Effective date: 8 September 2026
Who We Are and What This Policy Covers
Store Huddle is operated by Slurvo FZ-LLC (“Store Huddle,” “we,” “us,” or “our”), located at SFFO0050, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates.
This policy explains how we process personal information to provide the Store Huddle Shopify app, operate our related business and support services, and measure visits and installation activity associated with our Shopify App Store listing. It applies to merchants, their authorized team members and invitees, people who contact us, and people whose information merchants process through the app.
Shopify, advertising platforms, and other independent services have their own privacy policies. This policy describes our processing; it does not replace a merchant’s privacy notice to its employees or customers, or Shopify’s notice for its platform.
Contact us about privacy at support@storehuddle.com.
Our Role and the Merchant’s Role
The merchant generally determines the purposes for processing workspace content and Shopify customer information. For this information, we generally act as a processor or service provider on the merchant’s instructions. Those instructions include the merchant’s use and configuration of the app. If the merchant acts for another organization, that organization may be the controller.
We determine the purposes for our account administration, billing administration, service security, customer support, business operations, legal compliance, and our own product and acquisition analytics. For those activities, we generally act as an independent controller, subject to applicable law and our agreements.
Merchants are responsible for having authority to provide information to Store Huddle, informing affected people, inviting appropriate users, and configuring workspace access. Our Data Processing Addendum describes the terms for processing merchant data on the merchant’s behalf.
Information We Collect and Its Sources
We receive information from Shopify through authorized APIs, authentication flows and webhooks; from merchants and their team members; from people who contact us; and from the operation of the app and its service providers.
Store, Account and Team Information
This includes store names and Shopify domains, installation and connection status, Shopify user identifiers, names, email addresses, store-owner status, invitation details and status, workspace membership, roles, permissions, notification preferences, and activity such as presence and last-active times. We process session and access credentials needed to authenticate users and connect the app to Shopify. Store Huddle does not ask users to provide their Shopify password to us.
Workspace Content
This includes channel and direct messages, replies, forwarded messages and their source references, reactions, mentions, pinned messages, tasks, task assignments and activity, room and category settings, uploaded files and images, file names and metadata, resource attachments, and access-management records. The information may include personal information that users place in messages, tasks, or files.
Shopify Resources and Operational Alerts
Subject to the store’s authorization, Shopify permissions, and available app features, we access and store selected Shopify resource information for search, attachments, refreshes, synchronization, and operational alerts. This processing is not limited to the moment a user attaches a resource.
- Orders and draft orders: identifiers, order names, creation dates, statuses, payment and fulfillment status where available, amounts and currency, subtotals, discounts and discount codes, shipping and tax amounts, outstanding amounts, and selected line items such as item and variant titles, SKUs, quantities, and prices.
- Products and inventory: identifiers, titles, status, vendor information where returned by the API, prices and compare-at prices, thumbnail images and alternative text, and inventory quantities used for low-stock alerts. Information received from Shopify may be stored even when a particular field is not displayed on a card.
- Customers: identifiers, names, email addresses and order counts used for customer search and attached resource summaries.
- Alerts: low-stock information and Shopify-provided high-risk order information. Store Huddle displays Shopify’s risk signals; it does not itself approve payments or make fulfillment decisions.
We use Shopify read permissions for these resource features. The current resource integration does not request full payment-card numbers or customer passwords. Users should not put payment credentials, passwords, or unnecessary sensitive information in workspace content or support messages.
Billing and Usage Administration
We process plan selection and status, trial and subscription information, Shopify billing identifiers and approval status, seat and invitation status, usage calculations and records, and uploaded-file storage usage. Shopify handles approval and collection of app charges through its billing system. We do not collect full payment-card details for Store Huddle subscriptions.
Support and Email Information
We process support requests, conversations, attachments and contact information provided to support, together with technical and account context needed to investigate an issue. For invitations and notifications, we process recipient information, message content, delivery status and provider message identifiers.
