Effective date: August 3, 2026
This Privacy Policy explains how Peter Nuako, operating as Amamrefie ("we," "us," or "our"), processes information when Shopify merchants install or use Amamrefie Premium Customer Account (the "App").
1. Roles and Scope
The Shopify merchant determines why customer information is used and generally acts as the data controller. We process customer information on the merchant's behalf to provide the App and generally act as a data processor. We act as an independent controller for merchant account administration, security, legal compliance, and support.
2. Personal Data We Process
We process only the data needed for the merchant-enabled account experience:
- Customer identity: first and last name, email address, and telephone number.
- Customer addresses: saved, billing, and shipping addresses.
- Order information: order identifiers, dates, purchased items, totals, payment and fulfillment status, delivery details, refunds, returns, and order-status links.
- Customer choices: account preferences, profile changes, consent or opt-out choices provided through Shopify, and support requests.
- Merchant information: store domain, installation status, configuration, support email, accepted terms, and Shopify authentication sessions.
- Security information: request timestamps, limited diagnostic information, and infrastructure logs used to protect and operate the App.
The App does not collect payment-card numbers or customer passwords. Shopify handles customer authentication. The customer portal retrieves account information directly from Shopify when the authenticated customer opens the App. We do not build advertising profiles or sell personal data.
3. Purposes
We process information only to:
- Display and manage the authenticated customer's account, profile, addresses, orders, returns, and preferences.
- Provide merchant-configured membership benefits and customer support.
- Authenticate merchants, maintain secure sessions, prevent abuse, diagnose failures, and operate the App.
- Respond to verified access, correction, deletion, consent, and opt-out requests.
- Comply with applicable law and enforce our agreements.
We do not use customer data for unrelated advertising, data brokerage, or automated decisions that create legal or similarly significant effects.
4. Consent and Customer Choices
The App honors choices communicated through Shopify and does not use customer data beyond the functional purposes above. Where a feature relies on consent, the feature must remain disabled or stop processing when consent is withdrawn. We do not sell personal data, so all customers are treated as opted out of data sales. Customers may update profile information in the App or through Shopify and may direct privacy requests to the merchant.
5. Service Providers
We use Shopify for authentication, customer-account APIs, order data, webhooks, and billing. We use Google Cloud for application hosting, managed database hosting, secret management, backups, builds, and operational logging. Service providers process information only to provide contracted services and are subject to their applicable privacy and security commitments.
6. Retention and Deletion
The customer portal reads customer and order information from Shopify on demand and does not permanently copy those records into the App database. If a feature creates a limited customer-linked operational event, it is deleted when Shopify sends a valid customer-redaction request and is not retained longer than 30 days unless needed to complete an open customer request or required by law.
Merchant configuration is retained while the App is installed. Shopify sessions are deleted on uninstall. Remaining merchant configuration and customer-linked events are deleted when Shopify sends the required shop-redaction request. Infrastructure logs and encrypted backups follow configured Google Cloud retention schedules and are overwritten or deleted in the ordinary course. Data required by law may be retained only for the required period and isolated from ordinary use.
7. Privacy Requests
Customers should ordinarily submit access, correction, deletion, consent, or opt-out requests to the Shopify merchant with whom they have a relationship. Shopify sends verified privacy requests to the App through mandatory compliance webhooks. The App authenticates those requests, deletes applicable customer-linked records, and completes required action within 30 days.
8. Security
Information is encrypted in transit using HTTPS/TLS and encrypted at rest by Google Cloud managed services. We use Shopify authentication, HMAC-verified privacy webhooks, least-privilege access, managed secrets, database authentication, and separation of production secrets from source code. No security method can provide an absolute guarantee.
9. International Processing
The App is operated from Pennsylvania, United States, and currently uses Google Cloud infrastructure in the United States, including the us-east1 region. Shopify, Google Cloud, and their subprocessors may process information in other locations subject to applicable transfer safeguards.
10. Changes
We may update this Policy when the App, law, or our service providers change. The updated version will show a new effective date. Merchants will be asked to accept materially updated processing terms where required.
11. Contact
Peter Nuako / Amamrefie
44 E Bacon St
Pottsville, PA 19560
United States
Email: info@amamrefie.com