PromoFinch

Privacy policy

Updated 6 October 2026. PromoFinch is provided by Chris Online, Netherlands. Contact info@chrisonline.nl about this policy or your data.

What we process and why

We process your shop identifier, domain, base currency, app authorization and subscription status to authenticate your store and provide the service. Shopify authentication may include staff identifiers and contact details. We read product and variant identifiers, titles, tags, vendor, product type, prices, compare-at prices, available product costs, collection membership, discount settings and related Rollout status to check your selected promotions.

We store your rules, promotion settings, price baselines, normalized discount evidence, check results, issues and job metadata so monitoring and reports can work. If you enable email alerts, we store the recipient you provide and delivery metadata. We also receive information you choose to include in support messages.

Data we do not request

The app requests read_products, read_discounts and read_rollouts. It does not request access to orders, customer records, checkout or payments and does not edit your products or discounts. Do not send customer or payment information in support messages.

Providers and sharing

Shopify provides authentication, catalog access and app billing. OVHcloud hosts the application and PostgreSQL database in London, United Kingdom. Encrypted backups are stored with Backblaze B2 in the EU. Render temporarily retains the previous deployment and database in Frankfurt for migration rollback. Resend processes transactional email recipients and alert messages. Providers may process operational or support information internationally under their own terms and data protection arrangements. We do not sell merchant data or use it for advertising.

Retention and deletion

Campaign records and their associated baselines, checks and issues are removed by the scheduled retention process after the campaign has been ended for 180 days. Settings and authorization data are retained while needed to operate your installation. Turning alerts off removes the saved recipient. Uninstalling deactivates sessions and background work. When Shopify sends a valid shop/redact request, tenant records are deleted from the application database. Provider backups and operational logs follow provider retention schedules.

Security

The app uses HTTPS, verifies Shopify requests, encrypts stored access tokens and restricts reports to the authenticated shop. Operational logs avoid access tokens and full merchant payloads. These measures reduce risk but cannot guarantee absolute security.

Your choices and rights

You can change app settings, turn alerts off, export issue reports or uninstall through Shopify. Contact us to request access, correction or deletion of personal data, or to exercise other rights under applicable law. We may need to verify that you are authorized to act for the shop. You may also contact your local data protection authority.

Changes

We update this page when our processing changes. Material changes will be communicated where required. Shopify’s own privacy policy governs its platform services.