Privacy Policy

Last updated 28 June 2026

Rately (“we”, “us”) is a Shopify app that collects and displays product reviews. This policy explains what data we process and why. The Shopify merchant who installs Rately is the data controller for their shoppers’ data; Rately acts as a data processor.

Data we process

  • Review content — ratings, titles, text, and uploaded photos/videos submitted by shoppers.
  • Reviewer details — author name, and (optionally) email; customer id when provided by Shopify for verified-buyer attribution.
  • Review requests — order id, recipient email and/or phone, and locale, used to send review request emails/SMS.
  • Questions & answers — shopper questions and merchant/community answers.
  • Merchant account — shop domain, store contact email, plan, and settings.
  • Support chat — messages you send to the in-app assistant (retained up to 90 days, then purged).
  • Operational data — aggregate analytics and audit logs (no sensitive personal data).

AI & third-party processing

AI features are bring-your-own-key (BYOK): when you enable them, the minimum necessary content (e.g. review text) is sent to the AI provider you configure (US: OpenAI, Anthropic, Gemini; China: DeepSeek, Qwen, Zhipu, Moonshot, ERNIE). We never send Shopify access tokens, secrets, or unrelated personal data, and we do not use content to train third-party models beyond the inference call. AI is optional and can be disabled at any time.

Other processors we use:

  • Shopify — app hosting context, billing, and webhooks.
  • Resend — transactional and review-request email delivery.
  • Cloudflare R2 — storage of uploaded review media.
  • An SMS provider (e.g. Twilio) — only when SMS review requests are enabled.

How we use data

To collect, moderate, and display reviews and Q&A; to send review requests and reminders; to provide analytics, AI insights, and support; and to operate billing. We do not sell personal data.

Retention & security

Data is retained while the app is installed and for the period needed to provide the service; chat history is limited to 90 days. Provider API keys are encrypted at rest (AES-256-GCM). On uninstall we revoke stored keys and sessions; all shop data is erased after Shopify’s 48-hour redaction window. See our Data Deletion page.

Your rights (GDPR/CCPA)

Shoppers can exercise access/deletion rights through the merchant, who can trigger Shopify’s GDPR webhooks. Rately honours customers/data_request, customers/redact, and shop/redact automatically (export, anonymize, erase).

Contact

Questions about this policy or your data: rately@webb9.com.