Privacy policy
What FairRev does with personal data, who is responsible for which part, how long we keep it and where it is stored.
Version 1.2. Effective date: 3 October 2026.
This policy explains what FairRev does with personal data. FairRev is operated by Doment Digital FZE LLC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, licence 4431328.01.
Contact: [email protected]
1. Two different roles, and why it matters
We handle two kinds of personal data and our role is different for each.
About the merchant. When you install FairRev we hold your name, your email address, your shop domain and your billing history. For this we are the controller. We decide what to collect and why, and this policy is our explanation to you.
About your shoppers. When a shopper sees or accepts an offer on your store, we record what happened. For this the merchant is the controller and we are the processor. We act on the merchant's instructions and the data processing agreement at https://fairrev.com/dpa governs it. If you are a shopper reading this, the store you were buying from decides what happens to your data, and we handle it for them.
2. What we collect
From the merchant
- Shop domain, shop name, contact email, country, currency, timezone and Shopify plan.
- The Shopify access token for your shop, encrypted.
- Your settings, your offers and their history.
- Your billing history: what was charged, when, and the reason.
- Support messages you send us.
- A record of which version of these documents you accepted, when, from which address, and which staff account clicked accept. We keep it as evidence that you agreed to the version that was in force, and we cannot change it afterwards.
From your store, about orders
- Order identifiers, line items, quantities, prices, currencies, discounts and refunds.
- The payment methods used on an order, which we need to know whether a post purchase offer can be shown at all.
- Whether an order came from the online store, point of sale, an import or a draft, which is how we exclude orders we must not bill you for.
We do not request access to customer records. We do not ask Shopify for the read_customers
permission, so we do not receive your customers' names, addresses, email addresses or phone numbers.
Where an order payload contains such fields, we discard them on receipt, before anything is stored
or written to a log. We keep one identifier: the customer number Shopify itself assigns inside your
store. It is not a name, an address, an email address or a telephone number, and it means nothing
outside your store.
From shoppers, on the storefront
- A rotating, random session identifier. It is not linked to a name, an email address or an account.
- Which offer was shown, clicked, accepted or declined, and when.
- The cart token, so an offer can be connected to the order it produced.
- Page type, locale and text direction, and coarse device type.
We do not use third party advertising trackers in the widget. We do not build shopper profiles across different merchants' stores. A shopper who visits two shops that both use FairRev is two unconnected records to us.
3. Why we use it
| What | Why |
|---|---|
| Shop and contact details | To run the app for you and to reach you about it |
| Access token | To read your catalogue and orders, and to write the tags and products you ask for |
| Order data | To work out which revenue our offers produced, and to exclude everything else |
| Billing history | To charge you correctly and to prove why a charge was made |
| Shopper events | To measure whether an offer worked, and to show you what it earned |
| Support messages | To answer you |
Where the UK or EU GDPR applies to our handling of merchant data, our legal basis is the performance of our contract with you, and our legitimate interest in keeping the service secure and working. We do not rely on consent for any of it, and we do not use your data for marketing to your customers.
4. What we never do
- We never sell personal data.
- We never share one merchant's data with another, and we never use it to give another merchant an advantage.
- We never use your customers' data to market anything to them.
- We never place a third party advertising pixel on your storefront through our widget.
5. Who else touches it
We use a small number of suppliers. Each is bound to protect the data and may only use it to provide their service to us.
| Supplier | What for | Where |
|---|---|---|
| Hostinger International Limited | Servers, database and background jobs | Frankfurt, Germany |
| Cloudflare, Inc. | Serving the widget and offer configuration | Global edge |
| Shopify | The platform the app runs on | As set out in Shopify's own policy |
| OpenAI OpCo, LLC | Suggesting wording for offers and summarising your figures, only when you use those features | United States |
The current list is always at https://fairrev.com/subprocessors. We will give you thirty days' notice before adding a new one, so that you can object or uninstall.
