Privacy policy
Last updated: 6 October 2026
Sellrova is a Shopify app that helps stores sell more (bundles, cart drawer, reviews, sales pop-ups, post-purchase offers and related tools). This policy explains what data the app accesses, why, how long it is kept, and how it is deleted. Questions: support@sellrova.com.
What the app can access in your store
When a merchant installs Sellrova, Shopify asks them to approve these permissions. Each is used only for the feature named:
- Read orders: real recent sales for sales pop-ups, “verified buyer” on reviews, the order tracking page, cart reminders and the revenue dashboard.
- Write products: image alt texts and the store’s review rating fields on products.
- Write files: review photos and image backups, stored in the store’s own Shopify Files.
- Write discounts: the automatic bundle discount that Shopify applies at checkout.
- Read themes: to show the merchant whether the app’s theme blocks are switched on.
- App proxy: the storefront widgets talk to the app through the store’s own address.
What we store
- Store settings: the merchant’s choices in the app (texts, colors, offers, bundles).
- Recent sales for pop-ups: product, city and country of recent orders, and the order time. Never a customer’s name, email, phone or street address. Kept for up to 30 days (at most 200 per store).
- Reviews: the name the reviewer chose to show, rating, text and photos. The reviewer’s email is used once to check the purchase and is stored only as a one-way hash, never in readable form.
- Cart reminders (only if the merchant switches them on, and only for shoppers who ticked Shopify’s “text me” box at checkout): the phone number is kept only until the one reminder is sent (or the order is placed), then deleted. The merchant’s reminder list keeps the shopper’s first name, the last 4 digits of the phone, and the cart items and total, for 30 days.
- Revenue dashboard: order IDs and amounts of sales that came through the app’s features. No customer details.
- Merchant’s messaging keys (Twilio or WhatsApp, optional): encrypted (AES-256-GCM) and never shown again in the app.
- Competitor Spy: only public product information from other online stores that the merchant chooses to watch.
- Shopify access token: needed for the app to work; kept on our server and used only for the features above.
What we never do
- We never sell or share store or customer data, and never use it for advertising.
- We never show fake orders, fake reviews, fake visitor counts or fake countdowns.
- We never send messages to shoppers from our own accounts. Reminders go out only through the merchant’s own Twilio or WhatsApp account, with the shopper’s consent.
Where data is processed
The app runs on our server at Oracle Cloud. Data stays between Shopify, that server and, only if the merchant sets it up, the merchant’s own Twilio or Meta (WhatsApp) account. All connections use HTTPS.
Deletion
- When a merchant uninstalls Sellrova, Shopify removes the app’s storefront settings at once, and we delete all of the store’s data from our server when Shopify sends its shop-deletion request (48 hours after uninstall).
- When a customer asks a store to delete their data, Shopify forwards the request and we delete that customer’s sales pop-up entries, reviews and cart reminders.
- Merchants can ask for deletion or a copy of their data at any time: support@sellrova.com.
Changes
If this policy changes, the new version is posted on this page with a new date.