Privacy policy
Last updated 4 September 2026
Who we are
Confirmly is a Shopify app that places order confirmation calls to customers on a merchant's behalf. In this policy, “we” means Confirmly, “you” means the merchant who installs the app, and “your customer” means the person who placed the order.
For the personal data of your customers, you are the data controller and we are your processor. We handle that data only to provide the service you installed us for, and only on your instructions.
What we collect from Shopify
When you install the app it requests these Shopify permissions: read_orders, read_customers, write_products, write_metaobjects and write_metaobject_definitions. From those we copy, for each order:
- Order number, total, currency, and payment and fulfilment status
- Whether the order is cash on delivery, and its payment gateways
- The customer's name, phone number and email address
- The delivery address — street lines, city, state, postcode and country
- The line items on the order: title, variant, quantity and price
- Your store's myshopify.com domain and access token
At install we import the last 7 days of orders. After that, orders arrive through Shopify webhooks as they are created, updated, cancelled or deleted.
We copy this data because the calling agent has to say it out loud. It is a cache of what Shopify already holds — Shopify remains the source of truth for your orders.
What we create when a call happens
- Whether the call connected, and how long it lasted
- Whether the name, the order and the address were each confirmed
- Any corrected address the customer gave, in their own words
- Questions the agent could not answer, recorded verbatim
- A transcript of the conversation
- A recording, only if you switch recording on. It is off by default
What we never collect
- Permission to change your orders. The app asks Shopify to read orders and customers. It has no ability to edit, cancel or tag an order, so nothing it records can alter your store.
- Card and payment details. Credits are bought through Shopify's own billing. Your card never reaches our servers.
- Anything from your storefront visitors. The app runs only in your Shopify admin and has no storefront script.
How we use it
We use the data above only to:
- Decide which orders should be called, and when
- Give the calling agent the facts it reads to your customer
- Record what happened on the call and show it to you
- Charge credits for calls that connected
- Investigate faults you report to us
We do not sell personal data. We do not share it with advertisers. We do not use your customers' personal data to train models.
Who else touches the data
- Shopify — the source of your orders and the processor of your credit purchases.
- Our hosting and database provider — stores the app and the order cache.
- A telephony and voice provider — places the call and holds the audio for as long as it takes to produce a transcript. The provider is being onboarded; this page will name it before any live call is placed.
No live customer calls have been placed yet. Until telephony onboarding finishes, the calling path runs against a mock provider that dials nothing.
How long we keep it
30 days. After that a scheduled job removes the personal parts of the order and of every call on it, and keeps the rest so your past months do not silently change.
Removed: customer name, phone number, email, street address and postcode, the line items, the call transcript and any recording.
Kept: the order number, the totals, whether it was COD or prepaid, the dates, the call outcome and how long the call ran, and the city, state and country. None of these identify a person on their own, and they are what a merchant's own reporting is built from.
Orders whose confirmation is still in progress are never touched mid-flight — the retention job only redacts orders whose calling has finished.
When you uninstall the app, we delete your store's data. We also handle Shopify's three privacy webhooks — customers/data_request, customers/redact and shop/redact — so a request made through Shopify reaches us directly.
Your customers' rights
Your customers can ask you for a copy of their data, ask for it to be corrected, or ask for it to be deleted. Forward the request to us at confirmly@frostleaf.co and we will action it within 30 days.
The agent states at the start of every call that it is your store's automated assistant. It never claims to be a person.
Recording and consent
Call recording is off unless you turn it on. Consent rules for recording differ by jurisdiction, and turning recording on is your decision and your responsibility as the controller. Transcripts are stored whether or not recording is on.
Security
Data is encrypted in transit. Access tokens, orders and call results are stored in a managed Postgres database with restricted access. Shopify webhooks are verified with Shopify's HMAC signature, and the call provider's webhook with a shared secret compared in constant time.
Call recordings are referenced by an internal key, never by a public URL. A link to listen is signed on request and expires.
Changes
We will update this page when the app changes, and change the date at the top. Material changes will be emailed to installed merchants.