What information do you collect through Shopify's APIs?
FlashWombat reads store catalog information needed to build and display merchant-selected product destinations.
What information do you collect directly from the merchant?
We collect the QR campaign, supporting campaign-link, QR-placement, custom-domain, destination, and design settings merchants choose to provide. Product details selected from the store catalog may be retained with those campaign settings.
What information do you collect directly from merchants' customers?
QR and supporting campaign-link visits may record campaign context, time, broad location, device, operating system, browser, referrer, and routing outcome. FlashWombat's Shopify pixel uses browser storage for up to one day to associate a recent campaign visit with checkout-started or checkout-completed activity. A temporary random visit credential supports that association; FlashWombat retains only its one-way value and does not retain Shopify's browser client identifier. This is directional marketing attribution and does not identify a customer or prove that a particular order came from one visit or QR scan. A separate one-way correlation value is retained to deduplicate checkout events; the raw checkout token is not retained.
How do you use the information you collect?
We use this information to operate QR campaigns, placements, and supporting links; route shoppers; show campaign analytics; provide merchant-requested automations; prevent abuse; troubleshoot problems; and meet Shopify's platform requirements. We do not sell shopper or merchant information.
For how long do you store or retain the data that you collect?
We retain campaign and analytics data while it is needed to provide the service. After uninstall, Shopify's shop-data redaction process removes shop-owned account, campaign, analytics, and custom-domain data once FlashWombat confirms that the shop has not reinstalled. Merchants may also contact us about a verified deletion request.