Legal

Privacy Policy

What Revy collects from Shopify, what stays private, how you control your public page, and how to delete your data.

Last updated July 12, 2026

Overview

Revy (“Revy”, “we”, “us”) provides verified growth pages, dashboards, flex cards, and leaderboards for Shopify merchants. This Privacy Policy explains what information we collect, how we use it, who can see it, and the choices you have.

This policy applies when you visit revy.app, create a Revy account, connect a Shopify store, or view a merchant’s public Revy page. By using Revy, you agree to this policy. If you connect Shopify, you also authorize the data access described below.

Who this policy covers

If you are a shopper on a merchant’s Shopify store, that store’s own privacy policy governs your relationship with the merchant. Revy does not receive your name, email, or shipping address from Shopify.

  • Merchants who sign up and connect a Shopify store to Revy.
  • Team members who access a merchant’s Revy dashboard through that merchant’s account.
  • Visitors who view public or unlisted Revy pages, the leaderboard, or marketing pages on revy.app.

Information we collect

Account information

When you create a Revy account, we collect the information needed to authenticate you and operate your dashboard. Authentication is handled by our identity provider (Clerk), which may collect your name, email address, and sign-in activity.

  • Email address and display name from your Revy / Clerk account.
  • Account identifiers used to link your Revy account to your connected Shopify store.

Store profile information you provide

You choose what appears on your Revy page. This content is stored so we can render your public profile and dashboard settings.

  • Store name, URL slug, tagline, short description, and longer “about” text.
  • Category, location, website link, and “operating since” year.
  • Logo and brand color choices you upload or select.
  • Privacy and visibility preferences (see “Your privacy controls” below).

Shopify store data we sync

Revy connects to Shopify with read-only API access. We pull store-level metrics and analytics needed to verify your dashboard, public Revy page, flex cards, and leaderboard ranking. Shopify remains the source of truth—Revy stores a synced copy so pages load quickly.

  • Revenue, order counts, average order value, and month-over-month growth.
  • Monthly and historical revenue series used for charts and year filters.
  • Product-level aggregates such as best-selling product titles and units sold (not tied to individual shoppers).
  • Marketing channel attribution derived from order referral data (for example Google, Facebook, email).
  • Recent order-level facts used for dashboard analytics: order date, net amount, referral channel, and line-item product titles, quantities, and revenue. These facts are trimmed to a rolling window for performance.
  • Optional Shopify Analytics data when you grant the read_reports scope—such as sessions, traffic trends, and marketing reports. Some report types require Shopify Protected Customer Data approval; if unavailable, Revy falls back to order-based estimates or synced history.
  • Shop domain, currency, OAuth access tokens, granted API scopes, and sync timestamps.

Billing information

Paid plans are billed through Shopify’s app billing system. We store your plan type, billing status, and Shopify subscription or purchase identifiers so we can enable paid features. We do not collect or store credit card numbers—Shopify processes payment on your Shopify invoice.

Usage and technical data

Like most web services, we automatically collect limited technical information when you use revy.app.

  • Device and browser type, approximate location from IP address, and pages viewed.
  • Referring URLs and basic interaction data needed to secure the service and fix errors.
  • Server logs retained for a limited period for security, abuse prevention, and debugging.

What we do not collect

  • Customer names, email addresses, phone numbers, or shipping and billing addresses.
  • Individual shopper profiles or a durable map of which person placed which order.
  • Payment card numbers or bank account details (Shopify handles merchant billing).
  • Permission to change your Shopify catalog, inventory, prices, checkout, or orders—Revy is read-only.

We may process aggregate counts (for example total orders or new vs. returning customer totals from Shopify Analytics). Those figures are not stored alongside customer identity in Revy.

Shopify permissions explained

When you install or reconnect Revy in Shopify, you approve a set of read-only scopes. Each scope exists for a specific feature:

  • read_orders — load recent order totals and referral attribution for your dashboard.
  • read_all_orders — access full order history so year filters, revenue history, and older marketing channel breakdowns stay accurate.
  • read_products — resolve product titles for top-product and best-seller displays.
  • read_reports — fetch Shopify Analytics sessions and marketing channel reports when available.

You can review granted scopes anytime under Dashboard → Integrations. Reconnecting Shopify lets you add missing scopes without losing your Revy account.

How we use information

  • Verify and display metrics on your Revy dashboard, public page, flex cards, and exports.
  • Rank stores on the merchant leaderboard when you opt in and your plan includes visibility.
  • Honor your privacy toggles—only metrics you enable appear publicly.
  • Process subscriptions and lifetime purchases through Shopify billing.
  • Send service-related messages (for example account, billing, or security notices).
  • Monitor performance, prevent abuse, and improve Revy.
  • Comply with law and respond to valid legal requests.

