CredooFy

Privacy policy

Last updated 10 October 2026.

CredooFy is a reviews app for Shopify stores. This page says what it stores, why, where it lives, who else can see it, and how to have it deleted. It describes what the software actually does.

Who is responsible for what

When a shopper leaves a review, the store they bought from decides what is collected and what is published. That store is the data controller. CredooFy processes that data on the store's instructions, as a processor.

For the store owner's own account — the shop domain, settings and billing status — CredooFy is the controller.

Contact for anything on this page: privacy@credoofy.com.

What is stored

From the store

  • The myshopify domain and the access token Shopify issues.
  • Widget and email settings: colours, layout choices, the wording of review requests.
  • Product identifiers and titles, so a review can be attached to the right product and a rating written back to it.
  • Provider keys for AI drafting, if the merchant adds any. Encrypted at rest with AES-256-GCM.
  • API keys for the read-only API, stored as a SHA-256 hash plus the first twelve characters so a key can be recognised in a list but never read back.

From shoppers

  • The review itself: rating, headline, body, and any photos or video attached.
  • The reviewer's name as they typed it, and their email address. The name is published; the email is not.
  • Country, where Shopify provides it, so a review can say where it came from.
  • The order number the review relates to, which is what makes a verified-buyer badge honest.
  • If someone reports a review, the reason and, optionally, an address so the shop can reply.
  • If someone unsubscribes, their address and the reason, on a do-not-email list. See below — this is the one record that survives a deletion request.

Permissions the app asks Shopify for

write_products to write rating metafields back to products, write_files to store review photos in the store's own Shopify Files, read_orders and read_customers to tell whether a reviewer actually bought the thing they are reviewing.

Where photos and video live

In the store's own Shopify Files, not on CredooFy's servers. A video upload goes from the shopper's browser straight to Shopify and never passes through this app at all. When a review is deleted, the file goes with it.

Email

Review requests are sent to shoppers on the store's behalf, after an order is fulfilled, in the merchant's own wording. Every message carries a working unsubscribe link and the one-click unsubscribe header mail clients use (RFC 8058). An address that unsubscribes is never written to again by any store using this app — see the do-not-email list.

No review-request email has been sent from this app yet. Before the first one is, the sending provider will be named in the sub-processor list below.

Artificial intelligence

A merchant can connect their own account with an AI provider to have replies drafted. When they do, the review text and the product name are sent to the provider they chose, under their account, billed to them. CredooFy does not train anything on review data and does not run a model of its own.

AI drafts replies to reviews. It does not write reviews, and there is no feature anywhere in the app that would let it.

Cookies and tracking

The storefront widgets set no cookies and run no analytics or advertising scripts. They use one browser session entry, credoofy-popup, to remember that a visitor closed the review pop-up so it does not reappear on the next page. It is cleared when the tab closes.

Who else sees the data

  • Shopify — the platform the app runs on, and where photos and video are stored.
  • Railway — hosting for the application server.
  • Neon — the managed PostgreSQL database.
  • The merchant's own AI provider, if they connect one, for the review text being replied to.
  • An email sending provider — to be named here before the first review request is sent.

Nothing is sold, and nothing is shared with advertisers or data brokers.

Deleting things

A shopper asks to be forgotten

Shopify sends the request and the app acts on it automatically. The review text stays, because it is the merchant's published content and a product's rating should not silently change — but the person comes off it. The name becomes "Anonymous", and the email address, country, order number and verified status are cleared. Any review request still waiting to be sent to that address is deleted. If they reported a review, the report stays and the address on it is removed.

The one request that is refused

The do-not-email list is kept. Deleting someone's row would erase the record that they asked not to be contacted, and the next order they placed with that shop would start mailing them again — which is exactly the harm they were protecting themselves from. Honouring an opt-out outlasts a request to forget the opt-out. The row holds nothing but the address and the reason, and it is deleted when the shop itself is.

A shopper asks for a copy

Shopify sends that request too, and it is answered with everything held against that address.

A store uninstalls

Shopify sends a shop-redaction request on its own schedule, and everything belonging to that shop is deleted in one transaction: reviews, requests, reports, the do-not-email list, AI keys, AI drafts, API keys, product ratings, settings and the session. There is no archive and no copy kept.

Export first if you want your reviews. The export includes the original photo and video files, and is available on every plan.

How long things are kept

Reviews are kept until the merchant deletes them or the shop is redacted. Review requests are kept while they are pending and for as long as they are useful for not asking the same person twice. Everything else goes with the shop.

Where the data is

The application server runs in Railway's Southeast Asia region and the database is a managed Neon PostgreSQL instance. Photos and video are held by Shopify, in whichever region Shopify holds that store's files.

Security

Everything is served over HTTPS. AI provider keys are encrypted with AES-256-GCM, with a fresh nonce per encryption, so a tampered row fails to open rather than decrypting to something wrong. API keys are only ever stored hashed. Storefront requests arrive through Shopify's app proxy and their signature is checked.

Children

CredooFy is a tool for merchants and is not directed at children. It does not knowingly collect anything from anyone under 16.

Changes

When this policy changes, the date at the top changes with it. Anything that materially affects shoppers — a new sub-processor, a new category of data — will be described here before it starts.

Contact

privacy@credoofy.com for anything on this page, including a request about your own data. If a review about you is on a store using CredooFy, the store is the right first contact, and there is a report link beside every review.