Privacy Policy
Swipeo privacy policy
Last updated: Aug 12th 2026
Who we are
Swipeo ("the app", "we", "us") is a Shopify app operated by Swipeo.
For merchants installing the app, we act as a data processor on your behalf for the shopper data described below. You remain the data controller for your own customers. For your own merchant account details, we act as a controller.
What the app does
Swipeo adds a shoppable short-form video feed to a Shopify storefront. Merchants upload videos and images, attach products to them, and publish them to their storefront. Shoppers watch that feed, and can like, save, share and add products to their cart from it.
Information we collect
From the merchant
When you install Swipeo, Shopify gives us your shop domain and an access token scoped to the permissions you approved. We store:
Your shop domain and Shopify session, so the app can authenticate.
Your subscription plan, resolved through Shopify's billing system.
Everything you create in the app: reels, media files, curated lists, tags, translations, and your storefront appearance settings.
The email address you contact support from, if you contact support.
We never see or store your payment details. Billing runs entirely through Shopify, which charges your existing Shopify bill.
From shoppers on your storefront
Product and catalogue data from your store, synchronised through Shopify's API so reels can show accurate titles, images, variants and prices.
Customer records, where your storefront makes them available to the app. We hold a local mirror so a returning shopper's saved items and cart can be recognised. This is limited to what Shopify passes us.
Cart contents, mirrored so that items added from a reel survive the shopper moving between the feed and your storefront.
Interaction events: views, likes, shares, saves, and add-to-cart actions, each tied to an anonymous browser session identifier rather than to a name. These produce the analytics a merchant sees.
Locally stored preferences: a shopper's saved items, language choice and sound preference are kept in their own browser's local storage. That data stays on their device and is not sent to us.
Photos, if a shopper submits one
If a merchant switches on the shopper remix feature, a shopper may upload a photograph of themselves to generate a personalised version of a reel. That photo is a special category of personal data in some jurisdictions, so it is treated separately:
The photo is stored only for as long as it takes to generate a result.
It is sent to Google's generative AI service to produce that result, and is deleted from our storage immediately afterwards.
A generated result the shopper never submits expires on its own within 30 days.
A shopper can withdraw a submitted remix, which deletes it.
This feature is off by default and requires the merchant to enable it.
Advertising and analytics events, if the merchant configures them
Swipeo can forward storefront events to third-party advertising and analytics platforms, but only if the merchant enters credentials for them. If none are entered, nothing is forwarded and no third party receives anything.
When a merchant does configure them, the app can send events to: Meta (Facebook), Google Analytics, Google Tag Manager, TikTok, Pinterest, Snapchat and X. Depending on the event, these may include a shopper's email address, phone number, name and postal code, alongside the products viewed or purchased.
Two things about this that a merchant needs to understand:
These events pass through our servers first. Identifiers arrive unhashed, are hashed on our servers, and only the hashed form is sent onward to the advertising platforms. We do not retain the unhashed values after forwarding.
Under the CPRA this constitutes a "sale" or "share" of personal information. The app declares this to Shopify, which means it will not run at all until a shopper has granted marketing consent, and it respects a shopper's opt-out through Shopify's customer privacy controls.
If a merchant uses this, their own store privacy policy must disclose it.
What we do not do
We do not sell merchant data.
We do not use shopper data to build profiles across unrelated stores.
We do not use your catalogue, media or shopper data to train AI models.
We do not send marketing email to your customers.
How long we keep it
Merchant content stays for as long as the app is installed.
When you uninstall, Shopify notifies us and we begin deleting. Your access token is destroyed immediately. The rest is erased when Shopify sends the shop redaction request, which it does 48 hours after uninstall.
Shopper photos submitted for remixes are deleted as soon as the result is produced.
Analytics events are kept for a certain moment to get processed based on the customer plan.
We implement all three of Shopify's mandatory privacy webhooks. A customer data request returns everything we hold on that shopper. A customer redaction request deletes it, including any photographs and any stored files. A shop redaction request deletes the whole store's data.
Rights
Depending on where a shopper lives, they may have the right to access, correct, delete or export their data, to object to processing, or to opt out of the sale or sharing of their information. Shoppers should contact the store they bought from, since that merchant is the controller of their data. Merchants can raise any such request with us at support@klaimz.app and we will act on as soon as possible.
Merchants can exercise the same rights over their own account data by writing to the same address.
Security
Access tokens are stored server side and never exposed to a browser. Storefront requests are verified as coming from Shopify before they are answered. Shopper photographs are stored under unguessable keys and are not publicly listable. Access to production systems is limited to the dedicated team only.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant supervisory authority as required by law.
Changes
If we change this policy materially we will update the date above and notify merchants through the app or by email before the change takes effect.
Contact
Contact at: support@klaimz.app