Technical and Usage Information
We and our service providers process technical information such as IP addresses, browser and device details, timestamps, session and cookie identifiers, request and error logs, security events, and feature-usage events. The specific analytics information and related controls are described below.
How We Use Information
We use information to:
- Authenticate users and connect their store to Shopify.
- Provide chat, direct messages, replies, forwarding, tasks, files, resource attachments, and workspace search.
- Apply permissions, manage invitations and memberships, and show activity and presence.
- Synchronize supported Shopify resources and show operational alerts.
- Deliver invitations, message and mention notifications, and task notifications according to applicable settings.
- Administer subscriptions, seat usage, storage limits, and retention rules.
- Answer support requests and diagnose technical problems.
- Secure the service, investigate abuse, and meet legal obligations.
- Understand product usage and onboarding, paywall, settings and collaboration flows, and measure which campaigns and listing visits lead to installation or subsequent use.
Where data-protection law requires a legal basis, the applicable basis depends on the activity. These bases may include performing a contract with the relevant individual, legitimate interests in operating and securing our business or supporting merchant accounts, legal obligations, and consent where required. The merchant is responsible for the legal basis for processing it instructs us to carry out on its behalf. Non-essential analytics or advertising measurement is not made strictly necessary merely because it helps our business, and a privacy notice is not a substitute for any required consent.
Workspace Visibility and Sharing by Users
Workspace information is available to people who have the relevant access under the app’s room, category and role rules. Owners and administrators can manage workspace access; direct messages and private spaces have additional access checks. These are application permissions, not end-to-end encryption.
Users with access can forward a message and its attachments into another accessible channel or direct message. That creates a copy visible to the destination’s participants. Permission to open the original source is checked separately. Do not assume that deleting or restricting an original message also recalls every forwarded copy, downloaded file, screenshot, or delivered email.
Our infrastructure processes workspace content to deliver these features. Support and operational access may also be necessary to investigate issues, secure the service, or comply with law. A private room or direct message should not be treated as a promise that content is inaccessible to the service operator in all circumstances.
Google Analytics and Campaign Measurement
We use Google Analytics 4 to understand product usage and acquisition. This includes visits to our Shopify App Store listing, Shopify-provided listing and installation events, and app activity such as onboarding, plan-picker views, upgrade selections, checkout starts, invitations, settings changes, messages and tasks. A checkout-start event records checkout activity, not proof that a subscription was paid.
We use campaign tags, including source, medium, campaign and ad-content values in links, to measure promotions such as Reddit ads. Campaign measurement is different from using personal information to target or retarget people. Our current app configuration disables Google Signals and advertising-personalization signals. We have not integrated a Reddit Pixel or Reddit Conversions API into the app.
Analytics can include pages or screens, event timestamps, device and browser information, approximate location derived by the analytics service, session information, cookie-generated identifiers, and limited feature metadata such as plan, paywall location, room type, attachment count, or task priority. Shopify may send listing and installation information to our analytics property under its own platform implementation.
For app-generated browser events, we use fixed page paths and restricted event fields. We do not intentionally send message text, task descriptions, file contents or names, Shopify customer or order details, names, email addresses, or authentication and invitation tokens to Google Analytics. App-generated page context excludes URL query strings and clears the page referrer. This describes our app instrumentation, not all data Shopify or Google may process independently.
Some message and task events are sent from our server using a pseudonymous identifier derived from the store and member identifiers. The raw store domain and member identifier are not sent as that identifier. Pseudonymous data is not necessarily anonymous. Server events are sent separately from browser analytics and do not depend on a browser analytics cookie.
Google’s processing is described in Google’s Privacy Policy. Analytics information may be processed outside your country, including in the United States.
Cookies, Support Sessions and Current Choices
This website and the app are different. Everything in this section describes the Store Huddle app, which runs inside Shopify admin. The public marketing website at storehuddle.com, including the page you are reading, loads no analytics, advertising or third-party scripts and sets no cookies of its own. Nothing on this website requires a consent choice, because there is nothing non-essential to consent to.
