Legal
Privacy Policy
Effective date: August 24, 2026
Mayra Apps ("Mayra", "we", "us") provides the Mayra - Order Edit & Upsell application ("App") for Shopify merchants. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
This policy covers two audiences: merchants who install the App, and their customers, whose order information the App processes on the merchant's behalf.
Our role. For a merchant's customer personal data, the merchant is the data controller and Mayra acts as a data processor that processes that data only to provide the App's functionality. For a merchant's own account information, Mayra is the controller.
1. Information we collect
From merchants (when you install and use the App):
- Your store's myshopify.com domain and store details available through Shopify.
- A Shopify access token that authorizes the App to call Shopify APIs on your behalf (stored encrypted - see Security).
- App configuration and settings you choose (edit window, allowed actions, refund handling, upsell and cancellation-deflection settings, etc.).
- Basic usage and diagnostic logs.
Customer personal data (processed on the merchant's behalf to provide the service):
- Order information (line items, quantities, variants, totals, fulfillment and payment status).
- Customer name, email address, and shipping address - used to verify that a customer owns the order they are editing and to apply changes such as address updates.
- Records of edits, cancellations, cancellation reasons, upsell offers, and related activity, linked to the relevant order.
We do not collect customer phone numbers, and we do not process or store payment card details - payments are handled entirely by Shopify Checkout.
2. How we use information
- To provide the App's core functionality: letting customers edit, cancel, or add to their orders; processing balances and refunds through Shopify; presenting post-purchase upsells; and offering store credit to reduce cancellations.
- To show merchants analytics about how the App is used (e.g., orders edited, revenue recovered, estimated support tickets avoided).
- To operate, secure, maintain, and improve the App.
- To comply with legal obligations and Shopify's requirements.
We do not sell personal data, and we do not use it for advertising or unrelated marketing.
3. Legal bases (EEA/UK)
Where GDPR applies, we process merchant account data to perform our contract with you and for our legitimate interests in operating and securing the App. Customer personal data is processed on the documented instructions of the merchant (the controller), under the merchant's legal bases.
4. Sharing and sub-processors
We share data only with service providers that help us run the App:
- Shopify Inc. - the platform the App runs on, and the source and destination of order data.
- Railway - application hosting and our PostgreSQL database.
- Convot - support chat in the Mayra admin and on our website. Processes your support messages and a limited set of account details (store domain, plan, contact name, email, phone, install date, admin language).
- Microsoft Clarity - product analytics and session replay in the Mayra admin. Processes masked interaction data (clicks, navigation, device and browser) with store domain, plan, and language as identifiers.
We maintain data processing agreements with our subprocessors.
Support chat (Convot). We use Convot to provide support chat inside the Mayra admin and on our website. When you use the chat, Convot processes the messages you send and a limited set of account details we attach so we can assist you: your store domain, Shopify plan, contact name, email, phone, install date, and admin language. Convot also provides an automated (AI) assistant that may process your messages to suggest replies. We do not send your customers' personal data to Convot. See Convot's privacy policy at convot.io/privacy.
Product analytics and session replay (Microsoft Clarity). We use Microsoft Clarity to understand how merchants use the Mayra admin so we can improve the interface and onboarding. Clarity records interaction data such as clicks, scrolling, navigation between pages, and general device and browser information, from the Mayra admin only. Text content on the screen is masked (Clarity is configured in strict masking mode), so the specific contents of orders, customer names, and addresses are not captured. We attach your store domain, plan, and admin language so we can locate and filter sessions. We do not use Clarity on your storefront or on the screens your customers see. See Microsoft's privacy statement at privacy.microsoft.com.
We may disclose information if required by law or to protect rights, safety, and security. We do not sell or rent personal data to third parties.
5. Data retention
We retain merchant configuration and order-linked records for as long as the App is installed and as needed to provide the service. When a merchant uninstalls the App, or upon a valid deletion request or a Shopify "shop redact" / "customer redact" request, we delete the associated data in line with Shopify's mandatory data-protection webhooks (customers/data_request, customers/redact, shop/redact).
6. Security
- Data is transmitted over encrypted connections (HTTPS/TLS).
- Shopify access tokens are encrypted at rest using AES-256-GCM.
- Access to production systems is limited and authenticated.
- We honor Shopify's mandatory compliance webhooks for data access and deletion requests.
No method of transmission or storage is 100% secure, but we work to protect information using industry-standard measures.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal data, and to data portability.
- Merchants can exercise these rights by contacting us (below) or by uninstalling the App.
- Customers of a merchant should direct requests to the merchant, who is the controller of that data; we will assist the merchant in fulfilling valid requests, including through Shopify's data-request and redaction webhooks.
Residents of the EEA/UK (GDPR) and California (CCPA/CPRA) have additional rights, which we honor as applicable. We do not "sell" or "share" personal information as those terms are defined under California law.
8. International data transfers
The App is hosted in the United States via our hosting provider. If you access the App from outside that region, your information may be transferred to and processed there. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The App is a business tool and is not directed to children. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date.
11. Contact
Mayra Apps
Email: Support@mayraapps.com
