← Back

Privacy Policy

Last updated: June 2, 2026

ChurnMiser ("we," "our," "us") provides an AI-powered customer retention and churn-prevention platform for Shopify stores. This Privacy Policy explains what data we collect, how we use it, who we share it with, and how merchants and end-customers can exercise their rights. It applies to the ChurnMiser Shopify App, the ChurnMiser marketing site at churnmiser.com, and any related services.

Our role under GDPR and CCPA

For data about end-customers of a Shopify store, the merchant is the data controller and ChurnMiser is the data processor. We process customer data only on the merchant's instructions and in accordance with our Data Processing Agreement. For merchant account data (the people operating the store), ChurnMiser is the data controller.

What we collect

When a merchant installs ChurnMiser, we request access to the following Shopify scopes and receive the corresponding data:

  • Orders and order history (read_orders, read_analytics) — order ID, value, line items, status, fulfillment, returns, refunds. Used to score churn risk and identify recoverable revenue.
  • Customer records (associated with orders) — email, name, order history. We do not request the broader read_customers scope; we only access customer fields exposed alongside orders.
  • Product and inventory (read_products, read_inventory) — used for personalization and margin-aware discount calculations.
  • Fulfillments and returns (read_fulfillments, read_returns) — used as behavioral churn signals.
  • Customer events and pixels (read_customer_events, read_pixels, write_pixels) — behavioral events such as page views, cart updates, and checkout starts. Used to detect cart abandonment and engagement decay.
  • Marketing events (read_marketing_events, write_marketing_events) — used to publish campaign sends back to Shopify so they appear in the merchant's Marketing dashboard.
  • Discounts (read_discounts, write_discounts) — used to create margin-aware discount codes for retention campaigns.
  • Metaobjects (read_metaobjects, write_metaobjects, read_metaobject_definitions, write_metaobject_definitions) — used to persist churn predictions alongside the customer record inside Shopify.
  • Checkouts (read_checkouts, write_orders) — used to detect abandoned checkouts and create recovery offers.

ChurnMiser does not request access to protected customer fields (phone numbers, addresses outside order context, payment methods) or to apps, themes, or storefront code.

How we use this data

  • Compute a churn-risk score for each customer based on order history and behavioral signals.
  • Generate personalized retention email and SMS copy using AWS Bedrock (Anthropic Claude models).
  • Recommend retention campaigns, discount strategies, and segments to re-engage at-risk customers.
  • Send retention messages on the merchant's behalf via the email and SMS providers the merchant has configured.
  • Display analytics and dashboards in the ChurnMiser admin interface.
  • Bill the merchant via Shopify's App Billing API based on the number of customers in their selected retention window and any SMS messages sent.

Third-party services and subprocessors

ChurnMiser uses the following services to operate the platform. Each receives only the data necessary to perform its function.

ServicePurposeData category
ShopifySource platform; billingAll merchant + customer data
AWS Bedrock (Anthropic Claude)AI inference for churn analysis and personalized copyAnonymized order summaries, customer behavior context
AWS Aurora PostgreSQLPrimary database (us-east-1, encrypted at rest)Order + customer records, predictions, settings
AWS LambdaApplication computeTransient processing only
AWS S3File storage (reports, exports)Merchant-uploaded files, generated reports
AWS SESTransactional email (assessment reports, account)Recipient email and message body
AWS SNSSMS message deliveryRecipient phone number and message body
AWS Secrets Manager + KMSCredential encryptionAPI keys, encryption keys
AWS OpenSearch ServerlessVector store for retention knowledge baseInternal product knowledge (no customer data)
AWS CognitoAuthentication for non-Shopify users (e.g., agency portal)Account email + credentials
CloudFront + CloudWatchCDN and observabilityRequest logs, error logs
Optional: SendGrid, Mailchimp, KlaviyoEmail delivery if the merchant connects their own accountRecipient email and message body

All AWS services are operated in the us-east-1 region under Anthropic's and AWS's standard contractual data-protection terms. We do not sell personal information.

Where the data lives and how long we keep it

All merchant and customer data is stored in AWS us-east-1, encrypted at rest using AWS-managed KMS keys and in transit using TLS 1.2 or higher. We retain data for as long as the merchant's subscription is active. When a merchant uninstalls ChurnMiser, we honor Shopify's compliance webhooks: shop/redact within 48 hours of uninstall and customers/redact within 10 days of an end-customer redaction request.

Rights of end-customers (GDPR, CCPA, and similar)

End-customers of a Shopify store may exercise the following rights by contacting the merchant they purchased from. The merchant will route the request to ChurnMiser via Shopify's standard data-request webhook.

  • Request a copy of personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to processing or request restriction
  • Lodge a complaint with your local data protection authority

AI and automated decision-making

ChurnMiser uses AWS Bedrock to run inference on Anthropic Claude models. Customer data we send to Bedrock is processed under AWS's standard terms and is not used to train foundation models. Churn-risk scores are advisory; merchants make the final decision about every campaign and discount offered, and may disable AI features at any time in Settings.

Security

We use HMAC-SHA256 to verify every Shopify webhook, OAuth Token Exchange for embedded-app session authentication, row-level security in Aurora to isolate merchant data, and short-lived IAM credentials for all AWS service calls. Secrets are encrypted with KMS and never written to logs. We follow Shopify's Built for Shopify security requirements.

Children

ChurnMiser is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe we have collected such data, contact us and we will delete it.

Changes to this policy

We update this policy when our practices change. When we make material changes we notify merchants by email and post a notice in the ChurnMiser app at least 30 days before the changes take effect.

Contact

For privacy questions, data requests, or to report a concern, reach out through the app's support channel in your Shopify admin.

© 2026 ChurnMiser. All rights reserved.