Legal and privacy

Privacy Policy

This Privacy Policy explains how ShopiDeck: Klaviyo Bot Cleaner processes personal data through the public website at https://shopideck.com and the embedded Shopify app at https://klaviyobotcleaner.shopideck.com. It describes the current product, its limits, the parties' privacy roles, and the choices available to individuals and merchants.

Effective: September 1, 2026Last updated: September 1, 2026

1. Scope and effective date

This policy applies to the ShopiDeck public website, the embedded Shopify app, merchant and administrator accounts, support and privacy requests, and the operation and security of the service. It is effective on September 1, 2026 and was last updated on September 1, 2026.

The English text is a translation. The Spanish version is the prevailing version. Where legally permitted and there is a contradiction, the Spanish version prevails without removing mandatory rights applicable to the merchant or any individual.

2. Controller identity and contact

ShopiDeck is a trade name operated by Andres Camilo Bonilla Carreño, a Colombian individual merchant based at Cra. 79A # 6-04, Bogotá D.C., Colombia.

Privacy, legal, support, and security incident contact: team@shopideck.com. The internal privacy contact is Andres Camilo Bonilla Carreño at team@shopideck.com; this contact is not described as a formal DPO.

3. Definitions

In this policy, merchant means the Shopify merchant or business that installs or uses the app; administrator means an authorized Shopify user; profile means a Klaviyo contact record made available through the authorized account; suppression means the Klaviyo action that prevents marketing sends and is not permanent profile deletion; and ShopiDeck, we, or us means the operator identified above.

4. Privacy roles

ShopiDeck acts as controller for merchant and administrator data, account administration, billing, product use, support, security, abuse prevention, contractual administration, and legal compliance.

ShopiDeck acts as processor for Klaviyo profiles processed on the merchant's documented instructions, including scoring, results, confirmed suppressions, and privacy requests submitted through Shopify. The merchant generally acts as controller for its customers' data and determines the applicable legal basis for that processing.

  • The merchant must have a legal basis to store customer profiles in Klaviyo and give lawful instructions to ShopiDeck.
  • The merchant must provide its own privacy notices and handle customer rights requests when it acts as controller.
  • The merchant must review profiles and confirm a suppression before ShopiDeck sends that action to Klaviyo.
  • The merchant must have authority to connect the Shopify and Klaviyo accounts and must not use the app for incompatible purposes.

5. People affected

  • Shopify merchants, owners, administrators, and other authorized users.
  • Customers and contacts represented by profiles in the merchant's authorized Klaviyo account.
  • People who submit support, privacy, or security incident requests.
  • People whose data appears in technical, security, or operational records created while the service runs.

6. Sources of data

  • Shopify, including installation, authentication, store and administrator identity, App Store, billing, webhooks, and privacy requests.
  • Klaviyo, through the OAuth connection authorized by the merchant and data available in that account.
  • The merchant or administrator directly, including support and privacy request forms.
  • The service's operation, security controls, and limited technical or error records.

7. Categories of data processed

  • Shopify and merchant data: myshopify.com domain, Shopify Shop ID, Shopify access token, session information, administrator user ID, administrator first and last name and email when Shopify provides them, locale, account-owner status, scopes, plan, billing cycle, usage limits, monthly consumption, support requests, and limited technical and operational records.
  • Klaviyo account data: Klaviyo Account ID, OAuth scopes, and encrypted access and refresh tokens.
  • Klaviyo profile data: Profile ID, email, first name, last name, phone when present, city when present, country when present, IP when available, creation date, update date, marketing subscription status, and email domain.
  • Derived data: normalized patterns used for detection, risk score, risk level, explainable detection reasons, suppression result, audit history, and suppression history.
  • Support, privacy, security, and operational data needed to receive requests, verify them proportionately, protect the service, and respond.

8. Data not requested

The app is not designed to intentionally request or process health data, biometric data, religion, sexual orientation, political opinions, financial information, card numbers, passwords, or equivalent special categories. Merchants must not submit sensitive data through fields that the app may process unless they have an appropriate legal basis and the use is lawful.

ShopiDeck does not store payment card information, sell personal data, share data for behavioral advertising, use profiles for its own advertising, create advertising audiences, or use data to train artificial-intelligence models.

9. Purposes and legal bases

The following table describes the purpose framework for the current processing. In Colombia, authorization is obtained when required, subject to the legal exceptions that apply. For Klaviyo profiles, the merchant determines its own legal basis and gives documented instructions. A legal basis listed for one purpose may not apply in every jurisdiction or circumstance.

