Privacy Policy
Executive Summary & Statutory Role Allocation
Loyalty Engine operates as an automated customer loyalty, VIP tier rewards, and referral platform engineered for the Shopify ecosystem. Under applicable privacy statutes (EU/UK GDPR Art. 4, CCPA/CPRA, and PIPEDA):
1. Introduction & Statutory Scope
This Privacy Policy governs the collection, processing, storage, transmission, and deletion of personal data by Loyalty Engine (the “Application”), developed and operated by Oxford Impulse (“Company”, “we”, “us”, or “our”), designed for Shopify e-commerce merchants (“Merchants”).
In delivering loyalty points calculation, VIP tier progression, milestone discounts, referral rewards, transactional notifications, and AI-driven program suggestions, the Company operates under statutory privacy frameworks including Regulation (EU) 2016/679 (European Union General Data Protection Regulation – EU GDPR), the UK Data Protection Act 2018 / UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), and Shopify’s Protected Customer Data (PCD) Requirements.
By installing, configuring, or accessing the Application through Shopify, Merchants acknowledge and agree to the data processing terms, security safeguards, and sub-processor engagements described in this Policy.
2. Categories of Personal Data Processed
A. Merchant Data (Data Controller Relationship)
When a Merchant installs and configures the Application via the Shopify App Store, we collect and process information necessary to maintain the shop account, execute billing, and deliver technical operations:
- Account Identifiers: Shopify Primary Domain (e.g.,
store.myshopify.com), unique Shop ID, Merchant Email Address, Shop Name, Store Physical Location, and Store Currency Settings. - OAuth Authentication Tokens & Authorized API Scopes: Application session tokens issued by Shopify for authorized API scopes:
read_customers,read_files,read_orders,read_inventory,write_app_proxy,write_content,write_customers,write_discounts, andwrite_products. - Billing and Subscription Telemetry: Selected app subscription plan — Starter ($19/month, up to 300 orders/month, no AI Insights), Growth ($39/month, up to 500 orders/month, AI Insights included), or Scale ($79/month, unlimited orders, AI Insights included) — each optionally combined with the Plus add-on (+$29.99/month, billed as a single combined Shopify subscription that itemizes both amounts, e.g. “Growth with Plus” at $68.99/month total) for a custom email sending domain and higher AI usage limits. Trial length is 30 days on Starter and 14 days on Growth, Scale, or any Plus-combined plan. Shopify App Subscription API transaction identifiers are also recorded.
- Support and Operational Communications: In-app message inquiries, technical support tickets, feature requests, and custom email configuration parameters (Resend API configurations, sender From Name, Reply-To email addresses).
- Marketing Outreach (Merchant Contact Details Only): The Merchant’s store email address and store name may be synchronized to Oxford Impulse’s internal administrative tools (a dedicated Klaviyo account and an encrypted Google Sheet operated by Oxford Impulse) to communicate critical product updates, service advisories, and renewal notices. This communication applies strictly to Merchant business contact information and never involves or accesses Merchant Customer data.
B. Customer Data (Data Processor Relationship)
To execute point accounting, reward redemptions, milestone issuances, and notifications on the Merchant’s instructions, the Application processes the following limited Customer personal data:
- Customer Identifiers (PCD Level 2): Shopify Customer ID, First Name, Last Name, Email Address, Marketing Email Consent State (
subscribedorunsubscribed), and — whenever Shopify provides a valid one on an order or account, regardless of whether the Klaviyo integration is enabled — Phone Number and SMS/WhatsApp Marketing Consent State (subscribedorunsubscribed). Customer names and emails are used solely to display account balances in the Merchant’s Customer Directory, address email greetings, and route transactional notifications. Phone Number and SMS/WhatsApp Marketing Consent State are only ever shared with Klaviyo — and only used to power an optional WhatsApp reminder channel the Merchant builds in their own Klaviyo account — when the Merchant has enabled our optional Klaviyo integration. - Transaction & Order Telemetry (PCD Level 1): Order IDs, timestamps, order total values, and order cancellation/refund events to compute points earned and execute refund clawbacks. In-Flight Processing Limitation: Line items, product IDs, variant IDs, and discount allocations are read and evaluated in memory at the exact moment of webhook arrival (to enforce product/collection exclusions and compute earnable points) but are not persisted in our database afterwards—only the resulting total order monetary value is stored.