Authentication and preferences. Inside the app, we use Shopify session tokens, session mechanisms and browser storage needed for authentication, security, embedded-app operation and relevant app preferences. Blocking necessary storage may prevent these functions from working.
Google Analytics. Google Analytics uses cookies or similar identifiers for browser measurement. Analytics is not required to send messages or otherwise use the core workspace. You can use browser controls, a suitable content blocker, or Google’s opt-out browser add-on, where supported, to limit browser-based Google Analytics. Availability and effectiveness depend on the browser and platform. These measures do not delete information already collected and do not, by themselves, stop our server-side analytics events.
Crisp support. We use Crisp for in-app support chat. When configured, its script loads with the app. Our integration supplies a support nickname made from the user’s and store’s names, plus the store name and domain, a Shopify admin link, the user’s role, and the Store Huddle plan. Crisp may process IP and browser information and use session cookies to operate and secure support conversations. It receives content and attachments you send in support chat; our integration does not automatically send it the contents of all workspace conversations. See Crisp’s cookie information.
Current consent-control limitation. The current app does not provide an in-app analytics consent or opt-out control before its configured analytics loads. Google Analytics and Crisp can initialize when the app starts, and the limited server analytics described above can be sent independently. Reading this policy or continuing to use the app is not consent to processing for which consent is required. Where applicable law requires prior consent, that requirement still applies; browser blocking is not a substitute for us obtaining it. Contact support@storehuddle.com to raise a privacy concern or request an objection or restriction. A support request is not an automatic, immediate technical switch for tracking.
Email Notifications
We use Resend to deliver transactional invitations and notifications. The provider receives the destination email address, subject and message body, and necessary delivery metadata. Invitations can contain names, store details, assigned roles and invitation links. Message, mention and task notifications can contain message or task text, actor and room names, and links back to the app.
Users can adjust available notification preferences in Store Huddle Settings. Some account, invitation, security, billing or legally required communications may be necessary to administer the service. Sending content by email creates a copy in the recipient’s mailbox; deleting content in Store Huddle does not recall delivered email. Resend’s privacy information describes its own processing.
Service Providers and Other Disclosures
Our providers and recipient categories include:
| Provider or category | Purpose and information involved |
|---|---|
| Shopify | Merchant and staff authentication, authorized resource APIs and webhooks, app billing, and App Store listing and install measurement. |
| Railway and infrastructure providers | Hosting app services, databases, job processing and infrastructure needed to store, transmit and secure service data. |
| S3-compatible file-storage providers | Uploaded files and images, object metadata, and authorized file delivery. |
| Resend | Delivery of invitation and notification emails, including addresses, email content and delivery information. |
| Crisp | Support conversations, submitted support attachments, support-session identifiers, technical data and the account context described above. |
| Google Analytics | Product and acquisition measurement as described above, including restricted browser events and pseudonymous server events. |
| Business email and professional service providers | Correspondence, support, legal advice, accounting and other necessary business administration. |
Providers receive information relevant to their role, not unrestricted access to every category of information. Their processing is subject to the applicable agreements and law; some providers also act independently for their own account administration, security or platform operations. Contact us for information about the providers and processing relevant to your workspace.
We may disclose information to meet legal requirements, respond to valid legal process, protect rights or safety, investigate fraud or security incidents, or in connection with a proposed or completed business transaction, subject to applicable safeguards.
We do not sell personal information. The current Store Huddle app does not use workspace content or Shopify customer details to build third-party advertising audiences or run behavioral retargeting. Measuring campaign performance in Google Analytics does involve the analytics processing explained in this policy.
International Processing
Store Huddle is operated from the United Arab Emirates. We and our providers may process information in other countries, including the United States, whose laws may differ from those where you live. A Shopify store’s location does not, by itself, determine where all Store Huddle data is processed.
International transfers are subject to applicable data-protection requirements. Contact us for information about the destinations and contractual or other safeguards applicable to your data. This policy does not offer a country-specific data-residency guarantee.
Retention and Deletion
Retention depends on the data, workspace plan, whether the installation is active, instructions and requests from the merchant, operational needs, provider arrangements, and applicable legal obligations.
