Privacy Policy

Alfreya Merchandising · Last updated 7 October 2026

Alfreya Merchandising (the “App”) is a Shopify app that ranks the products in a store’s collections by demand and, with the merchant’s approval, applies that order in Shopify. This policy explains what data the App collects when a merchant installs it, how that data is used, and the choices available to merchants and their customers.

1. Who we are

The App is provided by Alfreya (Konsiyer Teknoloji A.Ş.), a company based in Istanbul, Türkiye (“Alfreya”, “we”, “us”). For the store data the App processes on a merchant’s behalf, the merchant is the data controller and we act as a data processor. Questions about this policy can be sent to info@alfreya.com.

2. Information we collect

When a merchant installs the App, we access the following through Shopify’s APIs, limited to the permissions the merchant grants:

CategoryWhat it includes
Store informationShop domain, installation status, granted permissions, and the access token Shopify issues so the App can act for the store.
Catalogue dataProducts, variants, prices, discounts, tags, inventory levels, collections and their current sort order.
Sales dataOrder line items, quantities, dates and refunds, used only to measure how well each product sells. We do not request or store customer names, email addresses, phone numbers, postal addresses or payment details.
Storefront activityIf enabled, the App’s Shopify web pixel counts product views, add-to-carts and purchases. Each event carries only a product ID, a quantity and a timestamp, and is stored as a daily count per product. It sets no cookies and carries no customer ID or device identifier. We do not store IP addresses with these counts, though our hosting provider’s standard request logs may record them for a short time for security. The pixel runs in Shopify’s strict sandbox, so it follows each shopper’s consent choices.
App settings and activitySorting rules, pinned products, proposed and applied orders, and an audit log of approvals. The log records who approved a change, using the staff member’s email address where Shopify provides it and otherwise the shop domain.
BillingThe plan the store is on. Charges are handled entirely by Shopify; we never see card or bank details.

3. How we use it

We do not sell data, use it for advertising, build profiles of shoppers, or combine one store’s data with another’s. Store data is not used to train machine-learning models.

4. Legal basis

Where the EU/UK GDPR or Türkiye’s Personal Data Protection Law (KVKK, No. 6698) applies, we process data to perform our contract with the merchant and, for security and service improvement, on the basis of our legitimate interests. For shopper data, the merchant decides the legal basis and is responsible for their own storefront privacy notice and consent settings.

5. Sharing and sub-processors

We share data only with the service providers that run the App, under contracts that require them to protect it:

We may also disclose data if the law requires it, or to a successor if Alfreya is involved in a merger or acquisition. That successor would remain bound by this policy.

6. Where data is stored

App data is stored and processed in the European Union. Some of our providers may access it from other countries for support or operations. Where that happens, the transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. How long we keep it

8. Shopper privacy requests

We support Shopify’s mandatory privacy webhooks. Because the App holds no data that identifies an individual shopper, a customer data request or redaction request finds no records to return or erase. Shoppers should send privacy requests to the store they bought from. The merchant can contact us if they need help responding.

9. Security

Data is encrypted in transit (HTTPS) and at rest. Access is limited to the systems and personnel that need it. Storefront events must carry a per-store token, and every Shopify webhook is verified before it is processed. No system is perfectly secure, but we will notify affected merchants without undue delay if a breach affects their data.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to lodge a complaint with your data protection authority. In Türkiye that authority is the KVKK Board. To exercise any of these rights, email info@alfreya.com. We will reply within 30 days.

11. Children

The App is a business tool for merchants and is not directed at children. We do not knowingly collect data from them.

12. Changes to this policy

We may update this policy as the App changes. The “Last updated” date above will show the latest revision. We will notify installed merchants of material changes in the App or by email.

13. Contact

Alfreya (Konsiyer Teknoloji A.Ş.)
Istanbul, Türkiye
info@alfreya.com