Skip to content
Confirmly

Privacy policy

Last updated 4 September 2026

A note before you rely on this. This policy describes how Confirmly is built to handle data, and it is accurate to the app's design. It has not yet been reviewed by a lawyer. Have it reviewed against Indian data-protection law and Shopify's Protected Customer Data requirements before the app goes on sale.

Who we are

Confirmly is a Shopify app that places order confirmation calls to customers on a merchant's behalf. In this policy, “we” means Confirmly, “you” means the merchant who installs the app, and “your customer” means the person who placed the order.

For the personal data of your customers, you are the data controller and we are your processor. We handle that data only to provide the service you installed us for, and only on your instructions.

What we collect from Shopify

When you install the app it requests these Shopify permissions: read_orders, read_customers, write_products, write_metaobjects and write_metaobject_definitions. From those we copy, for each order:

  • Order number, total, currency, and payment and fulfilment status
  • Whether the order is cash on delivery, and its payment gateways
  • The customer's name, phone number and email address
  • The delivery address — street lines, city, state, postcode and country
  • The line items on the order: title, variant, quantity and price
  • Your store's myshopify.com domain and access token

At install we import the last 7 days of orders. After that, orders arrive through Shopify webhooks as they are created, updated, cancelled or deleted.

We copy this data because the calling agent has to say it out loud. It is a cache of what Shopify already holds — Shopify remains the source of truth for your orders.

What we create when a call happens

  • Whether the call connected, and how long it lasted
  • Whether the name, the order and the address were each confirmed
  • Any corrected address the customer gave, in their own words
  • Questions the agent could not answer, recorded verbatim
  • A transcript of the conversation
  • A recording, only if you switch recording on. It is off by default

What we never collect

  • Permission to change your orders. The app asks Shopify to read orders and customers. It has no ability to edit, cancel or tag an order, so nothing it records can alter your store.
  • Card and payment details. Credits are bought through Shopify's own billing. Your card never reaches our servers.
  • Anything from your storefront visitors. The app runs only in your Shopify admin and has no storefront script.

How we use it

We use the data above only to:

  • Decide which orders should be called, and when
  • Give the calling agent the facts it reads to your customer
  • Record what happened on the call and show it to you
  • Charge credits for calls that connected
  • Investigate faults you report to us

We do not sell personal data. We do not share it with advertisers. We do not use your customers' personal data to train models.

Who else touches the data

  • Shopify — the source of your orders and the processor of your credit purchases.
  • Our hosting and database provider — stores the app and the order cache.
  • A telephony and voice provider — places the call and holds the audio for as long as it takes to produce a transcript. The provider is being onboarded; this page will name it before any live call is placed.

No live customer calls have been placed yet. Until telephony onboarding finishes, the calling path runs against a mock provider that dials nothing.

How long we keep it

30 days. After that a scheduled job removes the personal parts of the order and of every call on it, and keeps the rest so your past months do not silently change.

Removed: customer name, phone number, email, street address and postcode, the line items, the call transcript and any recording.

Kept: the order number, the totals, whether it was COD or prepaid, the dates, the call outcome and how long the call ran, and the city, state and country. None of these identify a person on their own, and they are what a merchant's own reporting is built from.

Orders whose confirmation is still in progress are never touched mid-flight — the retention job only redacts orders whose calling has finished.

When you uninstall the app, we delete your store's data. We also handle Shopify's three privacy webhooks — customers/data_request, customers/redact and shop/redact — so a request made through Shopify reaches us directly.

Your customers' rights

Your customers can ask you for a copy of their data, ask for it to be corrected, or ask for it to be deleted. Forward the request to us at confirmly@frostleaf.co and we will action it within 30 days.

The agent states at the start of every call that it is your store's automated assistant. It never claims to be a person.

Recording and consent

Call recording is off unless you turn it on. Consent rules for recording differ by jurisdiction, and turning recording on is your decision and your responsibility as the controller. Transcripts are stored whether or not recording is on.

Security

Data is encrypted in transit. Access tokens, orders and call results are stored in a managed Postgres database with restricted access. Shopify webhooks are verified with Shopify's HMAC signature, and the call provider's webhook with a shared secret compared in constant time.

Call recordings are referenced by an internal key, never by a public URL. A link to listen is signed on request and expires.

Changes

We will update this page when the app changes, and change the date at the top. Material changes will be emailed to installed merchants.

Contact

confirmly@frostleaf.co