Privacy Policy
Last updated: June 3, 2026
Overview
BuyAgainFlow (“we”, “us”) is a Shopify application that helps merchants recover repeat orders by sending consent-safe Buy Again reminder emails with exact cart links and recovered revenue tracking. This policy explains what data we process, why, and how merchants and their customers can control it.
Who controls the data
The Shopify merchant who installs BuyAgainFlow is the data controller for their customers’ personal data. BuyAgainFlow acts as a data processor, handling that data only to provide the reminder service on the merchant’s behalf.
Data we process
- Store data: shop domain, store name, plan, and app settings.
- Order data: order identifiers, purchased product and variant, quantity, and order totals used for scheduling reminders and attributing recovered revenue.
- Customer data: customer email, marketing consent status, and unsubscribe status — used only to determine eligibility and to send reminders.
- Engagement data: reminder send, click, skip, and attribution events used to populate the merchant dashboard and audit trail.
How we use data
- Schedule and send Buy Again reminder emails to eligible, consented customers.
- Build exact cart links that rebuild the same variant and quantity.
- Attribute reorders to reminders so merchants can see recovered revenue.
- Provide a transparent audit trail of sent, skipped, failed, clicked, and attributed events.
Consent and unsubscribe
BuyAgainFlow only sends reminders to customers who accepted marketing at checkout and who have not unsubscribed. Every email includes a one-click unsubscribe link. Unsubscribes are enforced before every send.
Service providers
We rely on trusted infrastructure providers to operate the service:
- Shopify — order, product, and customer data via the Shopify Admin API.
- Resend — email delivery for reminder and test emails.
- Supabase — database hosting for app and reminder data.
- Vercel — application hosting.
These providers process data only as needed to deliver their part of the service.
Data retention
We retain reminder and attribution data while the app is installed so merchants can view performance. When a store uninstalls the app, related data is removed in line with Shopify’s data-handling requirements, including responses to data request and redaction webhooks.
Data sharing
We do not sell personal data. We do not share personal data with third parties except the service providers listed above that are required to operate the service.
Contact
Questions about this policy or your data can be sent to reminders@buyagainflow.com.