This Privacy Policy explains how Alfa Dev (“we”, “us”, “our”) handles information in connection with Panely (the “App”), a library of theme sections you can add to your Shopify store. It applies to you as a merchant who installs the App, and to the shoppers who visit a store that uses it.
In short
- Panely stores information about your store — its domain, your sections and your plan — so the App can work.
- Panely does not collect, receive or store any personal data about your customers or store visitors.
- We don’t sell data, show ads, or use analytics or tracking services.
- After you uninstall, Shopify asks us to delete your store’s data 48 hours later, and we do. Logs age out after 30 days.
1. Who we are
Panely is developed and operated by Alfa Dev. For your store’s data described below, Alfa Dev is the data controller. For questions about this policy or your data, email us at support@alfasdevs.com.
2. What we store about your store, and why
When you install Panely, Shopify gives it read access to your products and themes. The App uses that access to let you place sections on your store; it does not copy your product catalogue to our servers. What we do store is:
- Store identity — your store’s myshopify.com domain, and the access token Shopify issues when you install, so the app can act for your store.
- Your sections — every section you add: its code, name, the settings you choose, and a record of when it was last built. Any text you type into a section is kept as part of it — including a name you enter yourself, such as a testimonial author or a team member.
- Plan status — which Panely plan your store is on, and a history of plan checks, so we can unlock the right features.
- Account history — install, uninstall, plan and section events, and whether you have finished the in-app guide. We use this to support you and to understand how the app is used.
- Sign-in sessions — while the app is open in your Shopify admin, a session record holding the IP address and browser type of the person using it. Sessions expire after two hours of inactivity and are then cleared.
- Application logs — technical logs used to run and debug the app. They name your store, never your customers, and are deleted automatically after 30 days.
When you save a section, Panely also writes it into your store as Shopify metafields, which is how your theme displays it. That copy lives in your Shopify store, not on our servers.
We don’t collect your name, email address, phone number or payment details. Shopify handles billing, and we only see which plan your store is on.
3. Your customers’ data: none
Panely is built so that none of your customers’ or visitors’ personal data reaches us:
- Forms go to Shopify. Newsletter and contact sections submit to your store’s own Shopify form handling, not to us. Shopify stores those submissions as it normally would.
- Carts go to Shopify. Bundle builders, quick-add buttons and variant swatches add items through Shopify’s cart.
- Games stay in the browser. Spin-to-win and scratch-card draws run entirely in the shopper’s browser and are not sent anywhere.
- No calls home. Panely’s storefront code makes no requests to our servers.
No part of our database holds a customer ID, email address, phone number, postal address or order. When Shopify sends us a customer data request or a customer deletion request, we confirm that we hold no data about that customer. We log the request by its ID only.
Content loaded from other services
Some sections show content hosted by another company. When a shopper views one of these sections, their browser fetches that content directly from the provider. Like any web request, this shares the shopper’s IP address and browser details with that provider. Panely does not receive this data, and each provider’s own privacy policy applies. This happens only if you use one of these sections:
- Google Fonts (fonts.googleapis.com / fonts.gstatic.com) — when a section uses a font you picked from the Google Fonts list.
- Google Maps (google.com/maps) — when you add a map section with an embedded Google map.
- YouTube (privacy-enhanced mode) (youtube-nocookie.com) — when you add a video section with a YouTube video.
- Google Hosted Libraries (ajax.googleapis.com) — when you add a 3D model section, to load Google’s <model-viewer> component.
One more storefront detail: a countdown timer set to evergreen mode saves the time a shopper first saw it in their browser’s local storage, so the countdown continues across visits. It holds only a timestamp and is never sent anywhere.
If your store uses a cookie banner or lists third-party services in its own privacy policy, include the services above for any of these sections you use.
4. Who we share data with
We share your store’s data only with the services we need to run the App:
- Shopify — the platform Panely runs on. Your store data comes from Shopify, section content is saved to your store through Shopify, and Shopify handles all billing.
