Winback IQ
Privacy Policy
Last updated: July 12, 2026
Winback IQ (“the app”, “we”, “us”) is a Shopify app that reads a merchant’s own order history to produce an RFM (Recency / Frequency / Monetary) customer segmentation and a revenue-ranked win-back worklist. This policy explains exactly what data the app accesses, why, how long it is kept, and how we protect it. It applies only to the Winback IQ app; it does not govern the Shopify platform or any third-party tool you connect on your own.
Who is the controller
For the store data processed by Winback IQ, the merchant (store owner) is the data controller and Winback IQ is a data processor acting on the merchant’s instructions. If you are a shopper of a store that uses Winback IQ, please contact that store for any request about your personal data.
What data we access
On install the app requests the minimum Shopify scopes it needs to do its one job:
- read_orders — to read your order history (order dates, amounts and the associated customer identifier) so it can compute each customer’s Recency, Frequency and Monetary value.
- read_customers — to associate orders with customers when scoring them.
- write_customers — used only by the optional Pro tag-sync to add a non-destructive
WinbackIQ:<Segment>tag to a customer. It never reads, edits or deletes any other customer field.
Because it reads order and customer records that can identify a person, Winback IQ is classified as a Protected Customer Data Level 2 (customer identity) app at the access boundary under Shopify’s data protection requirements.
What we store — and what we do not
Winback IQ is aggregate-and-discard at the storage boundary. The analysis worker reads your orders and customer identifiers transiently (in memory, for the duration of a run), derives the aggregate scores, and then discards everything except:
- an opaque Shopify customer ID (the GID) — used only so you can open a customer in your own Shopify admin and so the optional tag-sync knows which customer to tag;
- numeric aggregates — recency (days), order count, total spend, the R / F / M scores (1–5), the lifecycle segment, and the revenue at risk.
We do not store customer names, emails, phone numbers, postal addresses, payment details or individual line items in our database or logs. We do not sell, rent or share your data, and we do not use it to build any cross-merchant profile.
No AI and no messaging
Winback IQ uses a deterministic RFM algorithm running on our own servers. It does not use any AI or large-language-model service, and it does not send any emails, SMS or other messages to your customers. It prepares segments and a worklist; any outreach is done by you, in your own email/SMS tool (e.g. Klaviyo or Shopify Email), where you remain the sender and controller.
How we protect data
- Data is transmitted over encrypted HTTPS/TLS connections to the Shopify Admin API.
- Access tokens are stored server-side and never exposed to the browser.
- Only the aggregate scores and the opaque customer ID are persisted; there is no customer PII at rest to leak.
- Access to production systems is restricted to the app operator.
Retention
Aggregate scores are retained while the app is installed so your dashboard, worklist and segments stay available, and are overwritten on each new analysis run. When you uninstall, we cascade-delete every stored row for your shop (see below).
GDPR & data-deletion (mandatory Shopify webhooks)
We honor Shopify’s privacy webhooks and applicable data-protection law (including the GDPR and CCPA):
- customers/data_request — for a given customer we hold only an opaque ID and aggregate scores; there is no PII for us to assemble or return.
- customers/redact — we delete that customer’s aggregate rows, keyed by opaque ID.
- shop/redact — when you uninstall, we cascade-delete every row for your shop (Shopify sends this request approximately 48 hours after uninstall).
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Because we hold no customer PII, most requests are satisfied by the redaction flows above; for anything else, contact us and we will act within the timelines required by law.
Sub-processors
Winback IQ runs on infrastructure operated for the app and relies on Shopify for the underlying store data. We do not send your store data to any advertising, analytics or AI third party.
Changes to this policy
We may update this policy as the app evolves; material changes will be reflected here with a new “last updated” date. Continued use of the app after an update constitutes acceptance of the revised policy.
Contact
Questions or privacy requests: privacy@syncerp.work. See also our protected customer data disclosure and our Terms of Service.