Skip to content

Privacy Policy

Effective
25 March 2026
Last updated
10 August 2026

1. Overview

Reorbit processes personal data as both:

  • Data Controller — account data
  • Data Processor — merchant customer data

2. Data We Collect

Merchant data

  • Name, email, company details
  • Billing information
  • Account credentials

Customer data

  • Names and emails
  • Shipping and billing addresses
  • Order and transaction data
  • Loyalty data (points, rewards, redemptions)
  • Behavioural and engagement data

Usage data

  • IP address
  • Device and browser info
  • Platform interaction data

Reorbit only collects and processes data necessary to provide and improve the Services.

3. Shopify Data Usage

Reorbit processes data obtained through Shopify solely to provide services to the Merchant.

Reorbit does not use such data for:

  • Advertising
  • Resale
  • Independent marketing

4. How We Use Data

  • Provide and operate Services
  • Enable reviews, loyalty and messaging
  • Improve performance
  • Provide support
  • Ensure security

We do not sell personal data.

  • Contract performance
  • Legitimate interests
  • Legal obligations

Customer data is processed under Merchant instructions.

6. Roles

  • Merchant — Controller
  • Reorbit — Processor

7. Data Sharing

We share data with subprocessors (hosting, analytics, integrations).

8. International Transfers

We use safeguards like Standard Contractual Clauses when transferring data outside the EEA.

9. Data Retention

  • Stored while the account is active
  • Limited retention after termination

Upon uninstallation of the Reorbit application, personal data obtained through Shopify will be deleted or anonymized within a reasonable period, unless legally required otherwise.

10. Security

We implement:

  • Encryption in transit — traffic to our services, and between them, is protected with TLS.
  • Encryption at rest — our production database and file storage are encrypted with AES-256, and their automated backups and snapshots inherit that encryption.
  • Additional protection for credentials — merchant access tokens and API keys are individually encrypted with AES-256-GCM under a dedicated AWS KMS key with automatic rotation, so they remain protected even from direct database access.
  • Access controls — access to production systems is restricted, and permission to decrypt merchant credentials is scoped to the single service that requires them rather than granted across our infrastructure.
  • Monitoring

We follow industry-standard security practices for data accessed through Shopify APIs.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we protect your data using the measures described above.

11. User Rights

Customers should contact the Merchant. We assist where required.

12. Cookies

See our Cookie Policy.

13. Updates

We may update this policy.

14. Contact

support@reorbit.app

Reorbit Labs OÜ · Sepapaja 6, Tallinn, Estonia