What Mapify stores
Mapify stores the location, dealer, inventory, and settings data you provide, plus operational data it needs to work: geocoding results, sync job history, audit logs, and privacy-preserving search analytics (hashed IPs, coarsened locations, rotating session hashes — never raw shopper identity).
Support chatbot conversations (admin and storefront) store message text and minimal metadata only — never secrets, API keys, or tokens — and are retained for a limited period before automatic purge; merchants can clear a conversation’s history at any time.
Merchant-provided keys and sync tokens
Map provider keys, AI provider keys, and Google Sheets/Google Business Profile OAuth tokens are encrypted at rest (AES-256-GCM) and are never logged or displayed in full — only a masked form (e.g. last 4 characters) is ever shown after saving.
Shopify customer data
Mapify does not store Shopify customer PII beyond what is described above. Store-locator visitors and dealer applicants may voluntarily submit contact details (name, email) through on-page forms; this data is used solely to operate the requested feature (e.g. routing a dealer application or a shopper lead to the merchant) and is deleted along with all other shop data on uninstall, per the GDPR section below.
GDPR webhooks
Mapify honors Shopify’s mandatory GDPR webhooks:
- customers/data_request — acknowledged; any stored data tied to the requesting customer (e.g. a matching dealer application or lead) is included in the response.
- customers/redact — acknowledged; any stored data tied to the customer is erased.
- shop/redact — deletes all shop-scoped data (locations, dealers, applications, leads, sync connections, chat history, audit logs, and settings) 48 hours after uninstall, per Shopify’s requirement.
Uninstalling
Uninstalling the app immediately stops all background processing for your shop (geocoding, sync polling, analytics retention) and revokes any stored OAuth tokens. Your data is fully deleted per the shop/redact webhook above; there is no separate manual deletion request needed for a normal uninstall.
Data deletion requests
To request deletion of your shop’s data outside the standard uninstall flow, or to ask about a specific record, contact us at mapify@webb9.com.
Contact
For privacy questions or anything else, contact us at mapify@webb9.com.