Privacy Policy

Effective date: August 19, 2026

Effective Date: August 19, 2026

Welcome to Shoffi, an independent service operated by Avit Tech, LLC. This Policy describes our privacy practices and rights that may apply under applicable privacy laws.

This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use our Service, accessible from shoffi.app and its subdomains.

1. Definitions and Interpretation

"Personal Data" refers to any information relating to an identified or identifiable natural person.

"Service" means the Shoffi websites and the services made available through them.

"App Owner" means a customer who creates or manages an app or affiliate program using Shoffi.

"Team Member" means a user authorized by an App Owner to access part of that App Owner's Shoffi account.

"Affiliate" means a user participating in an App Owner's affiliate program.

"User" means an App Owner, Team Member, Affiliate, or other individual who accesses the Service, as applicable.

"Partner API Credentials" means Partner API client access tokens, organization identifiers, app identifiers, permission-related information, and other configuration information manually provided by an App Owner to enable Shoffi to interact with the Shopify Partner API.

"Customer Data" means information, records, credentials, content, files, database information, analytics information, Shopify Partner API data, BigQuery data, referral information, merchant or shop identifiers, and other information submitted, provided, made accessible, or caused to be processed through the Service by or on behalf of an App Owner.

"Third-Party Services" means third-party platforms and services with which the Service interoperates or on which it relies, including Shopify and Google.

"Information We Process" includes Personal Data as well as Customer Data, App Owner-provided business information, confidential information, Partner API Credentials, Shopify Partner/API data, and data processed through customer-configured integrations that may not relate to an identifiable natural person.

"Processing" includes any operation performed on Information We Process, whether or not by automated means, such as collection, storage, access, use, organization, transmission, or deletion.

"Controller" refers, where applicable, to the entity that determines the purposes and means of processing Personal Data.

An Affiliate does not provide Shoffi with an App Owner's Shopify Partner API Credentials merely by registering for or participating in an affiliate program.

Shoffi acts as a controller for Personal Data that it determines the purposes and means of processing, such as account administration, authentication, billing, Service security, fraud prevention, support, Service analytics, and communications.

2. Information We Process and How We Use It

Some Information We Process is Personal Data. Other information consists of Customer Data, App Owner business records, Partner API Credentials, and Partner API data that may not identify a natural person. When business information identifies or can reasonably be linked to a natural person, we treat it as Personal Data under this Policy.

Information by Role:

  • App Owners: Account/contact details, app configuration, Partner API Credentials, BigQuery integration details, subscription/billing information, usage logs, and actions performed through the account.
  • Team Members: Account/contact details, assigned roles and permissions, usage logs, actions performed through the account, and information made available to them according to permissions assigned by the App Owner.
  • Affiliates: Account/contact information, nickname/profile information, affiliate-program memberships, affiliate links/codes, referrals, commission records, payout information and related activity.
  • Referred Shops: Shop identifiers, installation status, attribution information, transaction-related records and other information necessary to administer referrals and commissions.

Types of Information We Process:

  • Account and Contact Information: Names, email addresses, phone numbers, account roles, and authentication information.
  • Shopify Partner API Credentials: Partner API client access tokens, organization identifiers, app identifiers, permission-related information, and other configuration information manually provided by an App Owner to enable Shoffi to interact with the Shopify Partner API.
  • Shopify Partner and App Information: Partner, organization, app, and referral identifiers and other app information contained in Partner API responses.
  • Financial and Transaction Information: Transaction records, app revenue information, subscription or plan information, commissions, and related financial records retrieved through the Shopify Partner API or provided through the Service.
  • Installation and Referral Information: App installation and uninstallation events, referral and attribution information, and related activity.
  • Shop Identifiers: Shop identifiers contained in Partner API responses where present.
  • Other Partner API Data: Other information contained in Partner API responses that is needed to provide Service features requested or enabled by the App Owner.
  • Customer-Configured Analytics and BigQuery Data: Information made available to Shoffi through customer-configured Google BigQuery or similar data integrations, which may include shop identifiers, affiliate or referral identifiers, attribution events, app events, timestamps, transaction-related information, analytics information, and other records made available through the resources selected by the App Owner.
  • Usage and Technical Data: IP addresses, browser and device types, log data, diagnostic data, and service usage details.
  • Cookies and Tracking Technologies: We use various cookies and similar tracking technologies to understand how you interact with our Service and to enhance your user experience.

