Privacy Policy
Alfreya Merchandising · Last updated 7 October 2026
Alfreya Merchandising (the “App”) is a Shopify app that ranks the products in a store’s collections by demand and, with the merchant’s approval, applies that order in Shopify. This policy explains what data the App collects when a merchant installs it, how that data is used, and the choices available to merchants and their customers.
1. Who we are
The App is provided by Alfreya (Konsiyer Teknoloji A.Ş.), a company based in Istanbul, Türkiye (“Alfreya”, “we”, “us”). For the store data the App processes on a merchant’s behalf, the merchant is the data controller and we act as a data processor. Questions about this policy can be sent to info@alfreya.com.
2. Information we collect
When a merchant installs the App, we access the following through Shopify’s APIs, limited to the permissions the merchant grants:
| Category | What it includes |
|---|---|
| Store information | Shop domain, installation status, granted permissions, and the access token Shopify issues so the App can act for the store. |
| Catalogue data | Products, variants, prices, discounts, tags, inventory levels, collections and their current sort order. |
| Sales data | Order line items, quantities, dates and refunds, used only to measure how well each product sells. We do not request or store customer names, email addresses, phone numbers, postal addresses or payment details. |
| Storefront activity | If enabled, the App’s Shopify web pixel counts product views, add-to-carts and purchases. Each event carries only a product ID, a quantity and a timestamp, and is stored as a daily count per product. It sets no cookies and carries no customer ID or device identifier. We do not store IP addresses with these counts, though our hosting provider’s standard request logs may record them for a short time for security. The pixel runs in Shopify’s strict sandbox, so it follows each shopper’s consent choices. |
| App settings and activity | Sorting rules, pinned products, proposed and applied orders, and an audit log of approvals. The log records who approved a change, using the staff member’s email address where Shopify provides it and otherwise the shop domain. |
| Billing | The plan the store is on. Charges are handled entirely by Shopify; we never see card or bank details. |
3. How we use it
- To score products and propose collection orders.
- To apply an order to Shopify, but only when the merchant approves it or has turned on automatic sorting for that collection.
- To show the merchant their sorting history and the reasons behind each ranking.
- To provide support, keep the App secure, and fix problems.
- To manage the merchant’s subscription through Shopify Billing.
We do not sell data, use it for advertising, build profiles of shoppers, or combine one store’s data with another’s. Store data is not used to train machine-learning models.
4. Legal basis
Where the EU/UK GDPR or Türkiye’s Personal Data Protection Law (KVKK, No. 6698) applies, we process data to perform our contract with the merchant and, for security and service improvement, on the basis of our legitimate interests. For shopper data, the merchant decides the legal basis and is responsible for their own storefront privacy notice and consent settings.
5. Sharing and sub-processors
We share data only with the service providers that run the App, under contracts that require them to protect it:
- Shopify, which provides the platform, the APIs and billing.
- Google Cloud (Firestore, Cloud Run, Cloud Tasks) in Frankfurt, Germany (europe-west3), for storage and background jobs.
- Vercel, which hosts the App in its Frankfurt, Germany (fra1) region.
We may also disclose data if the law requires it, or to a successor if Alfreya is involved in a merger or acquisition. That successor would remain bound by this policy.
6. Where data is stored
App data is stored and processed in the European Union. Some of our providers may access it from other countries for support or operations. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Daily storefront counts are deleted automatically after about 100 days.
- Unapplied sort proposals are deleted after 90 days, and working snapshots after about a week.
- Settings, sorting history and the approval log are kept while the App is installed.
- When a merchant uninstalls the App, Shopify sends a deletion request 48 hours later, and we then delete all data held for that store. Merchants can also ask us to delete it sooner.
8. Shopper privacy requests
We support Shopify’s mandatory privacy webhooks. Because the App holds no data that identifies an individual shopper, a customer data request or redaction request finds no records to return or erase. Shoppers should send privacy requests to the store they bought from. The merchant can contact us if they need help responding.
9. Security
Data is encrypted in transit (HTTPS) and at rest. Access is limited to the systems and personnel that need it. Storefront events must carry a per-store token, and every Shopify webhook is verified before it is processed. No system is perfectly secure, but we will notify affected merchants without undue delay if a breach affects their data.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to lodge a complaint with your data protection authority. In Türkiye that authority is the KVKK Board. To exercise any of these rights, email info@alfreya.com. We will reply within 30 days.
11. Children
The App is a business tool for merchants and is not directed at children. We do not knowingly collect data from them.
12. Changes to this policy
We may update this policy as the App changes. The “Last updated” date above will show the latest revision. We will notify installed merchants of material changes in the App or by email.
13. Contact
Alfreya (Konsiyer Teknoloji A.Ş.)
Istanbul, Türkiye
info@alfreya.com