This policy explains how Sofenx ("we", "us", or "our") processes information when a merchant installs or uses Sofenx Confirm & Upsell (the "App") with a Shopify store.
Information we process
We process only information needed to provide the App:
- Store information, including the store domain, store name, merchant contact email, plan, currency, and time zone.
- Limited order information, including the order identifier and name, payment gateway, financial status, verification status, and tags used by the merchant.
- The buyer phone number entered in the Thank you page verification block, the one-way digest of the verification code, and SMS or WhatsApp delivery status.
- Merchant configuration, including encrypted credentials for the merchant-selected Twilio or Infobip account.
We do not use buyer phone numbers for marketing, advertising, profiling, or sale.
How we use information
We use this information to send transactional order-verification codes through the merchant's selected SMS provider or the Sofenx-managed Infobip WhatsApp channel, record verification results, apply the merchant's order tags or timeout action, display configured post-purchase offers, provide support, prevent abuse, enforce plan allowances, and operate App billing.
Service providers and international processing
The App shares the phone number and transactional message with the SMS provider selected and connected by the merchant, or with Infobip and WhatsApp when Sofenx-managed WhatsApp is selected. Provider terms, destination coverage, sender registration, template approval, and applicable charges or plan allowances apply. We also use infrastructure and email delivery providers to host and operate the App. Information can be processed in countries other than the merchant's or buyer's country, subject to applicable contractual and legal safeguards.
Security and retention
Connections to the App use HTTPS. Buyer phone numbers and merchant SMS credentials are encrypted at rest. Verification codes are stored only as one-way digests. We limit order payload storage to fields required for verification and enforcement. Administrative production access is limited to authorized operators using key-based authentication and is logged.
Order-verification records are retained for up to 90 days after their last update, then deleted. Store configuration is retained while the App is installed and is deleted after Shopify sends the required shop-redaction request, unless a longer period is required by law. Encrypted production backups are retained for up to 30 days and are accessible only to authorized operators.
Merchant and buyer choices
Merchants can disable verification, change the delivery method, disconnect their SMS provider, or uninstall the App. Buyers request an OTP from the Thank you page and can request access to or deletion of their personal information through the merchant from whom they placed the order. We process Shopify's mandatory customer data-request and redaction webhooks and provide the applicable data to the merchant or delete it.
Merchant responsibilities
The merchant determines why and when the App is used for its store and is responsible for providing required notices, obtaining any required SMS or WhatsApp consent, selecting compliant delivery settings, and responding to buyer requests. Sofenx processes buyer information on the merchant's instructions to provide the App.
Changes and contact
We may update this policy as the App or applicable requirements change. The effective date above identifies the latest version. For privacy questions or requests, email [email protected].