Shoffi may process both normalized information and underlying imported records where needed for synchronization, reconciliation, debugging, reprocessing, security, or support.

How We Use Information:

We use the Information We Process for purposes including:

  • To provide, secure, maintain, support, and improve the Service.
  • To use Partner API Credentials provided by an App Owner to interact with the Shopify Partner API.
  • To retrieve, synchronize, organize, display, and otherwise process Partner API data needed to provide the Shoffi Service.
  • To calculate referrals, attribution, commissions, transactions, and account or app statistics.
  • To administer accounts, subscriptions, support, and Service communications.
  • To monitor performance and usage, troubleshoot issues, and detect or prevent fraud, abuse, and security threats.
  • To comply with legal obligations and enforce our agreements.

Shoffi may use aggregated or de-identified information to analyze and improve the Service where permitted by applicable law.

Sources of Information:

Depending on the Service features used, we may obtain information directly from Users, from App Owners and Team Members, from Shopify through Partner API Credentials provided by an App Owner, from customer-configured BigQuery or other integrations, and from other information submitted or made available through the Service.

3. Shopify Partner API

Shoffi is an independent service operated by Avit Tech, LLC and is not operated by Shopify.

To use certain Shoffi features, an App Owner may manually provide Shoffi with Partner API Credentials created through its Shopify Partner organization. Shoffi does not require the App Owner to provide its Shopify account password.

The App Owner selects the Shopify permissions granted to its Partner API client from the options made available by Shopify. Shopify defines the technical capabilities associated with those permissions and may modify its APIs, permissions, resources, and functionality from time to time.

Shoffi uses the Partner API Credentials and data made available through them as reasonably necessary to provide, maintain, secure, troubleshoot, and support the Service and the features requested or enabled by the App Owner.

4. Customer-Configured BigQuery and Data Integrations

App Owners may choose to grant Shoffi access to particular Google Cloud or BigQuery resources. The App Owner determines which resources are made available, subject to Google's access-control system.

Shoffi processes information made available through those resources to provide the integration and related Service functionality requested by the App Owner.

App Owners are responsible for ensuring they have appropriate authority and lawful grounds to make such information available to Shoffi and for avoiding unnecessary or unrelated data.

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and store certain information. Cookies are small pieces of data stored on your device (computer or mobile device) that help us improve our Service and enhance your user experience.

Types of Cookies We Use:

  • Session Cookies: These cookies are essential for providing you with services available through our website and enable you to use some of its features. They help authenticate users and prevent fraudulent use of user accounts. Without these cookies, the services you have requested cannot be provided, and we only use these cookies to provide you with those services.
  • Analytics Cookies: We use Google Analytics cookies to measure and analyze how visitors use the website and to improve its functionality and user experience. Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. More information about Google Analytics cookies can be found on the official Google Analytics page.
  • Functionality Cookies: These cookies allow us to remember choices you make when you use our website, such as remembering your language preferences and chat settings. This includes cookies deployed by the Crisp platform to provide live chat support, and potentially other functionality cookies that improve your interaction with our site. These cookies can also facilitate enhanced, more personal features. They do not track your browsing activity on other websites.

Managing Cookies:

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. To manage cookies:

  • Visit the settings or preferences menu on your browser to manage settings.
  • Follow the instructions provided by your browser (usually located within the "help," "tools," or "edit" settings).
  • For more detailed information about cookie management with specific web browsers, find the respective browser's websites.

6. Legal Basis for Processing Personal Data

Where applicable privacy law requires a legal basis, we process Personal Data under one or more of the following:

  • Consent: We may process your data if you have given us explicit consent to use your personal data for a specific purpose.
  • Contract: Processing is necessary for the performance of a contract to which you are a party or to take steps at your request before entering a contract.
  • Legal Obligations: Processing is necessary for compliance with a legal obligation to which we are subject.
  • Legitimate Interests: Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party.

