1. Introduction and Scope
This Privacy Policy explains how NOVUS APPS LTD ("Novus", "we", "us" or "our") handles personal data in connection with the products and services we provide.
It applies to:
- our website and any associated marketing or informational pages;
- the Shopify applications we develop and operate (each an "App", together the "Apps");
- any associated dashboards, administrative interfaces, application programming interfaces (APIs) and integrations that we provide as part of, or in support of, those Apps.
We develop and operate software that extends and integrates with the Shopify platform. Our products are used by Shopify merchants (our "Merchants" or "customers") to support the operation of their own online stores.
In most circumstances, and in respect of the personal data that flows through our Apps about a Merchant's own customers, Novus acts as a data processor acting on the instructions of the Merchant, who is the data controller. This distinction is explained in detail in Section 7.
This Policy is intended to be read alongside any applicable Data Processing Agreement, terms of service, end user licence agreement or order form that governs the relationship between Novus and a Merchant. Where there is a conflict between this Policy and a signed agreement with a Merchant, the terms of that agreement prevail in respect of that Merchant's data.
This Policy does not govern the practices of Shopify Inc. or of any Merchant. Merchants are independently responsible for their own privacy compliance, including the information they provide to their own customers (see Section 7).
2. Company Identity and Contact Details
This Policy is issued by:
- Legal entity: NOVUS APPS LTD
- Trading name: Novus
- Company number: 17271978
- Jurisdiction of incorporation: England and Wales
For any questions about this Policy, or to exercise data protection rights where Novus is the relevant controller, you can contact us at:
- Email: hello@bynovus.io
We are not currently required to appoint a statutory Data Protection Officer under the UK GDPR. Where we appoint a person or team with day-to-day responsibility for data protection matters, enquiries sent to the address above will be routed to them.
3. Definitions
The following terms are used in this Policy with the meanings given below. Where a term is defined in the UK GDPR or the Data Protection Act 2018, that statutory meaning applies.
- UK GDPR means the United Kingdom General Data Protection Regulation, being Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018, and as amended.
- DPA 2018 means the Data Protection Act 2018.
- PECR means the Privacy and Electronic Communications (EC Directive) Regulations 2003, as amended.
- Personal data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on personal data, whether or not by automated means, including collection, storage, use, disclosure and erasure.
- Data controller (or "controller") means the natural or legal person who determines the purposes and means of the processing of personal data.
- Data processor (or "processor") means a natural or legal person who processes personal data on behalf of a controller.
- Data subject means the identified or identifiable natural person to whom personal data relates.
- Merchant means a business or individual that installs, accesses or uses one of our Apps, dashboards or services in connection with a Shopify store.
- End customer means a customer or visitor of a Merchant's Shopify store whose personal data may be processed through our Apps on the Merchant's behalf.
- Shopify means Shopify Inc. and its affiliates, which provide the underlying commerce platform on which our Apps operate.
- ICO means the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection.
4. What Data We Collect
The categories of personal data we process depend on how you interact with us, and on the configuration of the relevant App. We have grouped them below.
4.1 Merchant data
When a Merchant installs or uses our Apps or services, or contacts us, we may process:
- store identifiers and configuration information, such as the Shopify store domain, store name, store ID, primary store locale, currency, country and plan-level information made available to us by Shopify;
- account and contact details of the individuals who administer or use the App on behalf of the Merchant, such as name, business email address, role and, where provided, telephone number;
- billing and subscription information relating to the Merchant's use of our paid services, noting that card payment details are handled by Shopify or our payment providers and are not stored by us;
- correspondence and support records, including the content of enquiries, tickets and any information voluntarily provided when contacting us.
4.2 Limited end customer data accessed via Shopify APIs
Depending on the functionality of a given App and the scopes that the Merchant authorises on installation, we may access a limited set of personal data relating to the Merchant's own end customers, such as:
- order and transaction data;
- customer names, contact details and delivery or billing addresses associated with orders;
- product, cart and browsing-related data necessary for the App to function.
