App privacy policy
Reversa is a Shopify app that records a store's catalog changes, alerts you to anomalous changes and lets you undo them. This policy explains what data the app processes when a merchant or their agency installs it, for what purpose, who it is shared with and for how long.
1. Who is responsible
Reversa is a service of Santiago Gili Silvestre, a self-employed individual (autónomo) with Spanish tax ID (NIF) 34764541H and address at C/ Dels Montcada, 45, Local, 08203 Sabadell (Barcelona), Spain. In this policy, "Reversa" and "we" mean him. Contact for any privacy question: hello@enric.app. A data protection officer is not required for this activity, and none has been appointed.
2. What role we play
Your store's data (catalog, history and copies, alerts): you, the merchant, are the controller and Reversa is the processor (in California, a "service provider"; in Brazil, an "operator"). We process it on your behalf and only to provide the service, under the data processing addendum you accept together with the Terms of Service.
Data to manage our relationship with you (account, billing, support, service security and legal compliance): Reversa is the controller.
Shopify is an independent third party: it has its own relationship with you and its own privacy policy. It handles billing for the app.
3. What data we process
When you install the app, Shopify gives us access to the data covered by the permissions (scopes) you authorize: read_products, write_products, read_inventory, read_publications and write_publications.
| Category | Data | Source |
|---|---|---|
| Catalog | Products, variants, prices, images, product metafields, collections, status and sales channels, inventory levels (recorded only), and every change with its previous value, new value and time | Shopify API and webhooks |
| Image copies | A copy of the file of every product image Reversa sees while it is installed, so it can reattach it if it is deleted in Shopify | Downloaded from Shopify |
| Store | Store domain and name, currency, time zone, Reversa plan, install and uninstall dates | Shopify |
| People who use the app | First name, last name, email, language and whether they are the store owner or a staff member, as provided by Shopify when the app is opened; actions taken in Reversa (for example, who confirmed a rollback or answered "It was me") | Shopify and your use of the app |
| Alerts | The destination emails you configure and, if you connect Slack, your incoming webhook URL; if you connect it with "Add to Slack", also the name of the workspace and channel and a token we use only to revoke the permission when you disconnect it. The URL and the connection are stored encrypted | You and Slack |
| Agency dashboard members | Email, access level in the agency (View only, Can also undo or Administrator), language, whether they want the periodic summary and when they last signed in; actions taken in the dashboard (audit log) | The agency and use of the dashboard |
| Incident reports | A snapshot of an event taken when the report is generated: catalog figures and fields, names and SKUs of a sample of products, times, the undo outcome and who started it (internal version only); if shared, the link, whose key we store only as a hash, its expiry, whether it was revoked and how many times it was opened (no IP) | Generated by the store or its agency |
| Periodic summaries | The frequency chosen by the store and by each agency member, one record per email sent (type, period and result) and the opt-outs of alert addresses, stored as a hash rather than as the address | Your settings and use |
| Support | What you write to hello@enric.app and our replies (in the Zoho mailbox and its Gmail copy, section 6) | You |
| Billing | Plan, charges, credits and refunds for the app. We do not receive card or bank details | Shopify |
| Technical | IP address, date and time of requests, and errors in server logs | Automatic |
Catalog data is not usually personal data, but it can contain it (for example, a person's name in a description or a face in an image).
We do not access your customers' data, or your store's orders or payments: Reversa does not request those permissions from Shopify. Shopify sends us mandatory privacy notices about customers (customers/data_request and customers/redact); we log them without storing their content, because we have no customer data to hand over or delete.
4. What we use it for and the legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Storing the history and copies, grouping changes by event, detecting anomalous ones, sending you alerts and reports, undoing the changes you confirm, checking the result and exporting | As a processor, on the merchant's behalf (art. 28). For the data of the people who use the app: performance of a contract (art. 6.1.b) |
| Sending the periodic activity summary (by default monthly for the store and weekly for the agency) to the alert addresses and to the agency members who receive it | A communication about the service you use, not advertising: performance of a contract (art. 6.1.b) and legitimate interest in telling users what the service has done (art. 6.1.f). Anyone can stop receiving it in one click |
| Running the agency dashboard (single-use sign-in links, access levels and audit log) | Performance of the contract with the agency (art. 6.1.b) and legitimate interest in the security of the connected stores (art. 6.1.f) |
| Managing your account, plan, refunds and support | Performance of a contract (art. 6.1.b) |
| Keeping the service secure, preventing abuse and fixing errors | Legitimate interest in protecting the service and its users (art. 6.1.f) |
| Keeping billing records and responding to requests from authorities | Legal obligation (art. 6.1.c) |
| Informing you of important changes to the service or these terms | Performance of a contract (art. 6.1.b) |
Shared incident reports. The store or its agency can generate a report on an event and, if it wants, share it through a read-only link. The link shows a snapshot of the report taken when it was generated: catalog data and figures, and the agency's name and logo, but no email address or person's name (only the agency's name or "a store user"). Anyone with the link can view it, so we ask search engines not to index it and it expires after 7, 30 or 90 days (30 by default, and sooner if your plan's history period deletes it). The agency can revoke its own links and the store can revoke all of them from Settings › Your agency; links also stop working when the app is uninstalled or the agency's access is removed. Whoever shares a link decides who receives it.
