Privacy policy
Last updated: October 2, 2026
Loyalvia runs a points and rewards program for Shopify stores. This page explains what the app stores about merchants and their customers, why, who else sees it, and how to have it erased.
In short: to run a store's loyalty program we keep each member's points, their name, email and language, the order totals that earned points, and an optional birthday. We use it only to run that store's program, we never sell it or use it for advertising, and it is erased when the store asks, when a customer asks through Shopify, or when the app is uninstalled.
Who we are
The app is built and run by Plug Software, the trading name of Taukir Reza, an individual developer based in India. In this policy, “we” means Plug Software, “you” means the merchant who installed the app, and “customers” means the shoppers of your store.
For your customers' data, you are the controller and we process it on your behalf, only to provide the app to you.
What the app does
Customers earn points for orders, signing up, referrals, birthdays and similar actions, and spend them on rewards — discount codes the app creates in your Shopify store. The program appears on your storefront through a theme app embed, and on your customers' account pages.
What we store about you, the merchant
- Your shop's address (for example your-store.myshopify.com) and the access token Shopify issues when you install the app, so the app can act on your behalf.
- Your program settings: ways to earn, rewards, VIP tiers, widget appearance, email settings and similar configuration.
- Account state, such as whether setup is finished and which plan your shop is on, as reported by Shopify's billing.
- Your name and email address as the store owner, from Shopify, to email you about your account — a welcome when you install, and a heads-up when you're near or at your plan's monthly order limit — and occasional product news, which you can unsubscribe from in any of those emails.
What we store about your customers
- Identity: their Shopify customer id, name, email address and preferred language, as Shopify provides them.
- Points: their balance, lifetime points, tier and a history of every change — for example “Order #1001” or “Redeemed: $5 off”.
- Order totals used to calculate points, and the order numbers they came from. We do not store addresses, payment details or what was bought.
- Rewards redeemed and the discount codes issued for them.
- Referrals: who referred whom, and each member's referral code.
- Birthday (month and day only), if the customer chooses to enter it.
- Emails sent to them about their points, kept for 90 days so you can see what was sent.
- Imported files: if you import members from another loyalty app, the uploaded rows are kept for 30 days and then deleted.
The Shopify permissions we ask for
- Customers (read) — to know who a member is and address them by name and email.
- Orders (read) — to award points when an order is paid and take them back after a refund or cancellation.
- Products (read) — to let you pick the product a free product reward gives away, and read its current price when a customer redeems it. The app never changes your products.
- Discounts (read and write) — to create the discount codes customers redeem their points for.
We ask for nothing else. If a future feature needs another permission, Shopify will ask you to approve it before it takes effect.
On your storefront
The widget stores two small things in the shopper's own browser: a referral code from a referral link, until they create an account, and the widget's colours and label, so the button appears instantly on the next page. Neither is sent anywhere else. We use no tracking or advertising cookies.
How we use the data
Only to run your loyalty program: to calculate and show points, issue rewards, place members in tiers, credit referrals and, if you turn emails on, send customers messages about their points. We do not use it for advertising, profiling or anything unrelated to your program, and we never combine one store's data with another's.
Who else sees it
We do not sell, rent or share your data or your customers' data. The only third parties involved act on our instructions: Shopify itself; the hosting and database providers that run our servers; and the email delivery services we use (Resend, or Google's mail service) to deliver loyalty emails when you turn them on, and our emails to you.
How long we keep it, and how to have it erased
- While the app is installed, we keep your program and your members' points so they are there when customers return.
- When you uninstall, the access token is deleted straight away. Shopify then asks us to erase the shop 48 hours later, and at that point everything we hold for your store — settings, members, points, emails and imports — is deleted for good.
- When a customer asks you to erase their data, Shopify tells us and we delete their member record, points history, rewards, referrals and any imported rows about them.
- You can ask us to erase everything sooner, at any time, by emailing help.zainabfatima@gmail.com.
Security
All traffic runs over HTTPS. Every request from Shopify — webhooks, the storefront widget and customer account pages — is signed by Shopify and verified before it is acted on, so one customer can never see another's points. Access tokens are stored server-side only.
Your rights and your customers' rights
Depending on where you or your customers are, you may have the right to see, correct, export or erase personal data, or to object to how it is used. Customers should contact your store, and you can forward their request to us; we will act on it within 30 days at the latest.
Changes to this policy
If we change how the app handles data, we will update this page and the date at the top. Meaningful changes are also announced in the app.
Contact
Questions, requests or concerns: help.zainabfatima@gmail.com.