Appities Privacy Policy
Last updated: 2026-09-27
Appities ("we") is operated by STools Digital. Appities lets Shopify merchants build and publish native mobile apps for their stores. This policy explains what we process, why, and for how long. Contact: destek@stools.digital.
Roles
For merchant account data we are the controller. For data about a merchant's customers (shoppers who use the merchant's mobile app) the merchant is the controller and we act as a processor on the merchant's instructions under our Terms (Data Processing section).
Data we process
Merchant data: shop domain, shop name, contact email, store settings, app designs, app store credentials you provide (stored encrypted), billing status (handled by Shopify).
Shopper data (minimal, no names, emails, phone numbers or addresses): a random installation ID generated by the app; the push notification token if the shopper allows notifications (encrypted at rest); device platform, language and app version; aggregated daily usage counts (for example app opens, product views, add-to-cart); for orders placed through the mobile app, the order total and date with a one-way keyed hash of the order ID so the same order isn't counted twice.
If the merchant turns on location-based notifications and the shopper separately allows it, an approximate city/region (derived on the device from GPS and never the raw coordinates, which are discarded immediately) so the merchant can target notifications by area. This is never requested unless the merchant enables the feature, and it is asked for after an in-app explanation screen, not on first launch.
If the merchant connects Attentive (SMS marketing) and the shopper submits the in-app SMS sign-up form after checking the consent box, the phone number the shopper typed is sent directly to the merchant's Attentive account. We do NOT store this phone number on our servers; it passes through our server only to add Attentive's authentication and is discarded immediately after the request.
If the merchant connects an install-attribution SDK (AppsFlyer or Adjust), that SDK's own advertising identifier and install-attribution data is processed by that provider under its own privacy policy; on iOS this requires the shopper's separate App Tracking Transparency permission.
On the Plus plan, if the merchant turns on "Use customer email" and we have Shopify's approval for protected customer data (Level 2 — email): when a shopper is signed in and requests their loyalty points balance or redeems a reward, or triggers an in-app event, their email address is read from Shopify's Customer Account API and forwarded, in that moment only, to the merchant's connected loyalty provider (Smile.io or LoyaltyLion) or to Klaviyo. The email is never written to our database and never logged; it exists only for the duration of that single request. Without this setting turned on, email is never read, exactly as described above.
Checkout, payments, customer accounts and order details are handled by Shopify; we do not receive payment data.
Why we process it
To provide the service: render the merchant's app, deliver push notifications the merchant sends, build and submit the app to Apple and Google, and show the merchant aggregated performance metrics. We do not sell personal data, use it for advertising, build profiles, or make automated decisions with legal or similarly significant effects.
Retention
Device records and push tokens: deleted 13 months after the device was last seen. Mobile order totals: 25 months. Notification campaigns: 25 months. Aggregated daily counts contain no personal data.
When a merchant uninstalls Appities, shopper data is deleted when Shopify sends the shop/redact request (48 hours after uninstall). Customer redaction and data requests from Shopify are honored within 30 days.
Security
All traffic uses TLS. Push tokens and app store credentials are encrypted at rest with AES-256-GCM; order IDs are stored only as keyed hashes. Access to production systems is limited to authorized staff.
Subprocessors
Shopify (platform, billing, checkout), Expo (push delivery and app builds), Apple and Google (app distribution and push delivery), and our hosting provider. If the merchant connects them: Attentive (SMS marketing), AppsFlyer or Adjust (install attribution), Google Analytics, Meta and Klaviyo (see the merchant's Integrations page for the full optional list). We notify merchants before adding a new subprocessor.
Your rights
Shoppers should contact the merchant whose app they use; we assist merchants with access, correction and deletion requests. Merchants can contact us at destek@stools.digital. Shoppers can turn off notifications at any time in their device settings.