UVERON Daily App

Privacy policy

Pre-release draft · Updated September 22, 2026

USMIH Ltd. operates UVERON Daily App. This policy describes the data used to provide its Shopify features. Merchants control their store settings and customer relationships.

USMIH Ltd.
str. Sofia 65a, 1225 Sofia, Bulgaria
VAT number: BG207299888
info@seoexpert.bg

Data used by the app

  • Account and settings: shop domain, Shopify authorization tokens, granted permissions, staff identity and language, module settings, design preferences, translations and submitted feedback.
  • Catalog and ordering: products, variants, prices, inventory, locations and publication status. Customer tags and company assignments are read when needed to authorize access and obtain contextual Shopify pricing. Bulk Editor stores the selected changes, before-and-after values, job history and the staff reference responsible for a job.
  • Wishlist: saved product and variant IDs, quantities, notes, priorities and timestamps. Signed-in lists use a pseudonymous owner key and an encrypted Shopify customer ID; company lists also use company and location IDs.
  • Bundles & Cross-sell: the merchant’s chosen products, offer names, language and appearance settings. Private cart line properties identify the offer and a random add attempt so the widget can confirm the result; they are not used for cross-session tracking.
  • Back in Stock: an encrypted email address, a shop-specific email hash, selected product and variant, language, consent record, unsubscribe token hash and delivery status.
  • Analytics and purchase notifications: pseudonymous order references, quantities, currency, attributed amounts and processing timestamps for Analytics; product references and a paid timestamp for recent-purchase notifications. These new records do not contain buyer names, emails, addresses or readable order IDs.
  • Privacy requests: hashed matching references, request status and operational timestamps used to provide exports and perform deletion.

Purpose and browser storage

We use this data to operate the features selected by the merchant, authenticate users, enforce access and plan limits, deliver requested restock emails, prevent abuse, resolve support issues and process privacy requests. The app does not sell personal data or use it for third-party advertising.

Guest Wishlists and unfinished quick-order selections are stored in the shopper’s browser. If enabled, guest Wishlist items can be merged into the customer’s signed-in list. Promotion widgets use session storage to remember displayed or dismissed cards. Prices and availability are refreshed from Shopify.

Retention

  • Settings, active Wishlists, bundle offers, stock-planning rules, session records and operational visibility records remain while needed for the installed app, or until removed by the relevant deletion flow.
  • Completed Bulk Editor history is eligible for deletion after 90 days. Records needed by an active restore job remain until that job is finished.
  • Restock subscriptions expire after 180 days. Associated delivery records are removed during cleanup once any in-progress send has settled.
  • Analytics defaults to 365 days. Product-feedback records default to 30 days. Deployment settings can change either period within a range of 30 to 730 days.
  • Recent-purchase proof and cancellation or refund suppression records are retained for 30 days. Purchase cards are eligible for display for no more than 24 hours.
  • Customer-data export references expire after 30 days; request audit records are kept for up to 730 days. Completed Wishlist request records are removed after 90 days.

Scheduled cleanup removes expired records in batches. Uninstall and verified shop-redaction events trigger deletion of app-owned records for that store. The published policy must identify the configured retention periods and any separate infrastructure backup retention before public launch.

Service providers and protection

Shopify supplies the commerce and authentication services used by the app. Render is selected for application and PostgreSQL hosting, and Resend for restock email delivery. Their deployment and processing configuration remain to be verified for this release. When Resend sending is enabled, the recipient address and message content are sent to Resend. The final provider details and retention must be confirmed before this draft is published.

The application restricts records by store and checks authorization for protected actions. It encrypts stored Wishlist customer IDs and restock email addresses at the field level. Hosting region, database and backup encryption, and international-transfer arrangements are deployment details that have not yet been verified for this release.

Access, correction and deletion

Customers should contact the merchant operating their Shopify store to verify a request. The app accepts Shopify privacy webhooks and provides matching exports to authorized store administrators. An export supplied to the merchant’s browser does not prove that it reached the customer; the merchant remains responsible for verified delivery. Redaction requests queue removal of matching app-held records.

Merchants can contact info@seoexpert.bg for assistance. Do not email passwords, access tokens or an unrequested customer export. Restock recipients can also use the unsubscribe link in their email to stop further notifications for that request.

Updates

We will update this policy when the app’s processing or service providers change. The date above identifies this version.