We do not sell your personal information or Shopify metrics to data brokers. We do not use your store metrics to train generalized AI models.

Your privacy controls

Revy gives you granular control over what appears on your public page and in shareable assets. Settings are available under Dashboard → Settings → Privacy and during onboarding.

Changes apply to your public Revy page and new flex cards. Previously downloaded images are not retroactively changed.

Profile visibility

  • Public — your page can be listed and shared; may appear in search if indexing is on.
  • Unlisted — only people with the link can open your page.
  • Private — only you can view your page while logged in.

Metric toggles

  • Show or hide revenue, orders, average order value, growth rate, revenue chart, about section, best seller, leaderboard rank, operating since, and location.
  • Control whether search engines may index your page.
  • Choose whether to appear on the public merchant leaderboard.

Flex card display defaults

  • Exact revenue — show verified dollar amounts.
  • Growth only — show percentage growth without exact revenue.
  • Rank only — show category rank without revenue figures.

What is public vs. private

  • Private to you: dashboard analytics beyond your chosen public toggles, OAuth tokens, billing details, and raw synced order facts used internally.
  • Potentially public: any metric or profile field you leave enabled while your page is Public or Unlisted, plus leaderboard placement when enabled.
  • Visitors: anyone with your link can view an Unlisted page; Public pages may also be discoverable through Revy or search engines depending on your settings.

How we share information

We do not share Shopify metrics with advertisers for their independent use.

Service providers

We use trusted vendors to host and operate Revy. They may process data only on our instructions and under contractual confidentiality obligations.

  • Cloud hosting and database providers (for example Vercel and our PostgreSQL host).
  • Clerk for authentication and account management.
  • Shopify for store data sync and merchant billing.

Other sharing

  • Public Revy pages and leaderboard entries you choose to publish.
  • Legal or safety disclosures when required by law or to protect rights and security.
  • Business transfers if Revy is acquired—your data would remain subject to this policy or a successor notice.

Data retention & deletion

  • While connected: we retain synced Shopify metrics, dashboard analytics, and profile content needed to operate your account.
  • Disconnect: use Dashboard → Integrations → Disconnect. We delete synced store metrics, OAuth tokens, dashboard analytics, and uploaded logos from Revy. Your Shopify store is unchanged.
  • Uninstall: removing the Revy app from Shopify triggers the same shop-level cleanup via Shopify webhooks.
  • Shop data redaction: Shopify’s mandatory shop/redact webhook deletes remaining shop records for that domain.
  • Account data: your Revy login may remain after disconnect unless you ask us to delete it. Profile content tied to a deleted shop is removed with the shop record.

Backups may retain encrypted copies for a short window before automatic purging. Aggregated, non-identifying analytics used for operations may be kept longer.

Security

We use industry-standard measures to protect data in transit and at rest, including HTTPS, access controls, and encrypted storage of sensitive credentials such as Shopify access tokens.

No online service is perfectly secure. Please use a strong password and keep your Shopify and Revy accounts protected.

International users & your rights

Revy is operated from the United States. If you access Revy from the EU, UK, or other regions with privacy laws, you may have additional rights regarding access, correction, deletion, portability, and objection to certain processing.

EU / UK merchants: we process data to perform our contract with you (providing the Service), based on legitimate interests (security, product improvement), and with consent where required—for example marketing emails if we send them and you opt in.

California residents: we do not sell personal information as defined by the CCPA. You may request disclosure or deletion by contacting us.

  • Request a copy of personal data we hold about you.
  • Ask us to correct inaccurate account information.
  • Request deletion of your Revy account or remaining personal data.
  • Object to or restrict certain processing where applicable law allows.

To exercise these rights, email hello@revy.app from the address associated with your account. We may need to verify your identity before fulfilling a request.

Cookies & similar technologies

Revy uses essential cookies and local storage to keep you signed in, remember preferences, and protect against abuse. We may use minimal analytics to understand how the marketing site and dashboard are used.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from signing in or using the dashboard.

Children

Revy is intended for merchants and business users aged 18 and over. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes may also be communicated by email or in-dashboard notice.

Continued use of Revy after an update means you accept the revised policy.

Contact

Questions, privacy requests, or concerns about this policy: email hello@revy.app or visit https://revy-baaq5lx2l-denyslavangelov-gmailcoms-projects.vercel.app/contact.

For Shopify-specific data questions, you can also manage app permissions from your Shopify admin under Apps and sales channels.