Privacy
Last updated 1 September 2026
Atrox - Mobile App Builder turns a Shopify store into a native mobile app. This policy explains exactly what data the app reads from your store, what we store on our servers, how long we keep it, and how we delete it. It covers two groups of people: you, the merchant who installs Atrox - Mobile App Builder, and the shoppers who use the mobile app you publish.
Who controls your data
Atrox - Mobile App Builder is operated by ATROX TECHNOLOGY, Unit 519, JMD Megapolis, Badshahpur Sohna Road, Sector 48, Gurugram, Haryana 122018, India.
For data about you and your store, ATROX TECHNOLOGY is the controller. For data about shoppers who use the mobile app you publish, you are the controller and ATROX TECHNOLOGY is your processor: we handle shopper data on your instructions, for the purpose of running your app, and for nothing else. We do not sell data, we do not share it with advertising networks, and we do not use it to train machine learning models.
Atrox - Mobile App Builder is an independent product and is not affiliated with or endorsed by Shopify Inc.
What we read from your Shopify store
When you install Atrox - Mobile App Builder, Shopify asks you to approve a set of access scopes. We use the resulting access token to read from the Shopify Admin API and to receive webhooks. We read the following, and we read it only to build and run your mobile app.
- Store profile: shop domain, store name, currency, and the plan you are on
- Products, variants, options, prices, inventory status, and product images
- Collections and the products inside them
- Orders, including order number, total, currency, financial and fulfillment status, and a short preview of line items
- Customers, including name, email address, phone number, and default address
- Fulfillment events, so the app can tell a shopper their order shipped
- Your app subscription status, so we know which plan features to enable
What we store about you and your store
We keep a copy of the store data above in our own database so the mobile app loads quickly and works when the Shopify Admin API is slow or unavailable. Alongside it we store the things you create inside Atrox - Mobile App Builder.
- Your Atrox - Mobile App Builder merchant account: email address, name, and, if you sign in with a password rather than through Shopify, a hashed password
- Your Shopify access tokens, used to call the Shopify API on your behalf
- Your app design: screens, blocks, themes, colors, typography, navigation, and feature settings
- Images and other media you upload for your app
- Push notification campaigns you compose and the delivery counts for each send
- Support tickets you open with us, including the message thread
- Android signing keys generated for your published app, encrypted at rest
- Build records and app binaries produced for you
Shopper data in the app you publish
The mobile app you publish collects data from shoppers who use it. That data flows to our servers so the app can function, and it stays scoped to your store: no other merchant can see it.
- Account details for a shopper who signs in: name, email address, phone number, and address, synced from your Shopify customer record
- A session token that keeps a shopper signed in, valid for one hour, with a refresh token valid for seven days
- Cart contents, saved so a shopper can return to an unfinished cart
- Wishlist items
- A device push token, if the shopper allows notifications, so your campaigns and order updates can reach that device
- Notification history, so the shopper can reopen a message from the in-app inbox
- Support tickets a shopper raises through the app, including their email address and the message thread
- Product views, searches with the keyword typed, and campaign opens, recorded against an anonymous session identifier so you can see what is popular in your app
- Crash reports, including the device model, operating system version, and app version at the moment of the crash
What we never collect
Some data never reaches our servers, by design.
- Payment card numbers, bank details, and any other payment credentials. Checkout runs inside Shopify, and card data goes from the shopper to Shopify and its payment providers, never through Atrox - Mobile App Builder
- Shopify account passwords
- Precise device location
- Contacts, photo libraries, microphone, or camera content, except an image a shopper deliberately attaches
- Advertising identifiers, and we run no third party advertising or tracking SDKs in the published app
Why we process this data
Each purpose below is tied to the legal basis we rely on under the GDPR. Where you are the controller, these bases are the ones you rely on and we act on your documented instructions.
