Privacy Policy
- Effective
- 25 March 2026
- Last updated
- 10 August 2026
1. Overview
Reorbit processes personal data as both:
- Data Controller — account data
- Data Processor — merchant customer data
2. Data We Collect
Merchant data
- Name, email, company details
- Billing information
- Account credentials
Customer data
- Names and emails
- Shipping and billing addresses
- Order and transaction data
- Loyalty data (points, rewards, redemptions)
- Behavioural and engagement data
Usage data
- IP address
- Device and browser info
- Platform interaction data
Reorbit only collects and processes data necessary to provide and improve the Services.
3. Shopify Data Usage
Reorbit processes data obtained through Shopify solely to provide services to the Merchant.
Reorbit does not use such data for:
- Advertising
- Resale
- Independent marketing
4. How We Use Data
- Provide and operate Services
- Enable reviews, loyalty and messaging
- Improve performance
- Provide support
- Ensure security
We do not sell personal data.
5. Legal Basis
- Contract performance
- Legitimate interests
- Legal obligations
Customer data is processed under Merchant instructions.
6. Roles
- Merchant — Controller
- Reorbit — Processor
7. Data Sharing
We share data with subprocessors (hosting, analytics, integrations).
8. International Transfers
We use safeguards like Standard Contractual Clauses when transferring data outside the EEA.
9. Data Retention
- Stored while the account is active
- Limited retention after termination
Upon uninstallation of the Reorbit application, personal data obtained through Shopify will be deleted or anonymized within a reasonable period, unless legally required otherwise.
10. Security
We implement:
- Encryption in transit — traffic to our services, and between them, is protected with TLS.
- Encryption at rest — our production database and file storage are encrypted with AES-256, and their automated backups and snapshots inherit that encryption.
- Additional protection for credentials — merchant access tokens and API keys are individually encrypted with AES-256-GCM under a dedicated AWS KMS key with automatic rotation, so they remain protected even from direct database access.
- Access controls — access to production systems is restricted, and permission to decrypt merchant credentials is scoped to the single service that requires them rather than granted across our infrastructure.
- Monitoring
We follow industry-standard security practices for data accessed through Shopify APIs.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we protect your data using the measures described above.
11. User Rights
Customers should contact the Merchant. We assist where required.
12. Cookies
See our Cookie Policy.
13. Updates
We may update this policy.
14. Contact
Reorbit Labs OÜ · Sepapaja 6, Tallinn, Estonia