Privacy Policy

Last updated: 25 July 2026

Subflow ("we", "the app") is a subscriptions app for Shopify stores. This policy explains what data the app stores, why, and how long for.

What we store

When a merchant installs Subflow, we store:

What we do not store

We never receive or store payment card numbers or bank details. All charges are executed by Shopify against the payment method the customer already gave your store; Subflow only asks Shopify to create the charge and records the result.

Why we store it

Solely to operate the service: to charge subscriptions on schedule, to show you your subscribers, to let your customers manage their own subscriptions, and to notify you and them when a payment fails. We do not sell this data, do not share it with advertisers, and do not use it to train models.

Who we share it with

How long we keep it

Your customers' rights

We implement Shopify's mandatory privacy webhooks. When a customer asks your store for their data, we compile everything Subflow holds about them and send it to you. When a customer asks to be erased, we delete their personal data from our records. You do not need to contact us for either — Shopify triggers both automatically.

Security

All traffic is served over HTTPS. Data is isolated per shop: every query is scoped to the shop it belongs to, and the customer portal additionally verifies that a subscription belongs to the logged-in customer before showing or changing anything. Access tokens and secrets are stored as encrypted platform secrets.

Contact

Questions, data requests or complaints: privacy@subflow.store. We respond within 30 days.

← Back to Subflow · Support