Last updated: 4 August 2026
This policy explains what data the Segmently Shopify application (“Segmently”, “the app”, “we”) accesses, what it stores, and for how long. Segmently is operated by SC COVERED SRL (trading as Trackwise Studio), CUI RO47818139, Str. Principală nr. 98, Strei, Hunedoara, Romania.
The short version. Segmently reads your orders and customers in order to decide which tags to apply, but it does not keep them. Rules are evaluated in memory. What is written to our database is the Shopify ID of a record and the tags we applied to it. No customer name, email address, phone number or street address is ever stored.
For the merchant’s store data, the merchant is the data controller and Trackwise Studio is a data processor acting on the merchant’s instructions. For the merchant’s own account information (store domain, billing contact) Trackwise Studio is the controller.
Segmently requests the minimum Shopify API scopes needed to do its job:
| Scope | Why it is needed |
|---|---|
read_orders / write_orders | Evaluate rules against order data and add or remove order tags. |
read_customers / write_customers | Evaluate rules against customer data and add or remove customer tags. |
read_products | Resolve which products belong to a collection, so collection-based conditions can be evaluated. |
read_all_orders | Optional and separately approved by Shopify. Without it, Shopify only exposes the last 60 days of orders, so retroactive tagging cannot reach older history. |
gid://shopify/Order/123) together with the tags Segmently applied to them and when. This is what makes tag expiry, undo and the audit trail possible.When a relevant event occurs in your store, Shopify sends a webhook. Segmently verifies its signature, records only the delivery identifier for de-duplication, and queues a job. The job fetches the record from Shopify’s Admin API, evaluates your rules against it in memory, calls Shopify’s tag mutations, and discards the record. The same path is used for a backfill, where the records arrive from a Shopify Bulk Operation.
shop/redact request, all data for the store is deleted immediately.customers/data_request — we hold no personal data about a customer, so there is nothing to return. We respond confirming this.customers/redact — we delete the tag bookkeeping tied to that customer’s Shopify ID, and to the orders named in the request.shop/redact — we delete every record belonging to the store.| Provider | Purpose | Location |
|---|---|---|
| Railway Corp. | Application hosting and PostgreSQL database | Amsterdam, Netherlands (EU) |
| Shopify Inc. | Source of all store data; billing | Per Shopify’s own infrastructure |
| Resend / Brevo | Operational email alerts to the merchant only, if enabled. No customer data is included. | EU / US |
Under the GDPR you may request access to, correction of, or deletion of your data, and you may object to or restrict its processing. Write to support@trackwise.studio and we will respond within 30 days. You may also lodge a complaint with your supervisory authority; in Romania this is ANSPDCP.
Application data is hosted in the European Union. Where a sub-processor transfers data outside the EEA, it does so under Standard Contractual Clauses.
Segmently is a business tool and is not directed at children. We do not knowingly process data of anyone under 16.
We will post any change to this policy on this page and update the date above. Material changes are announced inside the app before they take effect.
SC COVERED SRL (Trackwise Studio)
Str. Principală nr. 98, Strei, Hunedoara, Romania
CUI RO47818139
support@trackwise.studio