Greet Privacy Policy
Last updated: June 2026 · Operated by OY Labs Ltd
1. Who we are
Greet is a Shopify application developed and operated by OY Labs Ltd.
Contact: hello@oylabs.co
Website: https://oylabs.co
2. Information we collect
When a merchant installs Greet, we collect:
- Store information — Shopify store domain, store owner email, and plan details.
- App configuration — onboarding flow settings (steps, questions, design choices), stored as Shopify metaobjects inside the merchant’s own Shopify account.
- Submission analytics — anonymised aggregated data such as popup sessions, completion rates, and step drop-off. We store the Shopify customer ID and timestamp of each submission to power the analytics dashboard.
We do not store customer answers. All question responses are written directly to the customer’s Shopify customer metafields, inside the merchant’s own Shopify account, and never leave Shopify’s infrastructure.
3. How we use information
- To operate and improve the app.
- To display completion analytics to merchants inside the Greet admin.
- To respond to support requests.
We do not sell, rent, or share merchant or customer data with third parties for advertising purposes.
4. Data storage and security
App configuration and submission analytics are stored in a Cloudflare D1 database. Data is encrypted in transit (TLS 1.2+) and at rest. Access is restricted to authorised personnel only.
5. Data retention
Merchant data (flow configuration and analytics) is retained for as long as the app is installed. When a merchant uninstalls Greet, all associated data is deleted from our database within 48 hours. Customer metafield data remains in the merchant’s Shopify account and is subject to Shopify’s own data policies.
6. GDPR and data subject rights
We comply with Shopify’s mandatory GDPR webhook requirements:
- Customer data request — we respond within 30 days. Customer answers live in the merchant’s Shopify account; our analytics records contain only a customer ID and timestamp.
- Customer data erasure — we delete all analytics records linked to a customer ID within 48 hours of a redact request.
- Shop data erasure — we delete all data associated with a shop within 48 hours of an uninstall and redact webhook.
7. Third-party services
Greet runs on Cloudflare Workers for compute and database. We may optionally use a third-party AI API to power the flow-generator feature; prompt text is not stored or logged. No other third-party data processors receive merchant or customer data.
8. Cookies
Greet is an embedded Shopify admin app. We do not set cookies on merchant storefronts. The embedded admin interface uses Shopify’s App Bridge session tokens for authentication.
9. Contact
Questions about this policy or data requests: hello@oylabs.co — OY Labs Ltd.