OpenAI receives no personal data. It writes two things for you, and only when you use them. Both are off until you turn them on in the app's settings. When you ask for suggested wording for an offer, FairRev sends the names of the products in that offer, the type of the product it appears beside, the discount and your store's language. For the short summary on your dashboard, it sends the period's counts and totals and the reasons orders were not counted. Nothing about a shopper is ever sent: no order number, no customer number, no session or cart identifier. Every request is checked for anything of that kind before it leaves, and a request that has any is not sent. OpenAI does not use what we send to train its models. It may keep it for up to 30 days to check for abuse, and then deletes it.
Because none of this is personal data, OpenAI is not a sub-processor under our data processing agreement and is not listed there. It is listed here so that you know where your product names go.
6. Where the data goes
The data is stored in Germany. Our servers, our database and our background jobs run in Frankfurt, which is inside the European Union, and nothing is copied out of there in the ordinary running of the app. The one exception holds no personal data: when you use the AI features described in section 5, product names, discounts and totals go to OpenAI in the United States.
Our company is in the United Arab Emirates, so the people who operate and support the service reach that data from there. The United Arab Emirates is not covered by a United Kingdom or European Union adequacy decision, so that access relies on standard contractual clauses and, for the United Kingdom, the international data transfer addendum. Those are part of the data processing agreement at https://fairrev.com/dpa.
7. How long we keep it
| What | How long |
|---|---|
| Shopper event records | 13 months, then deleted a whole month at a time by a job that runs daily |
| Order and attribution records | While you are a merchant, then erased when Shopify tells us to erase the shop, which it does 48 hours after you uninstall |
| Billing ledger | Kept for as long as the law requires us to keep financial records |
| Access token | Deleted when you uninstall |
| Support messages | 24 months |
When Shopify tells us a shop or a customer must be erased, we act on it. Shopify sends three requests of this kind and we handle all of them: a request to see a customer's data, a request to erase a customer's data, and a request to erase a shop's data after uninstall. We complete each one within the period Shopify requires.
The billing ledger is the one thing we do not delete on request, because it is the record of money that changed hands and we are required to keep it. We remove or anonymise anything in it that is not needed for that purpose.
8. Security
- Access tokens are encrypted before they are stored, and the key is never in the database.
- All traffic uses HTTPS.
- Access to production systems is limited to people who need it, and those people use multi factor authentication.
- Backups are taken daily, stored off the server, and tested by restoring them.
- We keep an append only record of changes that affect a merchant's charges or what their shoppers see.
If a breach happens that puts personal data at risk, we will tell affected merchants without undue delay and within seventy two hours of becoming aware of it, with what we know and what we are doing.
9. Your rights
If the UK or EU GDPR applies to you, you may ask us for a copy of your personal data, ask us to correct or delete it, object to some uses, or ask us to hand it to someone else. Write to [email protected] and we will reply within thirty days.
If you are in California, you may ask what we collect, ask us to delete it and ask us not to sell or share it. We do not sell or share personal data, so there is nothing to opt out of, but you may still ask.
If you are a shopper, ask the store you bought from. They decide, and we will help them answer you.
You may complain to your data protection authority.
10. Where FairRev is available
FairRev cannot be installed by stores in the United Kingdom or the European Economic Area. A shop registered in one of those countries is refused at install, before anything about it is stored.
We are telling you the reason rather than calling it a technical limit. Both the UK GDPR and the EU GDPR require a company with no establishment there, which offers services to people there, to appoint a local representative and to print that representative's name and address in this policy. We have not appointed one. The alternatives were to publish a policy naming nobody, or to claim a market we would then serve anyway, and we would rather close the market and say so.
When a representative is appointed, this section will name them, those countries will reopen, and we will say so here before it happens.
11. Children
FairRev is sold to businesses and is not directed at children. We do not knowingly collect data about anyone under sixteen.
12. Changes
If we change this policy in a way that matters, we will tell you at least thirty days before it takes effect and ask you to accept it in the app. Every version is kept and dated at https://fairrev.com/legal-archive.
Doment Digital FZE LLC Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates Licence 4431328.01 [email protected]