Skip to main content

Privacy Policy

How Justify Ltd handles the customer and order data we process for connected stores (Shopify, WooCommerce, TikTok Shop). Last reviewed 23 July 2026.

Our role: processor and controller

When you connect a store, Justify acts as a processor for that merchant's customer data. The merchant remains the controller of their own customer relationships, and their instructions (the connection / data-processing agreement) are the operative authority for what we ingest. Justify acts as a controller only for the derived influencer-attribution analytics it produces on top of that data.

What customer data we collect

The core privacy guarantee is on email: raw customer email is never stored. We persist only a keyed, one-way hash (emailHash), used solely for de-duplicating customers and matching customers to influencers. Because the hash is keyed and irreversible, it is pseudonymised data, not cleartext personal data. This is the only privacy claim we make unqualified. Other personal data below is retained.

From a connected store we also collect, under the lawful bases shown:

DataCategoryLawful basis
emailHashPseudonymised identifier (keyed one-way hash)Legitimate interest; merchant instruction
Display name / first-name initialPersonal data (name)Merchant instruction; legitimate interest
City / region / countryCoarse location (city-level only; no street, postcode, or phone)Legitimate interest (geo analytics)
Orders count / total spent / currencyPurchase summary (aggregate, not transaction-level)Legitimate interest (analytics)
Order line itemsProduct / quantity / price detail (no names or addresses)Legitimate interest (revenue/product analytics)
Promo codes, UTM source / medium / campaign / content / termMarketing attributionLegitimate interest (attribution)

We never persist a personal-data field we cannot name a use for. Aggregated summaries and line items must not carry names or addresses by design.

Retention and deletion on disconnect

We hold connected-store customer and order data for the life of the store connection. When a store is disconnected or the app is uninstalled, we purge that store's customer and order personal data within 30 days. We do not claim instantaneous deletion: the short, bounded window covers Shopify's mandatory data-request and redaction webhooks plus a safety margin. This 30-day rule is enforced by a scheduled purge job, not merely documented.

Sub-processors

We use the following third-party sub-processors. We notify customers at least 30 days before a new sub-processor begins processing personal data.

Sub-processorLocationPurpose
NeonUSDatabase hosting
UpstashUSCaching and rate limiting
ClerkUSAuthentication and user management
StripeUSPayment processing
VercelUSCloud hosting and analytics
AWS (Amazon)UKFile storage and delivery
Trigger.devUSBackground job execution
OpenAIUSAI text generation, analysis, and semantic moderation
Google (Vertex AI)USAI video and image analysis
AnthropicUSAI text generation
ResendUSTransactional email delivery
MuxUSVideo upload, encoding, and playback
SentryUSError monitoring and application diagnostics
PhylloUSSocial media analytics
CintSE/USSurvey panel recruitment and response collection
ShopifyCA/USE-commerce integration
TikTok ShopSG/USE-commerce integration
fal.aiUSAI media generation and transformation
TwilioUSSMS sending and delivery for outreach

How to request deletion

Shopify merchants and their customers can exercise deletion rights through Shopify's mandatory privacy webhooks, which we implement: a customer-data request, a customer redaction (customers/redact), and a shop redaction (shop/redact) each trigger real deletion of the corresponding records. You may also contact us in-app to request deletion. Disconnecting or uninstalling the app starts the automatic purge described above.

DiscoverJustify for agentsPrivacyjustify.app