Privacy Policy — Bizloop Rewards
Written to be accurate about what the app does. It is not legal advice, and
should be reviewed by a lawyer before the app is published.
Last updated: 5 September 2026
Provider: Mubashar Abbas, trading as Bizloop Rewards — Islamabad, Pakistan
Contact: bizloop123@gmail.com
Bizloop Rewards ("the app") is a loyalty program for Shopify stores. Customers
earn points on paid orders and redeem them for discounts.
This policy explains what personal data the app processes on behalf of a
merchant, and why.
What we process
The app stores, per store:
| Data | Purpose |
|---|---|
| Shop domain | Identify which store a record belongs to |
| Shopify customer ID | Attribute points to a customer |
| Order ID and refund ID | Award points, reverse them on refund, prevent duplicates |
| Order subtotal amounts | Calculate how many points an order earns |
| Points amounts and timestamps | Maintain the points balance and its history |
| Merchant program settings and reward definitions | Run the program as configured |
What we do not process
The app does not collect, store, or have access to:
- Customer names
- Email addresses
- Phone numbers
- Billing or shipping addresses
- Payment or card details
- Browsing, tracking, or analytics data
The app requests access to Shopify protected customer data at Level 1 only,
and requests none of the protected customer fields (name, address, phone,
email). Customers are identified solely by their Shopify customer ID.
Why we process it
Solely to operate the loyalty program the merchant has installed: awarding
points on paid orders, reversing them on refunds and cancellations, and applying
the discount a customer redeems at checkout.
Personal data is not used for any other purpose. It is not sold, shared for
advertising, or used to build profiles. It is not used for automated
decision-making with legal or significant effects.
Where it is stored
- In transit: all traffic uses TLS (HTTPS).
- At rest: in a managed PostgreSQL database with encryption at rest, hosted
by Railway in the United States (us-east).
How long we keep it
Points history is retained while the program is active, because a customer's
balance is the sum of it. Beyond that:
| Event | What happens |
|---|---|
Customer requests erasure (customers/redact) | That customer's entire points history is deleted |
Customer requests their data (customers/data_request) | Their points history is exported and made available to the merchant in the app, to pass on within 30 days. Deleted if the customer later requests erasure, or when the app is uninstalled |
Merchant uninstalls the app (shop/redact, 48 hours later) | All data for that store is deleted: points, rewards, settings, and sessions |
These are handled automatically through Shopify's mandatory compliance webhooks.
Customer rights
Customers exercise their rights through the merchant whose store they shopped
at. Shopify forwards those requests to the app, which fulfils them as described
above. Merchants can also contact bizloop123@gmail.com directly.
Subprocessors
| Subprocessor | Purpose |
|---|---|
| Shopify | Source of order and customer data; hosts the storefront and admin |
| Railway | Application hosting |
| Railway (managed PostgreSQL) | Managed PostgreSQL |
Changes
Material changes to this policy will be communicated to merchants before they
take effect.