Privacy Policy
Refiner helps merchants detect and resolve store issues in Shopify stores. This Privacy Policy explains what information we process, why we process it, how long we retain it, and what controls are available to merchants and authorized store users.
Who this policy applies to
This policy applies to merchants and authorized users of stores that install Refiner, and to data processed through the app while providing scan, diagnostics, fix, billing, and support features.
Data categories we process
- Store and installation metadata: shop domain, app installation identifiers, configuration values.
- Operational issue data: scan findings, issue states, fix attempts, and fix outcomes.
- Service usage data: feature usage logs, credits usage, plan and billing metadata.
- Support interaction data: in-app support messages and related troubleshooting context.
- Security and reliability logs: request metadata, error traces, and webhook processing records.
How and why we use data
- To provide core app functionality, including scans, issue diagnostics, and merchant-triggered fixes.
- To authenticate requests, enforce shop ownership, and protect service integrity.
- To apply plan limits, credit controls, and billing-related entitlement checks.
- To provide customer support, troubleshoot incidents, and improve service reliability.
Legal bases for processing
Where applicable, we process data to perform our contract with merchants, to satisfy legal obligations, and for legitimate interests such as security, fraud prevention, and service reliability.
Data sharing and subprocessors
We do not sell merchant data. We share data only with providers required to operate the service, such as hosting, database, and API infrastructure vendors, under contractual safeguards and only to the extent required for service delivery.
International transfers
Data may be processed in countries where our service providers operate. Where required, we apply appropriate transfer safeguards under applicable law.
Retention and deletion
We retain data for the following default periods:
- Scan logs and detected issues: 90 days from creation.
- Webhook and event processing records: 30 days from creation.
- Billing and subscription records: retained while required for billing operations and dispute handling.
- GDPR deletion requests: processed and data permanently deleted within 30 days of the request.
We may retain limited records longer where required for legal obligations, security investigations, fraud prevention, or dispute handling.
Merchant controls and rights
- Export available account and operational data from app settings.
- Request deletion of account data from app settings.
- Uninstall the app to stop new access to store resources.
Uninstall behavior
After uninstall, Refiner stops initiating new access to the store. Residual records may be retained temporarily for lawful operational purposes before deletion according to retention policy.
Security measures
We apply technical and organizational controls designed to protect data against unauthorized access, alteration, disclosure, or destruction, including request authentication, scoped access controls, and transport encryption.
Policy changes
We may update this policy from time to time. Material changes are reflected by updating the date above.
Contact
For privacy requests, contact info@onlytenbucks.com.