- Loyalty Ledger History: Spendable point balances, lifetime points earned, lifetime points redeemed, assigned VIP tier status, the inactivity date used to calculate expiration timelines (where enabled by the Merchant), and single-use 7-character discount coupon codes issued.
- Ways-to-Earn Input Telemetry: Customer-provided birth date (stored strictly as month and day only,
MM-DD; we never request or store a birth year), account registration timestamps, and social media follow claim records (platform identifier and claim timestamp only; the Application does not inspect external social media account profiles). - Referral Program Telemetry: Unique referral sharing codes/URLs, referrer-to-referee customer association mappings, conversion timestamps, and discount redemption statuses.
- Shopify Customer Tags & Metafield (Opt-In, Merchant-Enabled): Where the Merchant opts in, we write a
Loyalty: <status>tag (e.g.Loyalty: New, VIP tier, or RFM segment) and aloyalty_points_balancemetafield onto the Customer’s own Shopify record, so the Merchant can build native Shopify customer segments and target them with Shopify Email or other native tools. This creates no new data category beyond what is already listed above — it writes a subset of the Loyalty Ledger History data back onto the Merchant’s own Shopify customer record.
Strict Level 2 Data Minimization & Exclusions
In adherence to global privacy principles and Shopify PCD guidelines, the Application explicitly enforces:
3. Legal Bases for Processing (GDPR Art. 6)
We process personal data strictly in accordance with recognized lawful grounds:
- Performance of Contract (GDPR Art. 6(1)(b)): Processing Merchant account credentials, billing identifiers, and transactional settings is necessary to fulfill our service agreement with the Merchant and deliver application features.
- Legitimate Interests (GDPR Art. 6(1)(f)): Processing referral interactions (such as verifying first-order status and checking for matching referrer and referee email accounts) falls under our legitimate interest in preventing coupon fraud and protecting Merchant operating margins from bad-faith abuse.
- Data Processor Authorization & Legal Compliance (GDPR Art. 6(1)(c) & Art. 28): Processing Customer order records and points accounting is executed strictly pursuant to the Merchant’s instructions (under our Data Processing Agreement) and to comply with statutory legal mandates (such as Shopify GDPR webhook erasures).
- Consent (GDPR Art. 6(1)(a)): Promotional email notifications (such as “Points Earned” balances or “Redeem Nudge” messages) are sent only after verifying that the Customer holds an active
email_marketing_consent = subscribedstate in the Merchant’s Shopify customer profile. Transactional emails (such as reward code confirmations) are delivered under contractual necessity.
