SSegmentlyBack to site

Privacy policy

Last updated: 4 August 2026

This policy explains what data the Segmently Shopify application (“Segmently”, “the app”, “we”) accesses, what it stores, and for how long. Segmently is operated by SC COVERED SRL (trading as Trackwise Studio), CUI RO47818139, Str. Principală nr. 98, Strei, Hunedoara, Romania.

The short version. Segmently reads your orders and customers in order to decide which tags to apply, but it does not keep them. Rules are evaluated in memory. What is written to our database is the Shopify ID of a record and the tags we applied to it. No customer name, email address, phone number or street address is ever stored.

1. Roles

For the merchant’s store data, the merchant is the data controller and Trackwise Studio is a data processor acting on the merchant’s instructions. For the merchant’s own account information (store domain, billing contact) Trackwise Studio is the controller.

2. What the app accesses

Segmently requests the minimum Shopify API scopes needed to do its job:

ScopeWhy it is needed
read_orders / write_ordersEvaluate rules against order data and add or remove order tags.
read_customers / write_customersEvaluate rules against customer data and add or remove customer tags.
read_productsResolve which products belong to a collection, so collection-based conditions can be evaluated.
read_all_ordersOptional and separately approved by Shopify. Without it, Shopify only exposes the last 60 days of orders, so retroactive tagging cannot reach older history.

3. What is stored, and what is not

Stored

  • Your store domain and app session tokens.
  • The rules you create: names, conditions, tags and schedules.
  • Shopify resource identifiers (for example gid://shopify/Order/123) together with the tags Segmently applied to them and when. This is what makes tag expiry, undo and the audit trail possible.
  • Tag names and counts for your store, powering the Tag Manager.
  • Operational logs: rule run outcomes, backfill progress, errors.
  • Your plan and subscription status, mirrored from Shopify Billing.

Never stored

  • Customer names.
  • Customer email addresses. Only the domain part is evaluated, and it is discarded immediately after evaluation.
  • Phone numbers.
  • Street addresses. Only country, province and postal code are evaluated, and they are discarded immediately after evaluation.
  • Payment card details or any payment credentials.
  • Order line item contents beyond the moment of evaluation.

4. How processing works

When a relevant event occurs in your store, Shopify sends a webhook. Segmently verifies its signature, records only the delivery identifier for de-duplication, and queues a job. The job fetches the record from Shopify’s Admin API, evaluates your rules against it in memory, calls Shopify’s tag mutations, and discards the record. The same path is used for a backfill, where the records arrive from a Shopify Bulk Operation.

5. Retention

  • Webhook de-duplication records: 7 days.
  • Rule run logs: 90 days.
  • Tag assignment records for removed tags: 90 days.
  • Audit log: 12 months.
  • Rules and settings: kept while the app is installed, and for up to 90 days after uninstall so a reinstall restores your setup. Deleted immediately on request.
  • On a Shopify shop/redact request, all data for the store is deleted immediately.

6. Shopify’s mandatory privacy webhooks

  • customers/data_request — we hold no personal data about a customer, so there is nothing to return. We respond confirming this.
  • customers/redact — we delete the tag bookkeeping tied to that customer’s Shopify ID, and to the orders named in the request.
  • shop/redact — we delete every record belonging to the store.

7. Sub-processors

ProviderPurposeLocation
Railway Corp.Application hosting and PostgreSQL databaseAmsterdam, Netherlands (EU)
Shopify Inc.Source of all store data; billingPer Shopify’s own infrastructure
Resend / BrevoOperational email alerts to the merchant only, if enabled. No customer data is included.EU / US

8. Security

  • All traffic is encrypted in transit with TLS.
  • Data at rest is encrypted by the hosting provider.
  • Every webhook is HMAC-verified before it is processed.
  • Access tokens are short-lived and refreshed automatically; long-lived non-expiring tokens are not used.
  • Production and development environments are separate, with no shared credentials or data.
  • Administrative access is limited to the app’s operator, protected by multi-factor authentication.
  • The database is backed up daily; backups are encrypted and retained for 7 days.
  • Suspected breaches are investigated immediately and affected merchants notified within 72 hours, along with Shopify where required.

9. Your rights

Under the GDPR you may request access to, correction of, or deletion of your data, and you may object to or restrict its processing. Write to support@trackwise.studio and we will respond within 30 days. You may also lodge a complaint with your supervisory authority; in Romania this is ANSPDCP.

10. International transfers

Application data is hosted in the European Union. Where a sub-processor transfers data outside the EEA, it does so under Standard Contractual Clauses.

11. Children

Segmently is a business tool and is not directed at children. We do not knowingly process data of anyone under 16.

12. Changes

We will post any change to this policy on this page and update the date above. Material changes are announced inside the app before they take effect.

13. Contact

SC COVERED SRL (Trackwise Studio)
Str. Principală nr. 98, Strei, Hunedoara, Romania
CUI RO47818139
support@trackwise.studio

HomePrivacy policyTerms of servicesupport@trackwise.studiotrackwise.studio