Privacy Policy
Last updated: August 2026
Sublyra ("Sublyra", "the App") is a Shopify application that provides subscription management, dunning, retention, and analytics tools to merchants ("Merchants"). This policy describes what data the App processes, why, and how it is protected.
Data we process
Merchant data (collected at install via Shopify OAuth):
- Shop domain, shop name, contact email, plan selection.
- App configuration the Merchant creates (selling plans, dunning schedules, retention flows, widget settings, integrations).
Store customer data (processed on the Merchant's behalf, via Shopify webhooks and the Admin API):
- Customer name, email, and Shopify customer ID, limited to customers who hold or held a subscription created through the App.
- Subscription contract details (products, prices, billing intervals, status), order references, and billing-attempt outcomes.
- Cancellation-survey responses when a customer cancels.
We do not collect payment card numbers. Payment methods are tokenized and held by Shopify; the App only sees payment-method metadata (e.g. card expiry month/year) needed for dunning reminders.
How we use it
- Operating the subscription lifecycle: renewals, retries of failed payments, customer portal self-service.
- Transactional email/SMS on the Merchant's behalf (card-update reminders, win-back offers) via the Merchant's configured provider.
- Aggregated analytics shown to the Merchant (MRR, churn, cohorts).
We do not sell data, do not use store customer data for advertising, and do not share data with third parties except the processors below.
Subprocessors
- Hetzner — application and database hosting (VPS).
- Resend — transactional email delivery.
- Twilio — SMS delivery, only if the Merchant configures it.
- Klaviyo — marketing sync, only if the Merchant configures it.
Data retention and deletion
- Shop data is retained while the App is installed.
- On uninstall, Shopify's
shop/redactrequest triggers deletion of the shop's data within 30 days. Order-derived financial aggregates may be retained in anonymized form where required for accounting. - Customers: when Shopify sends a
customers/redactrequest, the customer's personal data is anonymized and any live subscription contracts are cancelled. Order totals are financial records and are kept in anonymized form. - Data-subject requests (
customers/data_request) are exported and delivered to the Merchant's contact email.
Security
- All traffic over HTTPS; Shopify webhook payloads verified by HMAC signature.
- Third-party credentials stored by the Merchant (e.g. Twilio, Klaviyo keys) are encrypted at rest with AES-256-GCM.
- Access to customer data is logged in an audit trail.
Contact
Privacy questions or data requests: support@sublyra.com