Periodic summaries by email. So you can see what Reversa has done, we send an activity summary (the period's figures, urgent alerts with their outcome and what is pending, with no customer data): to the store's alert addresses, monthly by default, and to each agency dashboard member who has it on, weekly by default (view-only members do not receive it unless they turn it on). It can be changed or turned off in Reversa → Protection (store) or in the dashboard → Settings (each member for themselves), and every email has a link to stop receiving it in one click. It is not advertising: we do not send marketing emails to these addresses.
History export. The store or its agency can download the change history as a CSV file at any time. The file is generated on request and downloaded directly; we do not keep a copy, only a record of each export (range, number of rows and date), kept for 30 days to apply the limit of 10 per day.
We do not sell or share data for advertising purposes, we do not build commercial profiles, and we do not use your store's data to train artificial intelligence models. Anomalous-change detection applies to catalog changes, not to people, and produces no decision with legal effects on anyone (art. 22 GDPR).
5. How long we keep it
| Data | Retention |
|---|---|
| Change history and image copies no longer in the store | Your plan's period: Starter 90 days, Growth 180 days, Pro 365 days. Deleted automatically afterwards. |
| Current copy of the catalog and of images still in the store | While the app is installed |
| All store data on uninstall | Shopify notifies us about 48 hours after the uninstall (shop/redact). We delete the data on receiving the notice and, in any case, within 30 days at most. Technical backups are overwritten within a further 10 days at most |
| Incident reports (the snapshot) | Your plan's period, like the history |
| Shared report links | Until they expire or are revoked; the link record is deleted 30 days later |
| Agency dashboard members and their audit log | While the person is a member; the audit log, up to 1 year |
| Records of summary emails sent | Up to 400 days |
| Record of the deletion | We keep only the *.myshopify.com domain, the uninstall date and the record of the deletion notice, so we can show that we comply |
| Free trial already used | After the deletion we keep a SHA-256 hash of the store domain, which cannot be turned back into the domain, and the date its free trial ended. It is used only so the same store cannot repeat the free trial by reinstalling. Legal basis: legitimate interest (art. 6.1.f GDPR) in preventing misuse of the trial. Kept for up to 3 years from the end of the trial, a reasonable period to prevent repeated abuse of the free trial. |
| Support | Up to 3 years from the last contact, a prudent period to handle any claim related to the support we provided. |
| Billing records | Up to 6 years from the last entry, as required by Spanish commercial law (art. 30 of the Commercial Code), which is longer than the 4-year period set by tax law (art. 66 of the General Tax Law). |
| Server technical logs | Up to 30 days. |
| Slack connection (webhook URL, workspace, channel and token) | While it is connected. When you click "Disconnect" or uninstall Reversa, we revoke the permission in Slack and delete it; in any case, it is deleted with the rest of the store data (shop/redact) |
6. Who we share it with
Only with the providers we need to provide the service, under a processor or sub-processor contract:
| Provider | What for | Where |
|---|---|---|
| Fly.io, Inc. | App servers and database | an EU region; US company |
| Fly.io, Inc. | Image copies, on a Fly.io volume in the same region (dedicated object storage such as Cloudflare R2 is planned but not in use yet) | an EU region; US company |
| Resend, Inc. | Sending alerts, periodic summaries and dashboard sign-in links by email | US (account data, metadata and logs are stored on Resend's US servers regardless of the sending region) |
| Zoho Corporation B.V. (Zoho Mail, Utrecht, Netherlands; EU data center) | Support mailbox hello@enric.app: receives the emails you write to us. It does not receive app data. | Netherlands (EU) |
Copy of the support mailbox in Gmail. The hello@enric.app mailbox automatically forwards a copy of every email it receives to the owner's personal Gmail account, for the same purpose: handling support. Zoho also keeps the original. For users in the European Economic Area and Switzerland, Gmail is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Because it is a personal account, not Google Workspace, there is no data processing agreement with Google: Gmail is governed by Google's own terms and privacy policy, which name Google Ireland Limited as the controller for its EEA users' information. The forwarding affects only support emails, never the data the app processes. That is why we ask you not to include your customers' or suppliers' personal data in your emails: we do not need it to give you support. You can ask us at any time to delete the Gmail copy of your emails.
