Appify Search & Discovery

APPIFY SEARCH & DISCOVERY — PRIVACY POLICY

Effective September 28, 2026

Appify Search & Discovery (the “App”) operates under the name Appify Creations. For privacy questions or requests, contact creationsappify@gmail.com.

This policy explains how the App handles information about merchants and their Shopify stores, shoppers who use its features, and people who contact support. A merchant’s own store privacy notice also applies to that merchant’s handling of shopper information. This policy does not change the App’s pricing or commercial terms.

Appify Creations
13 Beit Oved
Tel Aviv, 6329302
Israel

1. Information we process

Merchant and support information. We process the shop domain, installation and permissions information, authentication credentials supplied by Shopify, and subscription, billing-reference and trial information. Shopify authentication records may include a staff identifier, name, email address and locale. If you contact support, we process your reply address, subject, message and store context. We do not request payment-card numbers or security codes.

Store information and settings. We process the product and collection information needed to operate the App, including descriptions, images, prices, stock, options and variants. We also store the merchant’s settings for search, filters, recommendations, discounts, translations and vehicle-fitment features.

Searches and storefront interactions. Search text can pass through our server to find matching products. When Shopify’s customer privacy settings allow analytics, the App can record searches, product views, result or suggestion clicks, filter choices, recommendation interactions and additions to cart. These records can include time, product and widget references, device category, a random browser-session identifier and a cart identifier used to link an interaction to an order.

These identifiers do not directly name a shopper, but the information is not necessarily anonymous. A search or support message can contain personal information entered by the sender. Avoid entering sensitive information into a product search or sending passwords, access tokens or payment-card details to support.

Network addresses and technical request information can also be processed for request limits, security and operational diagnosis.

Optional order information. Order-based features require the merchant’s order-read permission and the relevant Shopify approval. The App requests order references and dates, purchased products and quantities, a cart identifier, currency and order totals. It uses recent orders from the preceding 60 days to update purchase-based recommendations and uses order-created information for attribution reports.

The App’s order subscription does not request customer names, email addresses, telephone numbers, billing or delivery addresses, payment details or order notes. It retains the information needed for purchase signals and attribution rather than the complete order payload. Shopify privacy requests can separately contain customer and order references needed to locate relevant records.

2. Why we use this information

We use this information to authenticate merchants, manage service access and provide support; operate and configure search, filters, recommendations and other enabled features; maintain the store’s product index and configured discounts; and report how the features are used.

Product, interaction and optional purchase information help rank search results and recommendations. Cart and session references can link discovery interactions to an order for attribution reporting. These reports are estimates of association with an order, rather than proof that the App caused a purchase.

Automated features match and rank products for display. The App does not offer functionality for selling shopper data or sending it to advertisers.

3. Privacy choices and browser storage

The App’s storefront analytics collect information only when Shopify reports that analytics processing is allowed. If permission is refused, undecided or unavailable, the storefront code does not create its analytics identifier, save recent-search or recently-viewed history, or send analytics events.

If Shopify subsequently reports that analytics are no longer allowed, the App clears its queued events, analytics identifier and locally stored recent-search and recently-viewed history. Interactions made before permission are not sent later when permission is granted. Changing the choice does not itself delete records already received by our server; see section 6 for requests about those records.

The App stores its analytics identifier and limited recent-search/recently-viewed history in the shopper’s browser. The history has an entry limit but no automatic expiry by date: older entries are replaced as new entries are added, and history can be cleared through the available controls or browser settings. It is also cleared following a reported withdrawal. The App can separately cache search-bar appearance settings to preserve the merchant’s chosen design on later visits.

Shopify supplies its own authentication, cart and privacy mechanisms. Functional product searches and server-side order processing are separate from optional storefront analytics. Declining analytics does not disable functional search. Merchants should configure Shopify’s privacy settings and explain their store’s processing to shoppers.

4. Service providers and processing location

The App uses Shopify for the commerce platform, authentication, APIs and customer privacy signals, and Fly.io for application and database hosting. The application database is hosted in Ashburn, Virginia, United States. Processing can therefore take place outside the country where a merchant or shopper lives.

The current AI search configuration processes product and search text within the application’s hosting environment; it does not send that text to a separate remote AI service. Order payloads are not used as inputs to AI search.

Contact our privacy address for information about the providers and transfer arrangements applicable to your store.

5. How long information is kept

Analytics and attributed orders. Current plans use a 365-day retention window for stored discovery events, search-term totals and attributed-order records. Older records are removed through periodic cleanup; deletion is not instantaneous at the end of the window. Recent-order synchronization separately removes older historical purchase signals when it updates its 60-day history.

Shopify privacy requests. When Shopify sends a customer access request, the App prepares a limited report of records linked to the supplied order references and makes it available to an authenticated merchant. The report is removed when the merchant marks the request fulfilled or after 60 days. If a request exceeds automatic processing limits, the App keeps a limited file of the supplied order references for manual review for up to 60 days. Erasure requests can also create a review case with limited cart and browser-session references when records cannot safely be assigned to one shopper; these references are removed after 60 days or when the case is marked fulfilled. A review file is not a completed customer data report.

Store, authentication and support records. These are retained in the active database while the App remains installed unless otherwise removed. The App does not currently apply a separate general timed expiry to authentication or support records. Uninstallation is described below.

Backups, logs and other copies. The hosting volume’s automatic backups have a five-day retention setting. Local backups created before database changes do not currently have automatic timed deletion. The App does not establish a fixed automatic expiry for technical logs, support email or copies exported outside the hosting volume. These copies can remain after deletion from the active database; we do not promise immediate deletion from every backup or log.

Browser-history retention is described in section 3.

6. Uninstallation and your requests

When Shopify reports that the App has been uninstalled, the App deletes the store’s operational data from its active database, including settings, catalog information, authentication records, support-form messages, analytics and attributed orders. A limited trial record is temporarily retained so reinstalling cannot restart a trial; Shopify’s subsequent shop-erasure request removes the remaining shop record.

Shopify customer-erasure requests remove matching attributed orders and conservatively linked storefront or purchase records using the order references supplied by Shopify. Shared browser sessions or carts, and information entered into a search without a reliable order link, may require manual review; we do not erase another shopper’s records merely because they share a device or cart. Erasing server records does not immediately erase backup copies, logs or data in a shopper’s browser.

Depending on applicable law, you may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent or complaint to a supervisory authority. Shoppers should normally contact the merchant first about information associated with their purchase or use of that store. Merchants and shoppers can also contact creationsappify@gmail.com about the App’s processing.

A request sent through Shopify does not automatically deliver a data report to the shopper. An authenticated merchant can download a prepared report in the App’s Privacy requests page and must handle delivery to the requester separately. Contact the merchant or our privacy address for help with an access or erasure request. The shop domain and relevant order references can help locate records. Do not send passwords, access tokens or payment-card details.

7. Security

Public application connections use HTTPS. The hosted application database is stored on encrypted Fly.io storage, including the Shopify authentication credentials held in that database. This describes protection of the hosted database and public application connections, rather than every file or email outside them.

8. Updates and contact

The published policy’s revision date identifies the current version. Changes to the App’s processing must be reflected in this policy. For privacy questions, data requests or complaints, contact creationsappify@gmail.com.