PurposeLegal basis or instruction
Providing the appPerformance of the contract.
AuthenticationPerformance of the contract and security.
Account administrationPerformance of the contract.
BillingPerformance of the contract and applicable legal, accounting, or tax obligations.
SupportPerformance of the contract and management of requests.
Security and abuse preventionLegitimate interest and applicable legal obligations.
Privacy requestsLegal obligation.
Klaviyo profiles and scoringThe merchant's documented instructions as controller; the merchant determines its legal basis.
Future non-essential cookiesConsent where legally required.

10. Shopify

Shopify provides installation, authentication, store and administrator identity, App Store and billing functions, webhooks, and privacy request mechanisms. Shopify is an independent platform and its own terms and privacy information also apply. Shopify may send privacy webhooks to ShopiDeck for the relevant store and customer records.

11. Klaviyo connection and permissions

The app connects to Klaviyo through OAuth, reads existing profiles and subscription information, applies rule-based scoring, and sends a suppression only after the merchant selects profiles and confirms the action. Current permissions are accounts:read, profiles:read, profiles:write, subscriptions:read, and subscriptions:write. The app does not request permission for permanent profile deletion.

Klaviyo OAuth access and refresh tokens are encrypted before storage. The merchant can disconnect Klaviyo from Settings. Disconnecting revokes and removes the OAuth tokens and connection while retained audit and suppression history remains for its retention period.

12. Scoring and automated evaluation

The app performs an automated assessment based on explainable rules. Possible signals include disposable email domains, unusual or apparently generated email formats, generic or incomplete names, missing data, repeated values, bursts of profile creation, shared email patterns, shared name patterns, shared IP patterns, shared phone patterns, and available subscription status.

The score is an estimate and does not prove fraud or that a profile is a bot. False positives and false negatives are possible. The result may classify a profile as low risk, needs review, or probable bot and shows understandable reasons for the classification.

13. Human review and significant decisions

The score does not create an automatic suppression. The merchant keeps the final decision, reviews the profile and its reasons, selects profiles, and confirms any suppression. ShopiDeck does not make legal or similarly significant decisions about an individual solely from the scoring. Results are not used for advertising, credit, employment, insurance, or eligibility decisions.

The app does not use opens, clicks, purchases, or browsing activity to declare a profile inactive.

14. Providers and subprocessors

ShopiDeck uses the following providers for the current service. They may process data as needed to provide their services and under their applicable contracts. Prisma is an ORM library and is not an independent subprocessor.

  • Shopify: installation, authentication, store and administrator identity, App Store, billing, webhooks, and privacy requests.
  • Klaviyo: OAuth, account and profile queries, subscription information, and merchant-confirmed suppression.
  • Supabase: PostgreSQL database and application storage; region US East, United States.
  • Vercel: hosting and serverless functions; processing in the United States.
  • Resend: email communications and support when applicable.

15. International transfers

The controller is established in Colombia. Data may be processed in the United States and other countries where Shopify, Klaviyo, Supabase, Vercel, and Resend operate. ShopiDeck does not represent that all data stays in Colombia.

ShopiDeck uses the contracts and safeguards made available by the relevant providers when applicable. A merchant or individual may request additional information about applicable safeguards by contacting team@shopideck.com. The provider's terms, privacy notice, DPA, and any applicable transfer mechanism may also apply.

16. Retention

ShopiDeck retains data for the periods below, subject to earlier deletion where required by law or the implemented deletion flows. Retention applies to local ShopiDeck records; Shopify and Klaviyo may retain data independently under their own policies and instructions.

Data or recordRetention
Klaviyo OAuth state10 minutes.
Klaviyo tokensUntil disconnect, uninstall, account deletion, or revocation.
Temporary scan dataDuring processing.
Temporary data for completed jobsApproximately 24 hours.
Failed or cancelled scans30 days.
Scan history365 days.
Results365 days.
Suppression history365 days.
Privacy requests and exports30 days.
Shopify sessionsWhile the app is installed or until removed.
Redaction HMAC hashesWhile the store record exists.
Legally necessary recordsFor the period required by applicable law.

17. Redaction HMAC hashes

Redaction HMAC hashes are pseudonymized values, not completely anonymous data. They are used to prevent an identifier that was previously redacted from being stored again. They are deleted when the store record is permanently deleted.

18. Cookies

The embedded app uses the functional or necessary cookie shopideck_locale to remember the language selected inside the embedded app. It lasts one year and has Secure, HttpOnly, and SameSite=None attributes. It is not used for advertising or analytics.

ShopiDeck does use cookies. Any future non-essential cookie will be used only with the consent or other legal basis required by applicable law and this policy will be updated where necessary.

19. Analytics and advertising

The current service does not use Google Analytics, Meta Pixel, Sentry, Vercel Analytics, advertising analytics, behavioral advertising, advertising audiences, or profile data for ShopiDeck advertising. ShopiDeck does not use personal data to train artificial-intelligence models.

