Privacy Policy
Last updated: June 2, 2026
ChurnMiser ("we," "our," "us") provides an AI-powered customer retention and churn-prevention platform for Shopify stores. This Privacy Policy explains what data we collect, how we use it, who we share it with, and how merchants and end-customers can exercise their rights. It applies to the ChurnMiser Shopify App, the ChurnMiser marketing site at churnmiser.com, and any related services.
Our role under GDPR and CCPA
For data about end-customers of a Shopify store, the merchant is the data controller and ChurnMiser is the data processor. We process customer data only on the merchant's instructions and in accordance with our Data Processing Agreement. For merchant account data (the people operating the store), ChurnMiser is the data controller.
What we collect
When a merchant installs ChurnMiser, we request access to the following Shopify scopes and receive the corresponding data:
- Orders and order history (read_orders, read_analytics) — order ID, value, line items, status, fulfillment, returns, refunds. Used to score churn risk and identify recoverable revenue.
- Customer records (associated with orders) — email, name, order history. We do not request the broader read_customers scope; we only access customer fields exposed alongside orders.
- Product and inventory (read_products, read_inventory) — used for personalization and margin-aware discount calculations.
- Fulfillments and returns (read_fulfillments, read_returns) — used as behavioral churn signals.
- Customer events and pixels (read_customer_events, read_pixels, write_pixels) — behavioral events such as page views, cart updates, and checkout starts. Used to detect cart abandonment and engagement decay.
- Marketing events (read_marketing_events, write_marketing_events) — used to publish campaign sends back to Shopify so they appear in the merchant's Marketing dashboard.
- Discounts (read_discounts, write_discounts) — used to create margin-aware discount codes for retention campaigns.
- Metaobjects (read_metaobjects, write_metaobjects, read_metaobject_definitions, write_metaobject_definitions) — used to persist churn predictions alongside the customer record inside Shopify.
- Checkouts (read_checkouts, write_orders) — used to detect abandoned checkouts and create recovery offers.
ChurnMiser does not request access to protected customer fields (phone numbers, addresses outside order context, payment methods) or to apps, themes, or storefront code.
How we use this data
- Compute a churn-risk score for each customer based on order history and behavioral signals.
- Generate personalized retention email and SMS copy using AWS Bedrock (Anthropic Claude models).
- Recommend retention campaigns, discount strategies, and segments to re-engage at-risk customers.
- Send retention messages on the merchant's behalf via the email and SMS providers the merchant has configured.
- Display analytics and dashboards in the ChurnMiser admin interface.
- Bill the merchant via Shopify's App Billing API based on the number of customers in their selected retention window and any SMS messages sent.
Third-party services and subprocessors
ChurnMiser uses the following services to operate the platform. Each receives only the data necessary to perform its function.
| Service | Purpose | Data category |
|---|---|---|
| Shopify | Source platform; billing | All merchant + customer data |
| AWS Bedrock (Anthropic Claude) | AI inference for churn analysis and personalized copy | Anonymized order summaries, customer behavior context |
| AWS Aurora PostgreSQL | Primary database (us-east-1, encrypted at rest) | Order + customer records, predictions, settings |
| AWS Lambda | Application compute | Transient processing only |
| AWS S3 | File storage (reports, exports) | Merchant-uploaded files, generated reports |
| AWS SES | Transactional email (assessment reports, account) | Recipient email and message body |
| AWS SNS | SMS message delivery | Recipient phone number and message body |
| AWS Secrets Manager + KMS | Credential encryption | API keys, encryption keys |
| AWS OpenSearch Serverless | Vector store for retention knowledge base | Internal product knowledge (no customer data) |
| AWS Cognito | Authentication for non-Shopify users (e.g., agency portal) | Account email + credentials |
| CloudFront + CloudWatch | CDN and observability | Request logs, error logs |
| Optional: SendGrid, Mailchimp, Klaviyo | Email delivery if the merchant connects their own account | Recipient email and message body |
All AWS services are operated in the us-east-1 region under Anthropic's and AWS's standard contractual data-protection terms. We do not sell personal information.
Where the data lives and how long we keep it
All merchant and customer data is stored in AWS us-east-1, encrypted at rest using AWS-managed KMS keys and in transit using TLS 1.2 or higher. We retain data for as long as the merchant's subscription is active. When a merchant uninstalls ChurnMiser, we honor Shopify's compliance webhooks: shop/redact within 48 hours of uninstall and customers/redact within 10 days of an end-customer redaction request.
Rights of end-customers (GDPR, CCPA, and similar)
End-customers of a Shopify store may exercise the following rights by contacting the merchant they purchased from. The merchant will route the request to ChurnMiser via Shopify's standard data-request webhook.
- Request a copy of personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to processing or request restriction
- Lodge a complaint with your local data protection authority
AI and automated decision-making
ChurnMiser uses AWS Bedrock to run inference on Anthropic Claude models. Customer data we send to Bedrock is processed under AWS's standard terms and is not used to train foundation models. Churn-risk scores are advisory; merchants make the final decision about every campaign and discount offered, and may disable AI features at any time in Settings.
Security
We use HMAC-SHA256 to verify every Shopify webhook, OAuth Token Exchange for embedded-app session authentication, row-level security in Aurora to isolate merchant data, and short-lived IAM credentials for all AWS service calls. Secrets are encrypted with KMS and never written to logs. We follow Shopify's Built for Shopify security requirements.
Children
ChurnMiser is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe we have collected such data, contact us and we will delete it.
Changes to this policy
We update this policy when our practices change. When we make material changes we notify merchants by email and post a notice in the ChurnMiser app at least 30 days before the changes take effect.
Contact
For privacy questions, data requests, or to report a concern, reach out through the app's support channel in your Shopify admin.