We access and process this end customer data only as a processor, strictly to provide the App's functionality to the Merchant, and only to the extent permitted by the access scopes granted at installation. We do not use end customer data for our own independent purposes. The handling of Protected Customer Data is subject to Shopify's data protection requirements, and we limit our access to what is reasonably required for the relevant App to operate.
Not all Apps access end customer data. Where an App does not require it, we do not request the relevant access scopes.
4.3 Technical data
When you use our website, Apps, dashboards or APIs, we may automatically collect technical information, including:
- internet protocol (IP) address and approximate location derived from it;
- device, browser and operating system information;
- log data, including timestamps, request paths, referring pages and error reports;
- usage and diagnostic analytics relating to how our products are accessed and used.
We use technical data primarily to operate, secure, troubleshoot and improve our services.
4.4 Special category data
We do not intend to collect special category personal data (such as data revealing health, ethnicity, religious beliefs or similar) and we ask that such data is not submitted to us through support channels. If a Merchant's store configuration causes such data to pass through an App, we process it only as a processor on the Merchant's instructions.
5. How We Collect Data
We collect personal data through the following channels.
5.1 Via the Shopify platform and APIs
When a Merchant installs an App, Shopify provides us with certain store and account information, and the Merchant authorises specific access scopes. Through Shopify's APIs we may then access the categories of data described in Sections 4.1 and 4.2, subject to those authorised scopes. Access is governed by Shopify's platform terms and by the permissions the Merchant grants and can revoke.
5.2 Directly from you
We collect data that you provide directly, for example when you create or configure an account, set preferences in a dashboard, complete a form on our website, subscribe to communications, or contact our support team.
5.3 Through cookies and similar technologies
We and our service providers may use cookies and similar tracking technologies on our website and, where applicable, within our dashboards, to enable core functionality, remember preferences, maintain security and understand usage. The use of non-essential cookies is subject to consent in accordance with PECR. Further detail is set out in Section 14.
6. Lawful Bases for Processing
Where Novus acts as a controller (for example, in respect of Merchant account data, our own marketing, website analytics and security), we rely on one or more of the following lawful bases under Article 6 of the UK GDPR:
- Performance of a contract (Article 6(1)(b)) — to provide our Apps and services to Merchants, manage accounts, process subscriptions and provide support;
- Legitimate interests (Article 6(1)(f)) — to operate, secure, maintain and improve our services, prevent fraud and abuse, communicate about our products, and run our business, provided these interests are not overridden by the rights and freedoms of the data subject;
- Compliance with a legal obligation (Article 6(1)(c)) — to meet our legal, regulatory, tax and accounting obligations, and to respond to lawful requests from authorities;
- Consent (Article 6(1)(a)) — for non-essential cookies, certain electronic marketing, and any other processing where we ask for and you give consent. Where we rely on consent, you may withdraw it at any time.
Where Novus acts as a processor in respect of Merchant and end customer data, the relevant lawful basis is determined by the Merchant as controller. We process that data on the Merchant's documented instructions and do not determine the purposes of that processing ourselves.
7. Role Clarification: Processor and Controller
The respective roles of Novus, the Merchant and Shopify are central to this Policy and are stated here for clarity.
7.1 Novus as processor
In respect of personal data that we access or process on behalf of a Merchant through our Apps, dashboards, APIs and integrations — including end customer data described in Section 4.2 — Novus acts as a data processor. We process that data only:
- on the documented instructions of the Merchant, including as set out in any applicable agreement;
- for the purpose of providing and supporting the App's functionality; and
- as otherwise required by applicable law, in which case we will inform the Merchant unless legally prohibited from doing so.
We do not sell end customer data, and we do not use it for our own independent purposes, including profiling or marketing unrelated to the operation of the App.
