FlowPerks FlowPerks Privacy Policy

Privacy for merchant and customer data.

FlowPerks helps Shopify merchants run memberships, store credit, referrals, and bonus events. This policy explains what data we access, how we use it, and what happens when a merchant uninstalls the app.

Last updatedApril 13, 2026
Primary hostingUnited States

The information needed to run the app.

We only collect data that supports FlowPerks features, security, billing, and support.

Shopify store data

  • Store name, domain, and merchant contact context.
  • Customer records needed for memberships, store credit, rewards, and referrals.
  • Order and product data required for tier logic, bonus events, and reporting.
  • Shopify-provided customer, checkout, order-status, and customer-account context used to render customer-facing rewards surfaces.

Merchant-provided configuration

  • Tier settings, perk rules, bonus-event configuration, and email preferences.
  • Branding assets and support contact information configured inside FlowPerks.
  • Storefront and customer-surface settings.
  • Information submitted through FlowPerks-operated interactions, such as referral or rewards actions, when a merchant enables those workflows.

Operational data

  • App usage logs, audit trails, and job metadata.
  • Error and performance telemetry used to troubleshoot and improve reliability.
  • Billing state and subscription lifecycle events provided by Shopify.

1. What this policy covers

This Privacy Policy applies to FlowPerks, a Shopify app operated by Cardflow Labs. It covers information we receive from Shopify, information merchants configure inside the app, limited information submitted through enabled FlowPerks interactions, and operational data we collect to run, secure, and improve the service.

2. Who we serve

FlowPerks is provided to Shopify merchants. Most customer-facing FlowPerks surfaces rely on Shopify-provided customer, order, and shop context instead of separate standalone accounts. Merchants remain responsible for their relationship with their customers and for making sure they use the app in compliance with applicable privacy laws and Shopify policies.

3. How we use information

  • Provide and maintain FlowPerks features.
  • Calculate and issue rewards, memberships, and store credit.
  • Render customer-facing rewards surfaces.
  • Send service, billing, and support communications.
  • Monitor reliability, investigate incidents, and prevent abuse.
  • Comply with legal obligations.

4. When we share information

We do not sell merchant or customer personal information. We share data only with service providers that help us operate FlowPerks, such as hosting and database providers, error monitoring, email delivery, and backup services, and when required by law or in connection with a business transfer. Our current operational vendors include Railway and PostgreSQL infrastructure for hosting and storage, Sentry for error monitoring, and Resend for transactional email delivery.

5. Security and retention

  • Data is transmitted over HTTPS/TLS.
  • Access to production systems is restricted.
  • Primary application and database hosting is in the United States.
  • Operational backups are encrypted and retained according to our recovery policy.
  • After uninstall, merchant data is retained for 30 days to support reinstall and recovery, then permanently deleted unless a shorter legal or operational retention period applies.

6. Rights and requests

Depending on applicable law, merchants or data subjects may have rights to access, correct, delete, or export certain information. FlowPerks also supports Shopify privacy workflows where applicable. To submit a privacy request, email support@cardflowlabs.com with your store domain and request details.

7. International and regional rights

For merchants or customers subject to GDPR, CCPA, or similar laws, we respond to valid data requests in line with applicable legal requirements. FlowPerks is operated from the United States, and data may also be processed in other jurisdictions where Shopify or our service providers operate. Merchants remain responsible for their own customer notices and lawful basis for using customer data inside their loyalty program.

8. Contact and updates

Last updated: April 13, 2026. If we make material changes to this policy, we will update the date on this page and, where appropriate, notify merchants through the app or by email.