20. Security measures

These measures reduce risk but do not guarantee absolute security.

  • Klaviyo tokens are encrypted.
  • Connections use HTTPS.
  • Secrets are kept on the server.
  • Shopify authentication and protected routes are used.
  • Webhooks are verified and backend input is validated.
  • Critical actions include ownership verification and confirmation before suppression.
  • Usage limits are enforced in the backend.
  • Privacy requests and exports are encrypted.

21. Security incidents

ShopiDeck investigates suspected security incidents and notifies affected parties or authorities when the law requires it. Merchants must report compromised credentials or suspected unauthorized access to team@shopideck.com. Do not send passwords, API keys, OAuth tokens, or other secrets by email.

22. Rights

Subject to applicable law and the relevant privacy role, individuals may have the right to know about processing, access data, update or correct it, request proof of authorization where applicable, be informed about its use, submit inquiries and complaints, request deletion or suppression, revoke authorization where legally available, and request review of automated processing.

The merchant generally handles rights concerning its customer data as controller. ShopiDeck assists the merchant as processor through documented instructions and responds directly where ShopiDeck is the controller.

23. Privacy requests

Send a request to team@shopideck.com. Include:

Do not send passwords, API keys, tokens, or full customer lists.

  • Your name.
  • Your relationship with the store.
  • The myshopify.com domain.
  • The right you want to exercise.
  • A description of the request.
  • Proportionate information needed to verify identity and authority.

24. Inquiries and complaints

Please contact team@shopideck.com first so ShopiDeck can review the request. The request should identify the store, the relevant data or processing, and the outcome sought. ShopiDeck will handle it under the applicable law and role of the parties.

25. Colombia

For processing subject to Colombian law, ShopiDeck requests authorization when required and relies on applicable legal exceptions when an exception applies. Individuals may exercise the rights described above by contacting the privacy address. Requests and complaints may be submitted through the applicable procedure before approaching the Colombian authority.

26. European Economic Area

ShopiDeck is not established in the European Union or the United Kingdom and does not currently have a formal representative in either jurisdiction. Andres Camilo Bonilla Carreño is the internal privacy contact and is not a formal DPO. Where EEA law applies, individuals may have rights under that law, including access, correction, deletion, restriction, portability, objection, and review of automated processing, subject to the applicable conditions and limits. This policy does not claim universal compliance or appoint a representative that does not exist.

27. United Kingdom

ShopiDeck is not established in the United Kingdom and does not currently have a formal UK representative. Andres Camilo Bonilla Carreño is the internal privacy contact and is not a formal DPO. Where UK law applies, individuals may exercise the rights available under that law, subject to its conditions and limits. This policy does not claim universal compliance or appoint a representative that does not exist.

28. Children

The app is directed exclusively to Shopify merchants and authorized business users; it is not directed to children. Merchants must not provide children's data or sensitive data in a way that is incompatible with applicable law.

29. Disconnecting Klaviyo

When Klaviyo is disconnected, ShopiDeck revokes and deletes the OAuth tokens and removes the Klaviyo connection. Audit and suppression history remains during its retention period unless an applicable deletion request or account-deletion flow removes it.

30. Uninstalling Shopify

When the app is uninstalled, sessions are removed, Klaviyo credentials are revoked or deleted, and the store is marked inactive. Shopify sends shop/redact approximately 48 hours later. shop/redact deletes the local store record and related data. Shopify or Klaviyo may retain data independently under their own policies.

31. Delete account

Only the store owner can use Delete account. The app is uninstalled, sessions and tokens are removed, the local store record is deleted, and local relationships are removed through cascading deletion. ShopiDeck does not claim to delete data that Shopify or Klaviyo retain independently.

32. Privacy webhooks

  • customers/data_request: locates data using email or phone, creates an encrypted export, allows the store owner to download the completed request, and keeps the request for 30 days.
  • customers/redact: deletes related results and temporary related data, while retaining an HMAC hash to prevent reintroduction of the identifier.
  • shop/redact: deletes the local store data.
  • app/uninstalled: supports uninstall cleanup.
  • app/scopes_update: records and supports scope changes.

33. Changes to this policy

ShopiDeck may update this policy when the service, data flows, providers, legal requirements, or retention practices change. The effective-date and last-updated labels identify the current version. Material changes will be communicated through an appropriate channel when required.

34. Contact

For privacy, legal, support, or security questions, contact team@shopideck.com. Legal-notice address: Cra. 79A # 6-04, Bogotá D.C., Colombia.

35. Supervisory authority

The Colombian personal-data authority is the Superintendencia de Industria y Comercio — Delegatura para la Protección de Datos Personales. Where applicable, a person may submit a complaint through the authority's official channels after the relevant direct request process.