7.2 The Merchant as controller
The Merchant is the data controller in respect of its own end customers' personal data. The Merchant determines why and how that data is collected and used in its store. Accordingly, the Merchant is responsible for:
- having its own privacy notice and lawful basis for collecting and processing end customer data;
- obtaining any consents required from its end customers;
- responding to data subject rights requests made by its end customers; and
- ensuring its use of our Apps is lawful.
End customers who wish to exercise their rights, or who have questions about how their data is used in a particular store, should contact the relevant Merchant directly (see Section 13).
7.3 Novus as controller
In respect of Merchant account data, our own website analytics, security logging, billing records and direct communications with Merchants and prospects, Novus acts as a controller and processes that data in accordance with Sections 6 and 8.
8. How We Use Data
We use personal data for the following purposes.
8.1 Providing and operating the Apps
To install, configure, authenticate and run the Apps; to deliver the features the Merchant has enabled; to display dashboards; to handle API requests; and to provide customer support and respond to enquiries.
8.2 Service improvement
To understand how our products are used, diagnose faults, develop new features and improve performance, reliability and usability. Where this involves data we hold as a processor, we use it in aggregated or de-identified form, or strictly as permitted by our agreement with the Merchant.
8.3 Security and fraud prevention
To protect the integrity and security of our services and our Merchants, including monitoring for unauthorised access, abuse and fraudulent activity, maintaining audit logs, and enforcing our terms.
8.4 Business administration and legal compliance
To manage billing and subscriptions, maintain business records, comply with legal and regulatory obligations, and establish, exercise or defend legal claims.
8.5 Communications
To send service-related messages (such as security, billing and operational notices) and, where permitted, information about our products. Marketing communications are sent in accordance with PECR and you may opt out at any time.
9. Data Sharing
We do not sell personal data. We share personal data only as described below.
9.1 Shopify
Our Apps operate on the Shopify platform and necessarily exchange data with Shopify in order to function. Shopify's own processing of personal data is governed by Shopify's terms and privacy policy.
9.2 Infrastructure and service providers
We may use trusted third-party providers to host, operate, secure, monitor and support our services. These may include, but are not limited to, cloud hosting and storage providers, content delivery networks, logging and error-monitoring services, analytics providers, communications and email providers, and payment and billing processors. Where these providers process personal data on our behalf, they do so as our processors (or sub-processors) under contractual terms that require appropriate safeguards consistent with the UK GDPR.
We select providers on the basis of their security and compliance posture and limit the data shared to what is necessary for the relevant service. We keep our use of providers under review and may change providers from time to time without changing the substance of this Policy.
9.3 Legal and regulatory disclosures
We may disclose personal data where required to do so by law, regulation, court order or other lawful request from a competent authority, or where necessary to protect our rights, property or safety, or those of our Merchants or others.
9.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and data protection safeguards.
10. International Data Transfers
We are based in the United Kingdom and prefer to keep personal data within the UK or the European Economic Area (EEA) where practicable.
Some of our service providers, and Shopify, may process personal data in countries outside the UK. Where we transfer personal data outside the UK, we ensure an appropriate safeguard is in place, which may include:
- transfers to countries covered by UK adequacy regulations (including, where applicable, the European Economic Area and other jurisdictions recognised as adequate by the UK government);
- the International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's Standard Contractual Clauses (SCCs); or
- another lawful transfer mechanism recognised under the UK GDPR.
Where we rely on such safeguards, you may request further information using the contact details in Section 2.
11. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, including to provide our services, meet our legal, accounting and reporting obligations, resolve disputes and enforce our agreements.
Retention periods vary by data type and context. As a general principle:
- Merchant account and configuration data is retained for the duration of the Merchant's use of our services and for a reasonable period afterwards;
- end customer data processed on a Merchant's behalf is retained only as long as required to provide the App, and is handled in line with the Merchant's instructions and applicable retention settings;
- log, security and diagnostic data is retained for a limited period appropriate to its purpose;
- billing and financial records are retained for the period required by law.
