How the service handles information
Information supports
the service.
A plain-language description of the information Firesio Trade In processes for Shopify merchants and their customers.
Last updated: September 29, 2026
01Information we process
The app processes the merchant store domain and Shopify installation identifiers; merchant staff names and email addresses used for access and support; customer name, email address, postal address, country, and optional marketing preference submitted in a trade-in; selected products, variants, quantities, condition notes, uploaded photos, estimates, offers, messages, handover status, reward preference, and request timestamps; and technical events needed to authenticate requests, prevent replay, audit changes, send notifications, and troubleshoot failures.
02Why we use it
We use this information to display the merchant catalog, receive and review requests, keep offers and messages together, coordinate handover, record the reward agreed by the merchant, provide request status, protect the service, and answer support questions. We do not sell this information, use it to build advertising profiles, or use customer trade-in content to train a general-purpose model.
03Service providers and Shopify
The app shares data only with providers that make the service work: Shopify for installation, merchant identity, billing, and store APIs; Cloudflare for application hosting, D1 relational storage, KV sessions and cache, queues, and object storage; and the configured email delivery provider for transactional messages. Providers receive only the data needed for their function and may not use it for their own advertising. We do not share data with data brokers.
04Storage and retention
Application records are stored in the Cloudflare resources configured for the deployment. We keep merchant and request records while the store uses the app so the workflow and support history work. When a shop uninstalls, Shopify compliance events trigger deletion of shop-scoped records, subject to a limited security or legal hold. Backups, logs, and email delivery records expire on their provider retention schedule.
05Security controls
Connections use HTTPS. Shop-scoped records are addressed by the store domain, access is checked before reads and writes, sessions and signed links expire, webhook payloads are verified, and background consumers use idempotency guards. Staff access is limited by role. No online system is risk-free, so suspected incidents are investigated and notifications are made when required by law.
06Individual and merchant requests
A customer can ask the merchant that collected the trade-in information to provide access, correct it, or delete it. A merchant can contact support to request export or deletion for its shop. Firesio Trade In also handles Shopify customers/data_request, customers/redact, and shop/redact compliance webhooks and applies the request to the shop-scoped data we control.
07How to contact us
Use the support page linked below and include enough context for us to find the correct shop and request without sending unnecessary personal data. The merchant remains responsible for its own privacy notice, lawful basis, customer communications, and choices about what the store accepts.
08Policy changes
We update this page when our processing or the service changes materially. The effective date at the top changes with each published revision. If a change affects an installed store in a material way, we will use an available merchant contact channel or an in-app notice.