4. Approved Sub-Processors & Infrastructure
To deliver scalable cloud hosting, transactional database storage, email delivery, and optional AI intelligence, we engage vetted third-party sub-processors. All vendors are bound by Data Processing Agreements meeting GDPR Article 28 and CCPA standards:
| Sub-Processor | Location | Processing Activity & Scope | Data Transferred |
|---|---|---|---|
| Shopify Inc. | Canada / USA | E-commerce host, GraphQL API provider, app subscription billing processor. | Merchant profile, API auth tokens, billing records. |
| Neon Inc. | United States | Cloud-hosted PostgreSQL database provider storing the primary points ledger and settings. | Encrypted customer loyalty ledgers, balances, and shop configs. |
| Railway Corporation | United States | Infrastructure-as-a-Service (IaaS) application container server execution. | Encrypted data in-transit during runtime API request handling. |
| Resend Inc. | United States | Transactional email delivery infrastructure executing reward confirmations and points updates. | Customer Name, Email Address, and generated reward codes. |
| Klaviyo Inc. (Optional) | United States | Merchant-configured marketing sync provider (active only when explicitly connected by Merchant). | Customer Email, phone number (when a valid one is available) and SMS/WhatsApp consent status, points balance, VIP tier status to Merchant’s own account. |
| Klaviyo / Google LLC (Internal) | United States | Oxford Impulse merchant relationship management tools for service notices. | Merchant Shop Name & Merchant Email only (Zero Customer Data). |
| Nage AI (Optional) | International API | Anonymized AI loyalty program optimization engine (active on eligible plans). | Zero Customer PII. Anonymous store percentiles and AOV only. |
Server-Side Anonymized AI Engine Architecture
The Application includes an intelligent optimization layer powered by Nage AI. Our server architecture enforces strict server-side statistical aggregation:
- Prior to calling the Nage AI API endpoint, our backend server aggregates raw shop order data into anonymous, store-wide metrics (such as customer spend distribution percentiles, store Average Order Value, and customer frequency buckets).
- Zero Customer Personal Data Transmitted: Customer names, email addresses, phone numbers, raw order IDs, physical addresses, and individual customer profiles are never transmitted to Nage AI.
- Merchant Supervisory Control: AI suggestions never alter live loyalty rules automatically. The Merchant must explicitly review and approve any proposed tier structures before they are applied.
5. Data Retention & Mandatory Deletion Pipelines
A. Active Subscriptions
Merchant configurations, customer loyalty ledgers, transaction records, and support logs remain securely retained in our Neon PostgreSQL database for the active duration of the Merchant’s subscription.
B. Uninstallation & Database Purge Policy
When a Merchant uninstalls the Application, Shopify immediately revokes OAuth API access tokens. Upon receiving Shopify’s statutory shop/redact webhook, the Application executes a complete, unrecoverable database wipe across all twenty-one (21) database models:
ShopSettings, LoyaltyCustomer, LedgerEntry, SocialClaim, ReferralConversion, Referral, ReferralSettings, AiSuggestion, AiSettings, OrderStat, BonusCampaign, EarnRule, VipTier, RedemptionTier, SpendMilestone, MilestoneReward, EarningExclusion, AttributedOrder, EmailSettings, EmailTemplate, and SupportRequest.
Note: Customer profiles synchronized to the Merchant’s own Klaviyo account are not deleted on app uninstallation, as those records remain the exclusive property of the Merchant.
C. Statutory GDPR Privacy Webhooks
In compliance with mandatory Shopify Partner requirements, the Application operates automated webhook handlers for data subject requests:
customers/data_request(GDPR Art. 15 / Access): Compiles the specified Customer’s loyalty ledger entries and spendable balance so the Merchant can fulfill Data Subject Access Requests.customers/redact(GDPR Art. 17 / Erasure): Immediately executes an unrecoverable database purge of the specified Customer’s records across all relevant tables:LoyaltyCustomer,LedgerEntry,MilestoneReward,ReferralConversion,Referral,SocialClaim, andOrderStat.shop/redact(Shop Erasure): Executes the full administrative database purge described above within statutory timelines.
6. Technical & Organizational Security Measures
We maintain comprehensive technical safeguards to preserve personal data integrity:
- Encryption in Transit: All HTTP traffic, GraphQL API queries, and webhooks enforce Transport Layer Security (TLS 1.2 / TLS 1.3).
- Encryption at Rest: Database storage provisioned through Neon PostgreSQL enforces AES-256 encryption at rest. App servers on Railway store no Customer personal data on disk.
- Cryptographic Webhook HMAC Verification: Every incoming webhook payload from Shopify is cryptographically verified via SHA-256 HMAC signatures prior to processing.