7. Your Privacy Rights

Depending on where you live and subject to applicable law, you may have rights regarding your Personal Data, including:

  • Right to access – You may have the right to request copies of your Personal Data.
  • Right to rectification – You may have the right to request that we correct inaccurate Personal Data.
  • Right to erasure – You may have the right to request that we erase your Personal Data under certain conditions.
  • Right to restrict processing – You may have the right to request that we restrict the processing of your Personal Data.
  • Right to object to processing – You may have the right to object to our processing of your Personal Data.
  • Right to data portability – You may have the right to request that we transfer certain Personal Data to another organization or directly to you.
  • Right to withdraw consent – Where processing is based on consent, you may withdraw that consent at any time, without affecting processing that occurred before withdrawal.
  • Right to complain – You may have the right to lodge a complaint with an applicable data protection authority.

8. Data Retention

We retain Information We Process for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Policy, comply with legal, accounting, reporting, or contractual obligations, resolve disputes, and enforce our agreements. In determining an appropriate retention period, we consider the nature and sensitivity of the information, the purposes for processing it, and the potential risks associated with unauthorized use or disclosure.

Different categories of information may be retained for different periods depending on the purpose for which they are processed, contractual obligations, security and fraud-prevention requirements, dispute resolution, backup cycles, and legal, accounting, or regulatory requirements.

Deleting an account or integration does not necessarily result in immediate deletion of every copy from backups, security records, legal records, or other systems where retention remains reasonably necessary or legally required.

Removing credentials from Shoffi does not itself revoke those credentials at the third-party provider. App Owners who wish to terminate third-party access should also revoke or rotate the applicable credentials through Shopify, Google, or the relevant provider.

9. Information Security and Incidents

We maintain reasonable administrative, technical, and organizational safeguards designed to protect the Information We Process, including account information, Customer Data, Partner API Credentials, Shopify Partner/API data, and data processed through customer-configured integrations, against unauthorized access, loss, misuse, alteration, or disclosure.

No security measure, information system, storage system, API, integration, or method of transmission can guarantee absolute security.

Shoffi may investigate suspected security incidents and may notify users or require credential rotation where required by law or contractual obligations, or where Shoffi reasonably determines that doing so is appropriate to mitigate security risk. App Owners remain responsible for safeguarding their Shopify Partner accounts and credentials and should promptly rotate or revoke credentials they know or suspect have been compromised.

10. Disclosure of Information

We may disclose Information We Process to service providers and contractors that help us host, secure, support, analyze, and operate the Service, including hosting and infrastructure providers; databases and storage providers; email and communications providers; customer-support providers; analytics providers; security providers; payment and billing providers; professional advisers; and other vendors needed to operate the Service, subject to appropriate obligations.

We may also transmit information to and receive information from Shopify when an App Owner provides Partner API Credentials to Shoffi for use of the Service.

We may disclose information when required by law or in response to a valid legal request, or where we believe in good faith that disclosure is reasonably necessary to protect rights or safety, investigate fraud or security issues, enforce our agreements, or respond to a government request. Information may also be disclosed in connection with a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to applicable law.

We do not disclose Personal Data to third parties for their direct marketing purposes without authorization.

11. International Data Transfers

Shoffi and its service providers may process information in countries other than the country in which the user is located. Where Personal Data is transferred internationally, we use applicable legal mechanisms and safeguards as required by applicable data protection law, which may include adequacy decisions or approved contractual safeguards.

12. Do Not Provide Sensitive Data

Unless expressly requested or supported by Shoffi for a specific feature, customers should not provide or make available through Customer Data or third-party integrations information concerning health, biometric or genetic information, precise personal financial credentials, government identification numbers, special-category personal data, or other highly sensitive personal information unrelated to the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised Policy and update its effective date. We may communicate material changes by email, in-app notice, or another reasonable method where appropriate or required by applicable law.

14. Contact Us

If you have any questions about this Privacy Policy, you can contact us:

By email: support@shoffi.app