In addition:
Shopify receives the information its platform needs to charge for the app and for the rollbacks you confirm (Reversa writes to your store through its API).
Slack, if you connect it (by pasting an incoming webhook URL or with "Add to Slack"): we send to the channel you choose the urgent alerts, the result of undoing those alerts and, only if you turn it on, the summaries. They include the store name, figures about the change, names and prices of sample products, the rule that triggered, links to Reversa and, when Shopify provides it, the name of the team member linked to the change; never your customers' data. With "Add to Slack" we only ask for permission to post in that channel: we do not read your messages or channels. Slack is a service you choose and contract yourself (it is not a Reversa processor), and what we send is subject to your terms with Slack.
Alert recipients: we send alerts, periodic summaries and reports to the emails you configure (for example, an agency's client) and to agency dashboard members.
Whoever receives a report link: the person the store or its agency decides to share it with.
Authorities, when a law requires it.
If the business were transferred to another person or company, the data would pass to the new owner, who would be bound by this policy; we would notify you beforehand.
7. International transfers
We keep store data in the European Union. Some providers are US companies or send data from there (email). Fly.io, Inc. (servers, database and image copies) is certified under the EU-US Data Privacy Framework, and its processing agreement also includes the European Commission's standard contractual clauses as an additional safeguard. Resend, Inc. (sending emails) is certified under the EU-US Data Privacy Framework and its UK Extension, and its processing agreement likewise includes the standard contractual clauses; the metadata and logs of what it sends are stored on its US servers. Zoho keeps the support mailbox in its EU data center (Netherlands); if there were ever any access from outside the EU, it would rely on the standard contractual clauses of Zoho's processing agreement.
Google (the copy of the support mailbox in Gmail, section 6) has servers worldwide and may process those emails outside the EEA. Its privacy policy states that, for such transfers, it relies on the European Commission's adequacy decisions, the EU-US Data Privacy Framework and standard contractual clauses. Google LLC is certified under that framework, its UK Extension and the Swiss-US framework. These are safeguards Google applies to all its users: we have not signed any processing or transfer agreement with Google.
You can ask us for a copy of Fly.io's, Resend's and Zoho's safeguards at hello@enric.app. Google's are on its page on legal frameworks for data transfers (policies.google.com/privacy/frameworks).
If your store is outside the European Economic Area, your data comes back to you through Shopify and through exports, with the safeguards of the data processing addendum.
8. Security
Encryption in transit and at rest, encrypted access tokens and secrets, minimum permissions in Shopify, signature verification for every Shopify notice, per-store data separation and two-factor-restricted access to production. No system is completely secure: if a security breach affected your data, we would notify you without undue delay. Details in Annex II of the data processing addendum.
9. Your rights
Everyone. You can request access, rectification, erasure, objection, restriction of processing and portability of your data, and withdraw any consent you gave, by writing to hello@enric.app. We will respond within one month at most (extendable in the cases the law allows). If the data belongs to a merchant's store (for example, you are a store employee), we will forward the request to the merchant, who is the controller, and help them handle it. A merchant or agency can also export the store's full change history as a CSV file at any time, from the app or the agency panel, without needing to ask us.
Complaints. You can complain to the Spanish Data Protection Agency (aepd.es) or to the data protection authority of your country of residence or work (in the UK, the ICO).
California (CCPA/CPRA). Regarding store data, Reversa is the merchant's "service provider": requests must be directed to the merchant, and we will help them handle it. Regarding the data we process as a controller, you can ask what personal information we hold, access it, correct it and delete it, without suffering discriminatory treatment for it. We do not sell or share personal information ("sell" / "share") and we do not use sensitive personal information. You may act through an authorized agent; we will verify the request reasonably.
Brazil (LGPD). You can exercise the rights the LGPD grants you, including confirmation of processing, access, correction, anonymization or deletion, portability and information about who we share the data with, by writing to hello@enric.app.
Canada (PIPEDA) and Australia. You can request access to your information and its correction, and file a complaint with us and, if not satisfied, with the Office of the Privacy Commissioner of Canada or the Office of the Australian Information Commissioner.
10. Minors
Reversa is a service for businesses and is not aimed at minors.
11. Changes to this policy
We will notify you in the app and by email of any important change at least 30 days in advance, unless the change is required by a law or an authority with a shorter period. Previous versions will be available on request.