smartFlash Privacy Policy
smartFlash (“we”, “our”) is a Shopify Admin embedded app that helps merchants manage return policies, draft policy-grounded customer replies, run lightweight US/EU withdrawal checklist scans, and suggest proportional refund amounts. We process data only to provide these features.
Data we process
- Shop domain and offline access tokens (Shopify OAuth / session auth)
- Policy text merchants paste into the app
- Order and line-item data looked up for Refund assist (read-only; we do not create Shopify Refunds)
- Optional Ask prompts and generated replies (may include text the merchant pastes from a customer message)
- Mandatory GDPR compliance webhook payloads from Shopify
How we use data
Data is used solely to operate smartFlash features for the installing merchant. We do not sell personal data. We do not use buyer data for advertising or profiling.
AI processing
When Ask is used with a configured model key, question text and selected published policy excerpts may be sent to our AI provider (DeepSeek, or another provider configured for the deployment) to draft a reply. Drafts are guidance only—not legal advice. Merchants should review every reply before sending it to a customer.
Retention
Shop-scoped data (policies, Ask logs, compliance scans, GDPR request logs) is deleted when Shopify sends shop/redact after uninstall, or when the merchant deletes content in-app. Customer redact webhooks clear matching customer identifiers and related Ask log text where an email match is found.
Security
Data in transit is protected with HTTPS/TLS. Application data is stored in a managed PostgreSQL database with encryption at rest provided by the host.
Contact
Privacy and support: wufenghuo8@gmail.com
Last updated: August 5, 2026