1. Overview
This Privacy Policy describes how Loorx ("Loorx", "we", "our", or "us") collects, uses, stores, and protects information when a Shopify merchant installs or uses the Loorx Shopify app, related storefront widgets, APIs, and browser extension features.
By installing or using Loorx, the merchant authorizes us to access data from Shopify and connected services only as needed to provide the app features selected by the merchant.
2. Information We Collect
Merchant and store information
When a merchant installs or uses Loorx, we may collect:
- Shop domain, store name, Shopify shop ID, owner or staff contact details, and store email.
- Country, currency, locale, target language, subscription plan, installation status, and billing status.
- Shopify OAuth access tokens and app configuration needed to connect Loorx with the merchant's store.
- App settings for features such as size charts, trust badges, visitor counters, sticky add to cart, stock countdown, social media buttons, content protection, review widgets, and other enabled tools.
Product, review, order, and storefront data
Depending on which features the merchant uses, we may collect or process:
- Product titles, descriptions, images, variants, SKUs, prices, inventory, collections, and related product metadata.
- Imported product data from AliExpress or other supported supplier sources selected by the merchant.
- Product review content, including reviewer name, reviewer email if provided, rating, comment, images, country, review date, source, and publication status.
- Order details needed for order-management features, including order number, customer name, customer email, shipping address, phone number, line items, totals, currency, financial status, and fulfillment status.
- Storefront widget data such as product IDs, widget impressions or clicks, visitor country, visitor IP address, and visit time when visitor-related features are enabled.
Technical and support information
We may collect technical information needed to operate and secure the service, including:
- IP address, browser type, device information, request logs, error logs, and timestamps.
- Messages, screenshots, files, and account details that merchants provide when contacting support.
3. How We Use Information
We use collected information to provide, maintain, and improve Loorx, including to:
- Install, authenticate, and connect the app to Shopify stores.
- Import, edit, publish, and synchronize products, reviews, widgets, settings, and metafields selected by the merchant.
- Display enabled storefront widgets and app embeds on the merchant's Shopify storefront.
- Manage orders and product data when the merchant uses those features.
- Apply plan limits, provide billing-related functionality, and prevent misuse.
- Provide customer support, troubleshoot issues, and communicate service updates.
- Protect the service, detect errors, investigate abuse, and comply with applicable legal obligations.
We do not use Shopify merchant or customer data for unrelated advertising, and we do not sell personal information.
6. Data Retention and Deletion
We keep information only for as long as needed to provide Loorx, support merchants, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary depending on the data type and feature.
- Merchant account and app configuration data is generally retained while the app is installed or while the merchant has an active account.
- Imported products, reviews, widget settings, and order-related records are retained until the merchant deletes them, uninstalls the app, or requests deletion, unless retention is legally required.
- Security, access, and error logs are retained for a limited period needed for security, debugging, and compliance.
When a merchant uninstalls Loorx or requests deletion, we will delete or anonymize personal data that is no longer required, subject to backups, fraud prevention, tax, accounting, legal, and dispute resolution requirements.
7. Privacy Rights and Shopify Requests
Merchants may request access, correction, export, or deletion of their Loorx account data by contacting us. Customers of Shopify stores should contact the merchant directly first, because the merchant controls the customer relationship and store privacy notice.
Loorx supports Shopify privacy and compliance workflows, including requests to access stored customer data, delete customer data, and delete shop data after uninstall. We respond to verified Shopify compliance webhook requests and privacy requests as required by applicable law and Shopify platform rules.
8. Security
We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction. These safeguards include access controls, secure authentication, encrypted connections where supported, monitoring, and restricted access to production systems.
No internet service can guarantee absolute security. Merchants should protect their Shopify accounts, staff permissions, and connected third-party credentials.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our app, legal requirements, or business practices. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice in the app or by email.
10. Contact Us
For privacy questions, data requests, or security concerns, contact Loorx at support@loorx.com.
If you are a customer of a Shopify store that uses Loorx, please contact that store directly for customer privacy requests. We will work with the merchant and Shopify where required.