- Our hosting provider — runs Panely’s servers and database, where the data listed in section 2 is stored.
We don’t use analytics, advertising, email-marketing or error-tracking services. We don’t sell, rent or trade data. We may disclose information if the law requires it, for example in response to a valid court order.
5. Cookies and browser storage in the App
The Panely admin, which opens inside your Shopify admin, uses only what it needs to work. There are no analytics or advertising cookies.
- Session cookie (Cookie, strictly necessary) — keeps you signed in to the app inside your Shopify admin. Expires after two hours of inactivity.
- XSRF-TOKEN (Cookie, strictly necessary) — protects the app’s forms against cross-site request forgery.
- panely.guide.{store} (Local storage) — remembers where you are in the first-run guide on this browser. It never leaves your browser.
To show the App’s interface, your browser also loads fonts and scripts from Shopify’s CDN (cdn.shopify.com) and icons from unpkg.com. When you preview Google Fonts in the section editor, it also loads them from Google Fonts. These requests share your IP address and browser details with those providers.
6. How long we keep data
- While the App is installed, we keep your store’s data so the App keeps working.
- When you uninstall, Shopify revokes the App’s access right away, and we record the uninstall.
- 48 hours after you uninstall, Shopify sends us a deletion request. We then permanently delete your store’s record and access token, all your sections, your plan history, account history, sign-in sessions, and any queued background work that names your store. This is a permanent deletion, not a soft delete that can be undone.
- Application logs are deleted automatically after 30 days, so no log entry naming your store survives more than 30 days after you uninstall.
- If you reinstall before the deletion request arrives, we keep your data, because you are using the App again.
The section metafields Panely saved to your store live in your Shopify store, not with us. The App can’t remove them after uninstall because its access has been revoked. They have no effect once the App is gone, and you can delete them from your Shopify admin.
7. How we protect data
All traffic to the App is encrypted with HTTPS. Shopify webhooks are verified by their signature before we act on them. Access to our servers is restricted. No system is perfectly secure, but we keep what we store to the minimum the App needs.
8. Your rights
You can ask us to:
- Access — get a copy of the data we hold about your store, in a portable format.
- Correct — fix anything inaccurate. Most of it, such as your sections and settings, you can change yourself in the App.
- Delete — erase your store’s data. Uninstalling does this automatically (see section 6). You can also email us to have it deleted sooner.
- Restrict or object — limit how we use your data, or object to a particular use.
To use any of these rights, email support@alfasdevs.com from an address we can link to your store, and tell us your myshopify.com domain. We reply within one month.
9. GDPR and UK GDPR
If your store is in the European Union, the European Economic Area or the United Kingdom, the EU General Data Protection Regulation and the UK GDPR give you the rights in section 8. Our legal bases for processing your store’s data are:
- Performance of a contract — to provide the App you installed, including your sections, plan and sign-in sessions.
- Legitimate interests — to keep the App secure and working, through logs and account history, and to support you.
- Legal obligation — where the law requires us to keep or disclose information.
Your data may be processed outside the EU, EEA and UK, both by us and by our hosting provider. Where it is, we protect it as these laws require. Contact us to ask about the safeguards we use.
Because Panely processes no customer personal data, the App adds nothing about your shoppers to your own GDPR obligations, apart from the third-party content described in section 3.
If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to your local data protection authority. In the UK, that is the Information Commissioner’s Office (ico.org.uk).
10. Children
Panely is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
We update this policy when Panely changes how it handles data, for example when we add new kinds of sections or integrations. The “Last updated” date at the top shows the latest version. If a change affects what we collect or who we share it with, we will tell you in the App before it takes effect.
12. Contact us
- Developer: Alfa Dev
- App: Panely (Shopify App Store)
- Email: support@alfasdevs.com
- Website: alfasdevs.com