1. Who We Are

Randio Commerce LLC (New Jersey, USA) operates Randio and is the controller of merchant account data. For the store and customer data you connect to the Service, you are the controller and we act as your processor, handling that data on your instructions to provide the Service. Contact us at support@randioapp.com.

2. Data We Collect

We collect the following data as allowed by Shopify scopes:

  • Store info, products, collections, orders, and customer data
  • Merchant account info (name, email, store information)
  • Email engagement events (delivery, open, click, bounce, complaint, unsubscribe) for messages we send on your behalf
  • Usage data including log data and device/browser metadata

We do not knowingly collect data from anyone under 16, and the Service is not directed to children.

3. How We Use Data

We use the data for the following:

  • To provide and operate the app
  • Provide analytics on performance, activity, and usage
  • Calculate plan usage and billing
  • Create and send personalized campaigns to your customers using your collections and products
  • Authenticate accounts
  • Maintain reliability and security, including maintaining a global email suppression list to prevent delivery to invalid addresses
  • Provide support
  • Comply with platform requirements

We do not sell merchant or customer data, and we do not share it for cross-context behavioral advertising. Your data is never used to train, fine-tune, or improve general-purpose AI models.

4. Email Deliverability & Suppression

To protect email deliverability across our platform, we maintain a global email suppression list. When an email address produces a hard bounce (permanent delivery failure), a spam complaint, or an unsubscribe or erasure request, we record the address, the classification, and a timestamp to prevent future delivery attempts to that address from any store using our Service.

  • This list is used solely for send/no-send delivery decisions — never for analytics, profiling, or marketing
  • No merchant-specific data (store name, order history, campaign details) is attached to suppression records
  • Suppression records are not visible to or shared with merchants — merchants see only the delivery outcome for their own campaigns
  • Hard bounces, spam complaints, unsubscribes, and erasure requests are retained indefinitely — retaining the address is what allows us to keep honoring the request; soft bounce records expire after 30 days

5. Data Sharing & Sub-Processors

We may share data with service providers strictly to operate the app. All providers are bound to protect your data and may use it only to provide their service to us. Current categories of sub-processor:

  • Cloud hosting, storage, and databases
  • Email delivery
  • Your commerce platform, for authentication and billing
  • Logging, monitoring, and error reporting

We may change sub-processors as the Service evolves; the current list is available on request at support@randioapp.com. We may also disclose data where required by law or to protect our rights, and to a successor in a merger or acquisition, subject to this policy.

6. Retention

We keep store and customer data for as long as your account is active and for a reasonable period afterward, then delete it — except suppression records (see section 4), records we must keep for tax, accounting, or legal reasons, and de-identified aggregate statistics that cannot be tied back to you or your customers.

7. Your Rights

Depending on where you or your customers live, you may have the right to access, correct, delete, port, or restrict processing of personal data, to object to processing, and to withdraw consent. To exercise a right over your own merchant account data, contact support@randioapp.com.

For your customers' data you are the controller: send us the request and we will act on it as your processor. On Shopify, customer data requests and erasure requests routed through the platform's mandatory webhooks are handled automatically.

8. Cookies & Similar Technologies

The admin app uses cookies strictly necessary for authentication and session security. On your storefront we use a first-party identifier to recognize a returning visitor, so the same discount catalog is shown to them and a view is counted once per device. We do not use advertising or cross-site tracking cookies.

9. Security

We implement reasonable safeguards to protect platform data, but no system is completely secure.

10. Data Deletion

Upon uninstall, platform-required data deletion is followed within a reasonable timeframe.

11. Shopify Data Access & Compliance

When installed on Shopify, we collect and process data as allowed by the OAuth scopes you grant:

  • Store info — to identify your account and configure the app
  • Products & collections — to build personalized discount catalogs
  • Customers — to target campaigns and send personalized emails
  • Orders — to track campaign performance and analytics
  • Merchant account info — name, email, and store details for authentication and support
  • All data access follows Shopify's data protection requirements.
  • Upon uninstall, we process Shopify's mandatory data deletion webhooks (customers/redact, shop/redact) within a reasonable timeframe.
  • Customer data requests (customers/data_request) are handled automatically.

12. Changes to This Policy

We may update this policy. Material changes are announced by email to your account address and/or by a notice in the app. The current version and effective date appear at the top, and the latest version is always available in Settings → Legal.

13. Contact

For questions, contact Randio Commerce LLC at support@randioapp.com.