Privacy policy

How Cohortly handles store data

Effective July 17, 2026

Cohortly Repeat Tracker is operated by the developer identified in the app's Shopify App Store Business Imprint. Privacy questions can be sent to hakan.olcer@web.de.

Scope and roles

This policy applies to the Cohortly embedded Shopify app and this public documentation site. The merchant controls the Shopify store and determines why its commerce data is processed. Cohortly processes that data to provide the merchant-requested analytics service.

Data the app processes

Customer identity fields: Cohortly reads only the stable Shopify customer identifier needed to link orders from the same customer, then stores a keyed hash. Its order query does not request customer name, email address, phone number, billing address, or shipping address.

Why the data is used

Cohortly does not use store data to send marketing, build advertising audiences, sell personal information, or operate a marketplace.

Service providers and disclosure

The service communicates with Shopify to authenticate merchants, read approved store data, receive privacy webhooks, and use Shopify-hosted app billing. It uses Cloudflare infrastructure for application hosting, database storage, queues, and generated export storage. Data may also be disclosed when required by law or necessary to protect the service, merchants, or others. Cohortly does not sell merchant or customer data.

Retention and deletion

Merchants can select a source-data retention period from 30 to 365 days in the app. Source order facts older than that period are deleted by scheduled cleanup; affected derived analytics and exports are invalidated or removed. A privacy data-request report is retained for no more than 30 days. Operational and privacy request records are retained only for the configured operational period or as needed to complete an active request.

Verified Shopify customers/redact requests remove matching pseudonymous customer and order facts and invalidate affected aggregate output. Cohortly keeps only secret-keyed, non-reversible customer or order redaction fingerprints while the shop remains installed so a later sync cannot restore erased facts. Verified shop/redact requests remove those fingerprints together with the shop record, access token, settings, source data, derived analytics, exports, logs, and related artifacts held by Cohortly.

Security

Network traffic uses HTTPS. OAuth access tokens are encrypted before storage. Shopify customer and order identifiers used for analysis are transformed with a secret-keyed one-way hash. Access to app data is scoped to the authenticated merchant. No security method can eliminate every risk, so suspected security issues should be reported promptly to the contact below.

Privacy requests

Customers should first contact the merchant that controls their Shopify store data. Shopify sends applicable data-access and redaction requests to Cohortly through signed compliance webhooks. Merchants can also contact hakan.olcer@web.de about app data. Do not send customer names, emails, phone numbers, addresses, or unredacted order screenshots by email.

Public website

This public site is static and does not include advertising, behavioral analytics, or application login forms. Cloudflare may process standard network request information to deliver and protect the site.

Changes

This policy may be updated when the service or legal requirements change. The effective date above identifies the current version.