We support flexible, configurable retention periods where the relevant App or our agreement with a Merchant provides for them. When an App is uninstalled, or when a Merchant or Shopify requests deletion, we delete or de-identify the associated personal data within a reasonable period, subject to any overriding legal retention obligation. Our Apps are configured to respond to Shopify's mandatory data-deletion and data-request webhooks (including shop and customer redaction requests) in accordance with Shopify's requirements.
12. Security Measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures are kept under review and may include:
- encryption of data in transit and, where appropriate, at rest;
- access controls, authentication and the principle of least privilege;
- network and application security controls;
- logging, monitoring and alerting for security events;
- segregation of environments and controlled change management;
- vetting and contractual obligations for staff and providers with access to data;
- backup and recovery processes.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We maintain procedures to identify, assess and respond to personal data breaches, and to notify the ICO and affected parties where required by the UK GDPR and DPA 2018.
13. Your Rights
Subject to the conditions and exemptions in the UK GDPR and DPA 2018, data subjects have the following rights:
- the right to be informed about how personal data is used;
- the right of access to personal data we hold about them;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure in certain circumstances;
- the right to restrict processing in certain circumstances;
- the right to data portability in certain circumstances;
- the right to object to processing based on legitimate interests or to direct marketing;
- rights in relation to automated decision-making and profiling, where applicable;
- the right to withdraw consent at any time where processing is based on consent.
Where Novus is the controller (for example, in relation to Merchant account data), you may exercise these rights by contacting us using the details in Section 2. We will respond within the statutory time limits and may ask for information to verify your identity.
Where Novus is a processor — which is the case for end customer data processed on a Merchant's behalf — requests should be directed to the relevant Merchant, who is the controller. If we receive a rights request relating to data we hold as a processor, we will, where appropriate, forward it to the relevant Merchant and assist them in responding, rather than acting on it independently. End customers should therefore contact the Merchant (store owner) directly to exercise their rights.
14. Cookies and Tracking
We and our service providers use cookies and similar technologies on our website and, where relevant, within our dashboards. These fall broadly into:
- strictly necessary cookies, required for the service to function and to maintain security, which do not require consent; and
- non-essential cookies, such as analytics and preference cookies, which are used only where you have given consent in accordance with PECR.
You can manage your preferences through any consent mechanism we provide and through your browser settings. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.
Where we publish a separate, more detailed cookie notice, that notice forms part of this Policy and should be read alongside it.
15. Third-Party Services and Integrations
Our services operate within, and connect to, the Shopify platform and may integrate with other third-party services and providers. The categories of provider we rely on are described in Section 9.
We may use, add, replace or remove third-party providers including, but not limited to, hosting, storage, analytics, monitoring, communications and payment providers, from time to time, in order to deliver and improve our services. Where any such provider processes personal data on our behalf, we put appropriate contractual and security safeguards in place.
Third-party services that you choose to connect to, or that are operated by Shopify or by a Merchant, are governed by their own privacy terms, and we are not responsible for their independent practices.
16. Changes to This Policy
We may update this Policy from time to time to reflect changes in our services, our providers, or legal and regulatory requirements.
Each version of this Policy carries a version number and an effective date, shown at the top of the document. When we make material changes, we will take reasonable steps to bring them to the attention of affected Merchants, for example by notice within the App, by email, or by updating the published version. Continued use of our services after an updated Policy takes effect constitutes acceptance of the updated Policy, to the extent permitted by law.
We recommend reviewing this Policy periodically. Earlier versions are available on request.
17. Contact and Complaints
If you have any questions, concerns or requests regarding this Policy or our handling of personal data, please contact us:
- Email: hello@bynovus.io
- Company: NOVUS APPS LTD, company number 17271978, England and Wales.
We ask that you contact us first so that we can try to resolve any concern. If Novus is acting as a processor, please also note that the relevant controller is the Merchant whose store the data relates to.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
Exercising the right to complain to the ICO does not affect any other legal remedy available to you.