- Free message history: Free workspaces have a rolling 30-day message-history limit. Messages outside that window and files attached to those messages become unavailable under the app’s retention rules and are processed by background cleanup. Cleanup may not delete every underlying copy at the exact moment it becomes unavailable. Moving to Free can cause older history to expire; upgrading later does not restore data already deleted.
- Tasks and other workspace records: Tasks and files attached directly to tasks are not automatically deleted merely because a source message passes the Free message-history cutoff. Membership, invitation, permission, resource, task and operational records have separate retention needs. Removing a teammate revokes access but is not a request to erase all content they previously contributed.
- Paid history: Paid plans do not currently apply the Free plan’s automatic 30-day message-history cutoff. Content remains subject to deletion actions, applicable retention instructions, installation termination and legal requirements. This is not a permanent-backup promise.
- Uninstallation: On receipt of the uninstall notification, we remove the stored Shopify access credentials and app sessions. Uninstallation is not instantaneous deletion from every system. We process Shopify’s shop-redaction requests to remove the associated workspace documents, memberships, stored files, billing records and other scoped data. Limited installation or redaction records, including the store domain, can remain in the current system. Contact us about any remaining personal information.
- Customer requests: We process Shopify’s customer access and redaction requests using the supplied customer and order identifiers and associated resource links. Information independently typed into unlinked free text or uploaded images may require additional identification and review. Please provide enough context to locate it securely; do not send unnecessary sensitive information.
- Support, email and analytics: Provider-held support conversations, delivery records, analytics and operational logs have separate retention and deletion arrangements. They are not all automatically erased by the workspace’s 30-day cleanup or Shopify uninstall webhook. Requests may require separate action with a provider.
- Legal and backup records: Information may be retained where necessary for legal obligations, security, disputes or recordkeeping. Where backup copies exist, deletion from active systems may precede removal through the applicable backup lifecycle. We do not promise an unverified fixed period for every backup, log or provider system.
We cannot erase copies that a recipient independently keeps outside our systems, such as downloaded files, screenshots or delivered emails. Contact us for retention information or a request concerning a specific category of data.
Security
We use measures designed to protect information, including encrypted connections, authenticated sessions, shop-scoped authorization, role and room access checks, time-limited authorized file access, and Shopify webhook-signature verification. Messages and files are processed by our servers and providers; the app does not provide end-to-end encryption.
No service can guarantee absolute security. Contact us promptly if you believe a Store Huddle account or information has been accessed improperly.
Privacy Requests and Rights
Subject to applicable law and relevant exceptions, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information; withdraw consent where consent is the basis for processing; and complain to a data-protection authority. Some jurisdictions also provide rights concerning sale, targeted advertising or certain profiling, authorized agents, appeals, and protection against discrimination for exercising privacy rights.
Send requests to support@storehuddle.com with the subject Privacy request. We may need proportionate information to verify identity and authority and locate the relevant records. We will explain if a request cannot be fulfilled or if an exception applies, and handle requests within applicable deadlines.
For merchant-controlled workspace information, contact the merchant or workspace administrator where appropriate. Shopify customers should normally begin with the merchant that controls their customer relationship; we assist with requests relating to information processed through Store Huddle. You can also contact us directly, and we will help identify the responsible party without limiting your statutory rights.
Objections, consent withdrawals, requests about tracking, or complaints can be sent to the same address. Withdrawing consent does not affect processing carried out lawfully before withdrawal. The absence of an in-app control does not remove your legal rights or our obligations.
Children
Store Huddle is intended for Shopify merchants and their authorized business teams, not children under 18. Contact us if you believe a child has provided personal information in circumstances inconsistent with this purpose.
Changes and Contact
We may update this policy when our service or practices change. The published version will show its effective or last-updated date. We may provide additional notice of material changes, and seek consent where required.
Slurvo FZ-LLC
SFFO0050, Compass Building, Al Shohada Road,
Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
Email: support@storehuddle.com