Last updated: August 7, 2026
1. Scope of this policy
MarketFlow (“MarketFlow”, “we”, “us”) is an application delivered through SHOPLINE. This Privacy Policy explains how information is processed when a merchant installs, configures, or uses MarketFlow and when storefront visitors interact with Market Notice, Country Redirect, and related storefront features.
The developer identity for MarketFlow is the developer shown in the SHOPLINE App Store listing. Merchants remain responsible for their own storefront privacy notices, consent management, and consumer requests as required by applicable law.
2. Information processed through SHOPLINE APIs
- Store identity and authorization: store handle, store domain, granted scopes, authorization token, and token expiry state. Authorization tokens are stored encrypted in our database.
- SHOPLINE Markets information: market IDs, names, primary-market status, currencies, languages, regions, and market storefront URLs returned by SHOPLINE for rule matching and routing.
- App subscription information: subscription ID, plan/product identifiers, plan tier, subscription status, trial/billing period, activation and expiry dates, used to enforce plan entitlements. Payments and card data are handled by SHOPLINE; MarketFlow does not receive full payment card details.
MarketFlow's default authorization scopes do not include customer or order read access, and MarketFlow does not use SHOPLINE Customer APIs to retrieve shopper names, email addresses, phone numbers, postal addresses, or order details.
3. Information merchants provide or generate in MarketFlow
- Market Notice and Country Redirect rule names, target markets, countries/regions, languages, devices, pages, schedules, shopper-facing copy, redirect destinations, and visual settings.
- Admin language, rule priority, preview configuration, and app activation state.
- Support diagnostics generated to troubleshoot the app, such as app version, connection status, rule summaries, and recent storefront checks.
4. Storefront visitor information and browser storage
To match rules, protect redirects, and provide anonymous analytics, MarketFlow may process limited storefront information:
- Two-letter country/region code and current/destination market identifiers.
- Storefront locale, device type, page type, event type, and event time.
- A randomly generated anonymous/pseudonymous visitor ID used to estimate unique visitors. It is stored in browser localStorage and is regenerated after approximately 30 days.
- Notice dismissal preferences, Country Redirect “Stay here” choices, and short-lived redirect-loop state. These values use localStorage or sessionStorage. Their duration depends on merchant settings; a “do not show again” choice may remain until the visitor clears browser storage.
MarketFlow Analytics data models do not store full IP addresses. Standard network information, including IP addresses, may be processed transiently by servers and infrastructure providers for request delivery, security, and rate limiting, but full IP addresses are not written into MarketFlow Notice/Redirect Analytics records.
5. Analytics and diagnostics
Market Notice may record impression, button-click, and dismissal events. Country Redirect may record prompt/banner views, accepted redirects, “Stay here” choices, dismissals, automatic redirects, blocked access, and redirect-loop prevention events.
Diagnostic records may include a request reference, Theme App Extension version, execution stage, country/region, locale, device, page type, and error summary. Page URLs are sanitized before storage so only origin and pathname are retained; query parameters are removed. Merchant-downloadable support reports exclude visitor IDs, full IP addresses, login credentials, and full page URLs.
6. How we use information
- Provide, maintain, and secure MarketFlow's core features.
- Match merchant-configured market notices and country/region redirect rules.
- Synchronize SHOPLINE Markets, subscription status, and app Webhooks.
- Provide aggregated notice and redirect performance analytics.
- Diagnose Theme App Extension, rule configuration, and storefront issues.
- Prevent abuse, duplicate requests, invalid previews, and redirect loops.
- Comply with applicable law, platform requirements, and deletion requests.
We do not sell merchant or storefront visitor data, and we do not use this information for unrelated third-party advertising targeting.
7. Data retention
- Analytics events: the service is currently configured to retain them for up to approximately 180 days, after which database TTL cleanup removes them.
- Storefront diagnostics: currently retained for up to approximately 14 days, then automatically removed.
- Store, rule, and subscription records: retained as needed to provide the service, maintain entitlements, resolve disputes, or satisfy compliance obligations.
- App uninstall: when an uninstall notification is received, the store access token is removed and normal app access stops. Some configuration and historical records may remain until SHOPLINE sends the subsequent store data deletion request.
- Store data deletion: after a valid merchants/redact Webhook, MarketFlow deletes the related Store, rules, Analytics, diagnostics, subscriptions, and Webhook receipt data.
8. Service providers and international processing
We process information with platform and infrastructure providers only as needed to operate MarketFlow, including SHOPLINE for authorization, Markets, subscriptions and billing; application hosting and database providers; and, when location recognition is enabled, an edge-network provider. These providers may process information in different countries or regions, so information may be transferred outside the merchant's or visitor's location.
We do not disclose merchant or visitor information to third parties except as needed to provide MarketFlow, comply with law, protect rights, or where otherwise lawfully authorized.
9. Security
MarketFlow uses controls such as OAuth authorization, encryption of stored access tokens, signed sessions, Webhook HMAC validation, short-lived runtime tokens, origin validation, rate limiting, and data minimization. No internet service can guarantee absolute security, and we continue to maintain and improve these controls.
10. Choices and data rights
Depending on applicable law, merchants or individuals may have rights to access, correct, delete, restrict, object to processing, or request portability of applicable personal information. Storefront visitors can also clear localStorage/sessionStorage to remove MarketFlow browser preferences and anonymous visitor identifiers.
For a request relating to a SHOPLINE store, provide enough information to identify the store. We may need to verify that the requester is authorized to act for that store.
11. Children
MarketFlow is a B2B application for SHOPLINE merchants and is not designed specifically for children. We do not intentionally use MarketFlow to collect customer-profile information such as children's names or contact details.
12. Changes to this policy
We may update this policy as MarketFlow features, legal requirements, or service providers change. The current version will be published on this page with a revised “Last updated” date.
13. Contact us
For questions about this policy, data access, or deletion, email xiangwandi@outlook.com.