Privacy Policy — Bizloop Rewards

Written to be accurate about what the app does. It is not legal advice, and
should be reviewed by a lawyer before the app is published.

Last updated: 5 September 2026

Provider: Mubashar Abbas, trading as Bizloop Rewards — Islamabad, Pakistan

Contact: bizloop123@gmail.com

Bizloop Rewards ("the app") is a loyalty program for Shopify stores. Customers

earn points on paid orders and redeem them for discounts.

This policy explains what personal data the app processes on behalf of a

merchant, and why.

What we process

The app stores, per store:

DataPurpose
Shop domainIdentify which store a record belongs to
Shopify customer IDAttribute points to a customer
Order ID and refund IDAward points, reverse them on refund, prevent duplicates
Order subtotal amountsCalculate how many points an order earns
Points amounts and timestampsMaintain the points balance and its history
Merchant program settings and reward definitionsRun the program as configured

What we do not process

The app does not collect, store, or have access to:

The app requests access to Shopify protected customer data at Level 1 only,

and requests none of the protected customer fields (name, address, phone,

email). Customers are identified solely by their Shopify customer ID.

Why we process it

Solely to operate the loyalty program the merchant has installed: awarding

points on paid orders, reversing them on refunds and cancellations, and applying

the discount a customer redeems at checkout.

Personal data is not used for any other purpose. It is not sold, shared for

advertising, or used to build profiles. It is not used for automated

decision-making with legal or significant effects.

Where it is stored

by Railway in the United States (us-east).

How long we keep it

Points history is retained while the program is active, because a customer's

balance is the sum of it. Beyond that:

EventWhat happens
Customer requests erasure (customers/redact)That customer's entire points history is deleted
Customer requests their data (customers/data_request)Their points history is exported and made available to the merchant in the app, to pass on within 30 days. Deleted if the customer later requests erasure, or when the app is uninstalled
Merchant uninstalls the app (shop/redact, 48 hours later)All data for that store is deleted: points, rewards, settings, and sessions

These are handled automatically through Shopify's mandatory compliance webhooks.

Customer rights

Customers exercise their rights through the merchant whose store they shopped

at. Shopify forwards those requests to the app, which fulfils them as described

above. Merchants can also contact bizloop123@gmail.com directly.

Subprocessors

SubprocessorPurpose
ShopifySource of order and customer data; hosts the storefront and admin
RailwayApplication hosting
Railway (managed PostgreSQL)Managed PostgreSQL

Changes

Material changes to this policy will be communicated to merchants before they

take effect.