ReportifyPro← Back to site

Privacy Policy

Effective August 24, 2026

ReportifyPro ("the App", "we", "us") is a Shopify app operated by IntelliShop that turns a merchant's own store data into reports they can read, export and schedule. This policy explains what data the App processes, why, how it is protected, and the choices merchants and their customers have. By installing the App you agree to this policy.

The short version. ReportifyPro reads your store data to build the report you asked for and hands the result to you. It does not keep copies of your reports, it never sells or advertises with your data, and uninstalling it erases everything we hold for your shop.

1. Who we are and how to reach us

IntelliShop — contact support@reportifypro.app. We act as a data processor on behalf of the merchant, who remains the data controller for their store's data.

2. Data the App processes

The App reads store data through Shopify's Admin API when a merchant opens a report, exports one, or when a schedule the merchant created runs. It reads only what the selected report needs. Depending on the report this can include:

  • Order data: orders and line items, totals, discounts, taxes, refunds and returns, financial and fulfillment status, shipping and billing details.
  • Catalog data: products, variants, SKUs, prices, costs, vendors, collections, tags and inventory levels by location.
  • Customer personal data (Shopify "protected customer data"): customer name, email address, phone number and addresses, and the same fields as they appear on orders and draft orders.
  • Customer journey data: referrer, landing page and UTM parameters recorded by Shopify against an order.
  • Payments data: transactions, gateways, fees, payouts and disputes exposed by Shopify Payments.
  • Merchant account data: the shop domain and the Shopify access token needed to call the Admin API, plus your App settings, saved report views, schedules and run history.
  • A Google connection you choose to make: if you connect Google Drive or Sheets as a delivery destination, we store the OAuth tokens that allow the App to write the files it creates.

We do not collect data directly from a merchant's customers, and we do not use tracking pixels, advertising identifiers, or analytics on customer data.

3. Purposes

Personal data is used solely for store management on the merchant's instruction:

  • rendering the report the merchant opened, with the columns, filters, sort order and date range they chose;
  • producing the export file the merchant requested (Excel, CSV, PDF, HTML, XML or JSON);
  • delivering scheduled reports to the destinations the merchant configured — email recipients they name, their own FTP/SFTP server, their Amazon S3 bucket, or their Google Drive/Sheets account;
  • showing schedule history and results inside the App.

We never sell personal data, use it for advertising, profiling or automated decision-making, or share it with anyone other than the sub-processors listed below.

4. What we store, and for how long

The App is deliberately built so that report contents are not retained. A report is rendered from Shopify's API each time it runs, and an export is streamed to the merchant's browser or straight to their chosen destination. We do not keep a copy of the file or of the rows inside it.

What we do store, in the App's database:

  • Your Shopify session — shop domain and access token — for as long as the App is installed.
  • Your configuration — App settings, cost inputs, saved report views, favourites and schedules — until you delete them or uninstall.
  • Run history metadata — which report ran, when, in which format, how many rows and whether delivery succeeded. This contains no customer data. You can cap it with the history-retention setting, or erase it at any time from Settings.
  • Google OAuth tokens, only if you connect Google Drive or Sheets, until you disconnect or uninstall.

The database is hosted on Fly.io in Amsterdam (EU), encrypted at rest and backed up with encrypted snapshots. Test and development data is kept in a separate environment from production data.

On uninstall, Shopify notifies the App and the session for that shop is deleted immediately; Shopify's shop/redact webhook then removes every remaining row for that shop.

5. Sub-processors

We use these infrastructure providers, each bound by their own data-protection terms:

  • Fly.io — application hosting and database (EU region).
  • Cloudflare — DNS and email routing for our own domain.
  • Resend — email delivery, only when a merchant chooses email as a delivery destination or enables run notifications.
  • Google — Google Drive and Sheets, only when a merchant connects their own Google account.
  • Crisp — live chat on our website and inside the App, for support conversations you start.
  • Any FTP/SFTP server or Amazon S3 bucket a merchant configures is chosen and controlled by that merchant.

6. Security

  • All traffic uses TLS (HTTPS, FTPS/SFTP, HTTPS APIs).
  • Data is encrypted at rest. Delivery credentials and OAuth tokens are held server-side and are never returned to the browser.
  • Access to production systems is limited to the operator, protected by strong passwords and two-factor authentication.
  • Every scheduled run is logged in the App's history; infrastructure access is logged by our providers.
  • Optional controls you can switch on in Settings: anonymise personal data in report output, and restrict the App to the store owner.
  • In the event of a security incident affecting personal data, we will contain it, notify affected merchants and Shopify without undue delay, and rotate credentials.

7. Merchant and customer rights

Merchants can view and delete schedules, run history and saved views inside the App at any time, and can uninstall the App to delete all of their data. Merchants receiving access, correction or deletion requests from their customers can fulfil them from Shopify; because the App retains no report contents, there is normally nothing further for us to erase — but if you believe otherwise, email us and we will act within 30 days. The App honours Shopify's mandatory customers/data_request, customers/redact and shop/redact webhooks.

8. International transfers

The App runs in the EU. Where a sub-processor operates outside the EEA, transfers rely on that provider's Standard Contractual Clauses or an adequacy decision. If you deliver reports to a destination of your own choosing, that transfer is yours to control.

9. Changes

We may update this policy; the effective date at the top will change and material changes will be announced inside the App.

Terms of Service · Support · support@reportifypro.app