protected]. Please include sufficient information for us to understand your request.
Where the information is processed on behalf of a Shopify merchant, we may direct the request to the relevant merchant or assist the merchant in responding to the request.
We may take reasonable steps to verify identity before disclosing or changing personal information.
You may request deletion of personal information where applicable law provides such a right. Requests may be submitted to [email protected].
Deletion may be subject to legal exceptions, technical limitations, legitimate retention requirements, or information that Banify is required to retain.
For Shopify customer and shop data, Banify also follows the applicable Shopify privacy and redaction mechanisms.
If you have concerns about how Banify handles your personal information, please contact [email protected].
We will review privacy complaints and take reasonable steps to address them.
Depending on your jurisdiction, you may also have the right to complain to the applicable data protection or privacy regulator.
We may update this Privacy Policy from time to time to reflect:
When we make material changes, we will update the "Last Updated" date and provide additional notice where required.
For privacy questions, requests, or concerns:
Privacy & Admin
[email protected]App Support
[email protected]Website: https://banifyapps.io/
Write to [email protected] to exercise a privacy right. We respond to requests within 30 days.