For merchants using the Reviews Sync app. Last updated 23 August 2026.
This notice describes the personal data the Reviews Sync Shopify app processes on your behalf, and the limits we place on ourselves. It is separate from the privacy policy governing purchases made on this site, because the relationship is different: for your store's data we act as a processor, on your instruction, for the purposes set out below and no others.
1. What the app processes
Three things, and only in service of publishing a review:
- Customer name — displayed as the review author. Shown as a first name only.
- Customer email address — matched against your order records to confirm the reviewer actually bought the product, so a "verified purchase" mark means something. The address is used for that check and is not retained.
- The review itself — the rating and the words the customer wrote, stored verbatim.
Order data is read only to answer one question: did this person buy this product. The app reads product identifiers from order line items. It does not read or store order totals, payment details, or any financial field.
2. What the app deliberately does not process
- Phone numbers and addresses. Not requested, not read, and no field exists to hold them.
- Payment or card data. Never accessed. The app holds no payment scope.
- Contact details of reviewers migrated from another platform. When you import an existing review corpus, contact columns in the export are refused by name and reported back to you as refused. A migrated reviewer never agreed to hear from you, and importing their address would not change that.
3. How a review is stored
A published review is stored against a pseudonymous reviewer reference — a one-way derived identifier — rather than against an email address. Someone reading the review register cannot recover the reviewer's contact details from it, because they are not there.
Reviews are held in a register operated for us by Xano, and application state in Cloudflare Workers KV. Data is encrypted in transit and at rest. Credentials for your store are encrypted separately and are scoped to your store alone: a credential that escaped would read one shop, not every shop that ever installed the app.
4. Automated processing of review text
When a review is written or imported, its text is read once to extract what the customer praised and what they faulted, to detect the language it was written in, and to screen for spam. This runs inside our own infrastructure on Cloudflare's inference platform. Review text is not sent to a third-party model provider.
Spam screening holds a review for a human to look at. It does not reject a review automatically, and it has no legal or similarly significant effect on the person who wrote it. Where the model fails or times out, the review is stored unscreened and marked as not assessed, never as clean.
5. Consent
A review cannot be written without a recorded acceptance of the privacy terms. The acceptance is stored with its basis, its timestamp, and the surface it was collected on, and it is entered into a tamper-evident record. Where a reviewer arrives from a review-request link rather than an account, the terms are shown on that page and the acceptance is recorded against the link that authorised it — the requirement is met, not waived.
6. Erasure and data subject requests
On an erasure request, the review is tombstoned — the words, the display name and the reviewer reference are removed while the fact that a review existed and its date are retained, because that is what proves the rating you published was real. Where the review had been projected to Google, the copy held there is deleted as part of the same operation; erasure that stops at your own database is not erasure.
One deliberate exception: an unsubscribe record survives erasure. It is stored as a one-way hash rather than an address, so it is not personal data, and deleting it would re-enable mail to somebody who asked you to stop.
The app also answers Shopify's mandatory customers/data_request, customers/redact and shop/redact webhooks, and dispatches them to real export and erasure paths rather than acknowledging and discarding them.
7. Retention
A published review is retained for as long as it is published — that is the point of it. Review-request links expire after 30 days and can be used once. Uninstalling the app revokes your store's credential immediately. Erasure requests are actioned as described above.
8. Sub-processors
- Cloudflare — application hosting, storage, and the inference used for review enrichment.
- Xano — the review and consent register.
- Shopify — your store's own platform, from which order and customer data is read.
- Google — only where you enable the Google Merchant projection, and only for reviews you have published.
9. Your instructions
We process your customers' data on your instruction and for the purposes above. We do not sell it, do not use it to build a profile, and do not use one merchant's data to serve another. Reviews collected on your store belong to your store; where you operate several storefronts, they are pooled only if you explicitly configure them to be.
10. Contact
Data protection enquiries and data subject requests: [email protected]. We respond to erasure and access requests within the statutory period applicable to your jurisdiction.