- Tenant Isolation: Database queries strictly enforce tenant isolation by unique
shopdomain identifier to prevent multi-tenant data bleed. - Atomic Financial Ledger Accounting: Points transactions write to an append-only event ledger (
LedgerEntry) using atomic database operations, preventing race conditions or balance corruption. - API Credential Protection: External API keys (Resend API keys, Klaviyo Private API Keys) are stored as encrypted environment variables or secure database records and are never exposed in storefront scripts.
7. International Data Transfers
Personal data processed by the Application may be transferred to, stored, and processed in the United States, Canada, or other international jurisdictions where our infrastructure and sub-processors operate.
For Merchants located in the European Economic Area (EEA), United Kingdom, or Switzerland, cross-border data transfers to jurisdictions lacking an adequacy decision rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or adherence to the EU-U.S. Data Privacy Framework (DPF) and UK Extension where applicable to our sub-processors.
8. Data Subject Rights & Statutory Disclosures
End-customers seeking to exercise statutory privacy rights (Access, Correction, Erasure, Data Portability, or Opt-Out) should direct inquiries to the store Merchant, who acts as the primary Data Controller. We assist Merchants via Shopify’s automated privacy webhooks and direct administrative controls:
- Right to Access & Portability (GDPR Art. 15 & 20 / CCPA § 1798.100): Merchants can retrieve a compiled ledger summary via the
customers/data_requestwebhook or directly export records from the Customer Directory. - Right to Erasure (GDPR Art. 17 / CCPA § 1798.105): Executed automatically via the
customers/redactwebhook, or Merchants can exclude individual customers via the in-app Customer Directory. - California CCPA / CPRA Notice: We do not sell personal information, nor do we share personal information for cross-context behavioral advertising. We do not process Sensitive Personal Information for inferring characteristics.
- Non-Discrimination: We uphold the principle of non-discrimination for consumers exercising statutory privacy rights.
- Children’s Privacy (COPPA / GDPR Art. 8): The Application is designed exclusively for commercial e-commerce merchants and is not directed to children under 13 (or under 16 in the EU/UK). We do not knowingly collect personal data from minors.
9. Merchant Privacy Policy Disclosure (Copy-Paste)
To assist Merchants in maintaining complete transparency under GDPR Article 13 and local consumer disclosure statutes, Merchants may incorporate the following clause into their store’s public Privacy Policy:
Loyalty Program & Customer Rewards Data Processing:
We operate a customer loyalty and rewards program powered by Loyalty Engine (developed by Oxford Impulse). To compute point accruals, manage VIP status levels, process referrals, and issue single-use reward vouchers, we share specific purchase and profile information with Loyalty Engine.
Data processed for this purpose includes your customer identifier, name, email address, order monetary totals, point redemptions, and (where voluntarily provided by you) your birth month and day (MM-DD) or social follow claim timestamps. Where a phone number and SMS/WhatsApp marketing consent are available from your Shopify account or order, and the store has enabled its optional WhatsApp integration, that information may also be processed to support WhatsApp/SMS loyalty reminders. The application does not collect your physical shipping address, birth year, or payment card details.
Loyalty points and reward history are retained while you maintain an active account with our store or until you request deletion. You may request access to, or deletion of, your loyalty records at any time by contacting our store support team.
10. Modifications to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal regulations, Application functionality, or sub-processor arrangements. When material changes occur, we will update the “Last Updated” date at the top of this document and notify active Merchants through the Application admin panel or registered billing email.
11. Contact Information & Data Protection Inquiries
For inquiries regarding this Privacy Policy, compliance verifications, or Data Subject Access Requests (DSAR), contact our Data Protection Officer at:
Oxford Impulse Compliance Team
Attention: Privacy Compliance Officer
Email: info@oxfordimpulse.com
Website: https://oxfordimpulse.com
Application Support: https://loyalty-engine-production-0e12.up.railway.app/app/messages
EU/UK Residents: If you believe your data protection rights have been infringed and we are unable to resolve your concern, you have the right to lodge a complaint with your local supervisory authority (e.g., the UK Information Commissioner’s Office – ICO, or relevant EU Data Protection Authority).