Revuella Add to Shopify →

Privacy Policy

Last updated: 25 July 2026

Revuella ("we", "us", "our") provides AI-powered review intelligence for Shopify merchants. This policy explains what data we collect, how we use it, and the choices available to merchants and their customers.

1. Who this applies to

This policy covers data processed through the Revuella Shopify app, including data belonging to merchants who install the app ("Merchants") and end customers who visit a Merchant's storefront ("Shoppers").

2. Information we collect

From Merchants, via the Shopify Admin API on install and sync:

  • Shop domain, store name, and contact details provided by Shopify
  • Product catalog data (titles, IDs, images) needed to generate widgets
  • Review platform API credentials (e.g. Judge.me, Yotpo) that the Merchant enters in Settings, used solely to fetch review content
  • Klaviyo API key, if provided, used solely to sync generated content to the Merchant's Klaviyo catalog
  • Billing information via Shopify's native billing API — we never see card details directly

From Shoppers, via the storefront widgets and checkout:

  • Anonymous, aggregate interaction events — widget impressions, FAQ clicks, and add-to-cart events — used to power the Merchant's analytics dashboard.
  • If a Shopper begins checkout and does not complete their purchase, we receive their email address and the product they were purchasing via Shopify's checkout webhook. This is used solely to send a notification to the Merchant's connected Klaviyo account, so the Merchant can follow up with the Shopper about their abandoned cart. We do not use this email for any other purpose, and it is not stored in our own database — it is passed directly to Klaviyo and discarded once that request completes.

3. How we use information

  • To generate AI review summaries, FAQs, and research reports using Claude (Anthropic)
  • To sync generated content to the Merchant's connected review platform, storefront, and Klaviyo account
  • To operate billing, trials, and plan entitlements
  • To provide the Merchant with analytics about widget performance
  • To maintain and improve the reliability of the service

4. Third parties

We share data only as needed to provide the service: with Anthropic (to generate AI content), with the Merchant's chosen review platform (to fetch reviews), with Klaviyo (if connected), and with Shopify (for billing and store data). We do not sell Merchant or Shopper data.

5. Data retention

We retain Merchant configuration and generated content for as long as the app remains installed, plus a reasonable period afterward in case of reinstallation. Merchants can request deletion of their data at any time by contacting us.

6. Data security

API keys and credentials are stored as encrypted secrets. Access to production data is restricted to those who need it to operate the service. All database contents, metadata, and backups are encrypted at rest using AES-256, and all data in transit is protected using TLS/SSL.

7. Security incident response

If unauthorized access to merchant API keys, Shopify access tokens, or a suspected data breach is identified, we take the following steps:

  • Immediately rotate the affected credentials (Shopify app secret, review platform or Klaviyo API keys, or other affected credentials)
  • Revoke and reissue Shopify access tokens for any affected Merchant by triggering re-authentication
  • Review system logs for the affected time window to determine the scope of the incident
  • Notify affected Merchants by email within 72 hours of confirming a breach, describing what happened and what data may have been affected
  • If Shopper data was exposed, inform affected Merchants so they can notify their own customers as required under applicable law

To report a suspected security incident, contact [email protected].

8. Data loss prevention

  • API keys, access tokens, and secrets are stored as encrypted secrets, never in plaintext or in source code
  • Shopper personal data (checkout email, see Section 2) is never persisted to our database — it exists only in-memory for the single request that forwards it to the Merchant's Klaviyo account, then is discarded
  • All API tokens are scoped to the minimum access required for the app's functionality
  • Access to webhooks is verified via HMAC signature on every request, rejecting anything that isn't genuinely from Shopify
  • Every access to protected customer data is logged (shop, timestamp, and outcome — never the personal data itself), enabling review of when this data was accessed
  • Test and development activity is kept on our own development store; live merchant stores are not used for testing new features or sample data

9. Your rights

Merchants and Shoppers in the UK/EU have rights under GDPR (and equivalent rights elsewhere) to access, correct, or delete their personal data. To exercise these rights, contact us at [email protected].

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

11. Contact

Questions about this policy can be sent to [email protected].

© 2026 Revuella. Terms · [email protected]