Privacy Policy
Last updated: July 2026. This policy covers ollfy.com and every app Ollfy operates, including DisputePack and Complyo. It is the policy of record for our Shopify App Store listings.
Who we are
Ollfy ("we", "us") is an independent, fully remote software studio building applications for the Shopify platform, including DisputePack and Complyo. We operate from the United Kingdom and have no public trading address; the fastest way to reach us is contact@ollfy.com.
When you install one of our apps on your store, you are the data controller for your store's and customers' data, and we act as your data processor — we handle that data to provide the app's features and on your instructions, not for our own purposes. For our website and our direct dealings with you as a customer, we are the controller.
This website
Our marketing website (ollfy.com) is intentionally lightweight. When you visit it, our hosting infrastructure may process standard technical information such as your IP address and browser type in server logs, for security and reliability. We do not use advertising trackers, we set no marketing or analytics cookies, and we sell nothing collected through this site. If you email us or send a contact form, we use your message and contact details only to reply to you.
What our apps process
Every Ollfy app follows the same rules:
- it requests only the Shopify access scopes it needs to function, and its access is read-only unless a feature you use requires otherwise;
- it uses official Shopify authentication, and honours Shopify's mandatory data-protection webhooks (
customers/data_request,customers/redact,shop/redact); - it never sells merchant or customer personal information, never uses it for advertising, and never uses it to train our own models;
- it keeps data only as long as needed to provide the service, and deletes it on uninstall or on a valid request;
- it never accesses your payouts or bank details, and never sees full card numbers.
What each app processes, specifically:
| App | Data processed | Why |
|---|---|---|
| DisputePack | Store details; for disputed orders only — order and line-item data, fulfilment and tracking, payment verification results (AVS/CVV, card brand and last four digits), and the customer's email, name, address and phone; the Shopify Payments dispute record; and files, notes and settings you provide. | To assemble chargeback evidence into a PDF pack you review and submit. |
| Complyo | Store details and publicly available storefront content (pages, markup and images), plus scan results and settings. No customer personal data. | To scan your storefront for accessibility and compliance issues and report them. |
Each app also publishes its own detailed policy — see DisputePack's policy — which governs where it goes further than this one.
Sub-processors
We share the minimum data necessary with a short list of providers, each bound by confidentiality and data-protection obligations and acting only on our instructions:
| Sub-processor | Purpose |
|---|---|
| Shopify | The platform our apps run on and the source of store data. |
| Hostinger | Application hosting, databases and file storage. |
| Mailtrap | Delivery of notification, alert and digest email. |
| OpenAI | AI-assisted drafting, where an app offers it. |
| Our support and contact mailbox. |
Where an app uses AI-assisted drafting, we minimise what is sent: personal details such as customer email are redacted from the context first, and data sent to the OpenAI API is not used to train OpenAI's models.
Retention and deletion
- Generated files and reports are deleted automatically once they are no longer needed — in DisputePack, evidence packs are deleted after 90 days.
- On a customer erasure request (Shopify's
customers/redactwebhook, sent 48 hours after the request), we erase that customer's stored personal data, including any stored files. - On app uninstall or store erasure (
shop/redact), we erase all data we hold for that store. - You can ask us to delete your data at any time by emailing contact@ollfy.com.
Where your data is processed
Our servers, databases and file storage are located in the United Kingdom. If you or your customers are outside the UK, using our apps means data is transferred there. Some sub-processors listed above process data in other countries; where required, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement, the UK Addendum, or Standard Contractual Clauses — to cover those transfers.
Your rights
Depending on where you live — for example under the UK GDPR, EU GDPR, or CCPA/CPRA — you may have rights to access, correct, export, or delete personal data we hold about you, to object to or restrict certain processing, and to lodge a complaint with your data-protection authority. In the UK that is the Information Commissioner's Office.
To exercise any of these rights, email contact@ollfy.com and we will respond within the time required by applicable law. If your request relates to data one of our apps processes on behalf of a Shopify store, the store controls that data — we will coordinate with them, or direct you to them, as appropriate.
Data security
We use industry-standard measures to protect the data we process: encrypted connections (TLS) everywhere, encryption at rest for databases, file storage and sensitive credentials such as access tokens, access to production restricted to authorised personnel, and each store's data isolated from every other store's. No system is perfectly secure, but we work to reduce risk and respond quickly to any issue.
Children
Our apps are business tools sold to merchants and are not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
We may update this policy as our services evolve. When we make material changes, we will update the date at the top of this page. Continued use of our website or apps after a change means you accept the updated policy.
Contact
Questions about this policy or your data? Email contact@ollfy.com and a person will reply.