Legal
Privacy Policy
Effective date: August 12, 2026
Mayra ("Mayra", "we", "us") provides the Mayra - Order Edit & Upsell application ("App") for Shopify merchants. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
This policy covers two audiences: merchants who install the App, and their customers, whose order information the App processes on the merchant's behalf.
Our role. For a merchant's customer personal data, the merchant is the data controller and Mayra acts as a data processor that processes that data only to provide the App's functionality. For a merchant's own account information, Mayra is the controller.
1. Information we collect
From merchants (when you install and use the App):
- Your store's myshopify.com domain and store details available through Shopify.
- A Shopify access token that authorizes the App to call Shopify APIs on your behalf (stored encrypted - see Security).
- App configuration and settings you choose (edit window, allowed actions, refund handling, upsell and cancellation-deflection settings, etc.).
- Basic usage and diagnostic logs.
Customer personal data (processed on the merchant's behalf to provide the service):
- Order information (line items, quantities, variants, totals, fulfillment and payment status).
- Customer name, email address, and shipping address - used to verify that a customer owns the order they are editing and to apply changes such as address updates.
- Records of edits, cancellations, cancellation reasons, upsell offers, and related activity, linked to the relevant order.
We do not collect customer phone numbers, and we do not process or store payment card details - payments are handled entirely by Shopify Checkout.
2. How we use information
- To provide the App's core functionality: letting customers edit, cancel, or add to their orders; processing balances and refunds through Shopify; presenting post-purchase upsells; and offering store credit to reduce cancellations.
- To show merchants analytics about how the App is used (e.g., orders edited, revenue recovered, estimated support tickets avoided).
- To operate, secure, maintain, and improve the App.
- To comply with legal obligations and Shopify's requirements.
We do not sell personal data, and we do not use it for advertising or unrelated marketing.
3. Legal bases (EEA/UK)
Where GDPR applies, we process merchant account data to perform our contract with you and for our legitimate interests in operating and securing the App. Customer personal data is processed on the documented instructions of the merchant (the controller), under the merchant's legal bases.
4. Sharing and sub-processors
We share data only with service providers that help us run the App:
- Shopify Inc. - the platform the App runs on, and the source and destination of order data.
- Railway - application hosting and our PostgreSQL database.
We may disclose information if required by law or to protect rights, safety, and security. We do not sell or rent personal data to third parties.
5. Data retention
We retain merchant configuration and order-linked records for as long as the App is installed and as needed to provide the service. When a merchant uninstalls the App, or upon a valid deletion request or a Shopify "shop redact" / "customer redact" request, we delete the associated data in line with Shopify's mandatory data-protection webhooks (customers/data_request, customers/redact, shop/redact).
6. Security
- Data is transmitted over encrypted connections (HTTPS/TLS).
- Shopify access tokens are encrypted at rest using AES-256-GCM.
- Access to production systems is limited and authenticated.
- We honor Shopify's mandatory compliance webhooks for data access and deletion requests.
No method of transmission or storage is 100% secure, but we work to protect information using industry-standard measures.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal data, and to data portability.
- Merchants can exercise these rights by contacting us (below) or by uninstalling the App.
- Customers of a merchant should direct requests to the merchant, who is the controller of that data; we will assist the merchant in fulfilling valid requests, including through Shopify's data-request and redaction webhooks.
Residents of the EEA/UK (GDPR) and California (CCPA/CPRA) have additional rights, which we honor as applicable. We do not "sell" or "share" personal information as those terms are defined under California law.
8. International data transfers
The App is hosted in the United States via our hosting provider. If you access the App from outside that region, your information may be transferred to and processed there. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The App is a business tool and is not directed to children. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date.
11. Contact
Mobinyze
Email: Support@mayraapps.com
