Privacy Policy
Last updated: September 17, 2026
This Privacy Policy explains how TrustPulse Review ("TrustPulse Review", "we", "us") collects, uses, and protects information when a merchant installs and uses our Shopify app, and when shoppers interact with the review features it provides on a merchant's storefront.
1. Controller and processor roles
Our role depends on the data involved. For merchant account and billing data (such as your store domain, contact email, and app settings), we act as a controller. For customer and shopper data that we process on a merchant's behalf, we act as a processor, and the merchant is the controller. The terms on which we process personal data as a processor are set out in our Data Processing Agreement (DPA), which forms part of our agreement with each merchant. This policy covers two groups: merchants who install the app, and shoppers who submit reviews or receive review-request emails on a merchant's store.
2. Information we collect
From merchants
- Your Shopify store domain and the access token issued when you install the app.
- Basic store details returned by Shopify (shop name, contact email).
- App configuration you set (widget settings, email preferences, plan).
From your store's data (via the Shopify API, with your permission)
- Products — used to display and organize reviews.
- Orders and customers — used only to (a) verify that a reviewer actually purchased the product ("verified purchase") and (b) send review-request emails after an order is fulfilled. We access the customer name, email address, and the products on the order for these purposes.
From shoppers
- Review content: rating, title, review text, and any photos the shopper uploads.
- The shopper's name and email address submitted with a review (the email is stored for verification and is never displayed publicly).
- The IP address of the review submission, used solely for spam prevention and rate limiting.
3. How we use information
- To display product reviews, ratings, and verified-purchase badges on the storefront.
- To send review-request emails on the merchant's behalf after an order is fulfilled.
- To provide moderation, analytics, and import/export tools inside the app.
- To prevent spam and abuse (rate limiting, honeypot checks).
- To operate, maintain, and improve the app.
We do not sell personal information, and we do not use it for advertising.
We may also disclose information if required by law, regulation, or legal process, or where we believe disclosure is necessary to protect our rights, property, or safety, or those of our users or others.
4. Legal basis for processing (EU/UK)
For individuals in the EU, UK, and other regions with similar laws, we rely on the following legal bases:
- Performance of a contract — to provide the app's features to the merchant under our Terms of Service and DPA.
- Legitimate interests — to verify purchases, prevent spam and abuse, secure the service, and improve the app, where these interests are not overridden by an individual's rights.
- Consent — where a shopper voluntarily submits a review, and where otherwise required by law.
5. Where data is stored and international transfers
App data is stored in a Supabase PostgreSQL database and file-storage bucket, and the application runs on Hostinger. Data is processed in the region configured for each provider, which may be outside your own country, including outside the EU/UK. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses. All data is transmitted over encrypted connections (HTTPS), and review photos are stored in a bucket served over HTTPS.
6. Third-party sub-processors
We share information only with the service providers necessary to run the app:
- Shopify — the platform the app runs on and the source of store data.
- Supabase — database and file storage.
- Resend — delivery of review-request emails.
- Hostinger — application hosting.
Each provider processes data only as needed to provide its service. A current list is maintained in our DPA.
7. Security
We use encryption in transit (HTTPS), access controls, and reputable infrastructure providers to protect personal data. No method of transmission or storage is 100% secure, but we take reasonable technical and organizational measures to protect the data we hold and review these measures periodically.
8. Shopify mandatory compliance webhooks
As a Shopify app, we implement and honor Shopify's mandatory GDPR/CCPA compliance webhooks:
- customers/data_request — when a shopper asks a merchant for the data we hold about them, we make the relevant review data available to the merchant so they can respond. Requests are fulfilled within 30 days; merchants may contact support@trustpulsereview.com.
- customers/redact — when a merchant or Shopify requests erasure of a customer's data, we delete that customer's reviews, review requests, and any uploaded review photos.
- shop/redact — sent by Shopify 48 hours after a merchant uninstalls the app; on receipt we delete all of that store's data, including reviews, review requests, photos, settings, and subscription records.
9. Data retention and deletion
- Reviews and related shopper data are retained while the app is installed and until deleted by the merchant.
- Merchant account data is retained while the app is installed and deleted within 30 days after uninstall, except billing or tax records we are required by law to keep.
- On a customers/redact request, the customer's personal data (including review photos) is deleted within 30 days of the request.
- On uninstall, Shopify sends a shop/redact request after 48 hours; we begin deleting the store's data on receipt, with deletion completed within 30 days.
- Merchants can delete individual reviews at any time from the app's moderation tools, which also removes their photos.
10. Your rights
Depending on your location, you (or a shopper, via the merchant) may have the right to access, correct, delete, or restrict the processing of personal data, or to object to it. Requests can be made to support@trustpulsereview.com, and shoppers should contact the merchant whose store collected the data.
11. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to: know the categories of personal information we collect and the purposes for which they are used; request access to, deletion of, or correction of your personal information; and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law. You also have the right not to be discriminated against for exercising these rights. To make a request, contact support@trustpulsereview.com; shoppers should contact the merchant whose store collected the data.
12. Cookies
The embedded admin (the app screens inside Shopify) uses a session cookie solely to keep the signed-in merchant authenticated for the duration of their session; it is not used for advertising or cross-site tracking. The storefront review widget does not set advertising or tracking cookies.
13. Children
The app is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
15. Contact
Questions about this policy or your data can be sent to support@trustpulsereview.com.