Privacy policy
Post Purchase Upsell Abakira shows a one-click offer after a buyer has paid and before their order confirmation, and adds the accepted item to the order they just placed.
What we access, and why
- Products — so the merchant can choose which product and variant an offer promotes. We never modify the catalogue.
What we store
We store the offer the merchant configured: a product variant, a discount, and the shop it belongs to.
We also store the merchant’s contact email and the language of their Shopify admin, both provided by Shopify. They are used to run the app and to send essential service messages — for example, to warn a merchant, in their own language, that they are approaching the limit of their free plan and that their offer will stop being shown. This is not marketing consent: we do not send promotional email on this basis. Both fields are deleted when the app is uninstalled.
We do not store buyer names, emails, phone numbers, addresses, payment details or cart contents. When an offer is accepted, the buyer’s browser asks Shopify to compute the change and asks our server to sign it. The signature is computed and returned; nothing about the buyer is written down.
Your card is never seen by us. Shopify charges the payment method already attached to the order, on its own infrastructure.
Who else sees this data
We use Vercel to run the app, Neon to store it,Resend to send operational email to the merchant (a welcome note, and usage alerts on the free plan), and Crisp (Crisp IM SAS, Nantes, France) for the support chat inside the merchant admin. Neither Vercel nor Neon is given buyer data, because we hold none. Resend only ever receives the merchant’s contact email, never a buyer’s.
The support chat loads only in the Shopify admin. It never runs on a storefront, and never on the post-purchase page: your buyers never encounter it. Crisp sees only what a merchant chooses to write to us.
Our page on the Shopify App Store carries a Google Analytics tag, which we also use for Google Ads. We put a measurement ID in our listing settings and Shopify reports the page views, and the fact that an install happened, to Google. That tells us which ad brought a merchant to the listing, and it lets us advertise again to people who looked at it. It is Shopify’s page rather than ours, and all of it happens before anything is installed. The app itself carries no Google tag: none in your admin, none on your storefront, and your buyers are never part of it.
When someone clicks a partner link (abakira.com/go/…), we store the partner code, a salted hash of the visitor’s IP address (never the address itself — it cannot be recovered from the hash) and the browser’s user-agent, for up to 30 days, solely to credit the partner when a store installs the app shortly after. Stores referred this way may receive a free trial of paid features; the referral code is stored with the store’s record and deleted with it.
If a merchant connects their warehouse system (Picqer) on the Scale plan, we store the API key they give us encrypted, and never show it again. When a buyer accepts an upsell, we send that product and quantity to the merchant’s own warehouse system, on the merchant’s instruction, so the item ships in the same parcel. The key and the sync records are deleted with the store.
If a merchant connects their subscription app (Recharge) on the Scale plan, we store the API token they give us encrypted, and never show it again. When a buyer accepts an offer to extend their own subscription, we ask the merchant’s subscription app to change the frequency of that subscription, on the merchant’s instruction. We never create a subscription, we never charge a renewal, and we never read subscriptions unrelated to the order the buyer just placed. The token and the upgrade records are deleted with the store.
What we never do
- We do not sell or share merchant or buyer data.
- We do not use buyer data for advertising or profiling.
- We show no third-party advertising in the post-purchase page. The only thing a buyer sees there is the merchant’s own offer.
- We do not track buyers across stores.
How it is protected
Data is encrypted in transit (HTTPS/TLS everywhere, including between the app and its database) and at rest by our database provider. The discount applied to an offer is re-read from our database and signed on our server: it can never be set by the buyer’s browser.
Deletion
When a merchant uninstalls the app, their offer stops being shown immediately. Shopify then sends us a shop redaction request 48 hours later, and we delete every record we hold for that shop. Merchants can also ask us to delete their data at any time.
Our agreement with merchants
We act as a data processor on behalf of the merchant, who remains the controller of their store’s data. Installing the app means accepting this policy, and it is the data protection agreement between us: we process only the data listed above, only for the purposes listed above, and we never use it for our own ends. If we ever need to process anything else, this page changes first, in the same commit as the code.
Contact
Post Purchase Upsell Abakira is built by Abakira. Our other Shopify apps, and how we work, are at abakira.com.