- Running the service you paid for, which covers building your app, serving its content, syncing your catalog, signing in shoppers, and processing carts and wishlists. Legal basis: performance of a contract
- Sending transactional notifications about an order, such as confirmation, shipment, and delivery. Legal basis: performance of a contract between the shopper and your store
- Sending marketing campaign notifications. Legal basis: the shopper consent captured by the operating system permission prompt, which a shopper withdraws at any time in device settings
- Product analytics inside your app, meaning views, searches, and campaign opens, so you can improve the app. Legal basis: legitimate interests, balanced by the fact that these events carry no name, email address, or device identifier
- Crash reporting and abuse prevention, including rate limiting on support tickets. Legal basis: legitimate interests in keeping the service secure and working
- Billing and account administration. Legal basis: performance of a contract and compliance with a legal obligation
Subprocessors
We use the following providers to run Atrox - Mobile App Builder. Each one is bound by a data processing agreement and receives only the data it needs for its function. We update this list before a new subprocessor starts handling data.
| Subprocessor | What it processes | Where |
|---|---|---|
| Shopify Inc. | Source of your store, catalog, order, and customer data, and the billing channel for your subscription | Canada and United States |
| Hetzner Online GmbH | Application servers and the primary PostgreSQL database holding everything described in this policy | Germany |
| Amazon Web Services (S3) | Uploaded images, app icons, and other media assets | European Union |
| Redis | Job queues, rate limiting counters, and short lived cache entries, self hosted alongside the application | Germany |
| Google Firebase Cloud Messaging | Delivers push notifications. Receives the device push token and the notification title and body | United States |
| Expo (650 Industries, Inc.) | Delivers over the air updates to your published app. Receives no merchant or shopper personal data | United States |
| Sentry (Functional Software, Inc.) | Crash and error reports, including device model, operating system version, and app version | United States |
| Amazon Web Services (SES) | Sends support and notification emails. Receives the recipient email address and the message body | European Union |
Where your data is stored and moved
The primary database and application servers sit in Germany, on Hetzner infrastructure. Uploaded media sits in European Union object storage.
Some subprocessors in the table above operate outside the European Economic Area, and our own engineering team works from India. Those transfers rely on the European Commission standard contractual clauses, together with encryption in transit over TLS and access limited to the engineers who need it.
How long we keep data
These are the retention periods we hold ourselves to. Where a shorter period is set by a deletion request, the deletion request wins.
- Your store data, app design, catalog copy, customer records, orders, carts, wishlists, and analytics events: kept while Atrox - Mobile App Builder is installed, then deleted on receipt of the Shopify uninstall webhook and in every case within 48 hours of uninstall
- Uploaded media files in object storage: deleted within 30 days of uninstall
- Shopper sign in sessions: access tokens expire after one hour, refresh tokens after seven days
- Device push tokens: deleted when the shopper signs out, when the operating system reports the token is no longer registered, or on uninstall of your app
- Analytics events for product views, searches, and campaign opens: kept for 24 months, then deleted
- Support ticket threads, both yours and shoppers: kept for 24 months after the ticket closes
- Android signing keys for a published app: kept for as long as the app exists in the store, because losing the key makes further updates impossible, and deleted on your written request
- Billing and invoice records: kept for 7 years, as tax law requires
- Server and audit logs: kept for 90 days
Shopify compliance webhooks
Shopify sends three mandatory privacy webhooks. Every request is verified with an HMAC signature and an unsigned request is rejected. Here is what each one triggers on our side.
- customers/data_request: a shopper has asked you for their data. We open an internal ticket containing the shop, the customer reference, and the orders requested, and we return the stored data to you within 30 days so you can pass it on
- customers/redact: a shopper has asked to be erased. We delete their customer record, sign in tokens, device push tokens, and notification history outright, and we strip their identity from carts, orders, notification logs, and support threads, keeping only the anonymous record needed for your order statistics. This runs on receipt and completes within 30 days at the latest
- shop/redact: Shopify sends this 48 hours after you uninstall. We already delete your store in full when the uninstall webhook arrives, so this handler confirms nothing is left and purges anything that survived
Your rights and shopper rights
If you are in the European Economic Area or the United Kingdom, you have the right to access your data, correct it, erase it, restrict or object to its processing, and receive it in a portable format. If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing, and we sell and share nothing.
To exercise a right over your own merchant data, write to [email protected] and we respond within 30 days. Uninstalling Atrox - Mobile App Builder from your Shopify admin deletes your store data on its own.
A shopper who wants their data from the app you published should contact you, because you are the controller of that data. Route the request into Shopify, which sends us the customers/redact or customers/data_request webhook described above, and we act on it. A shopper who writes to [email protected] directly gets forwarded to you.
You also have the right to complain to your local data protection authority.
How we protect data
All traffic runs over TLS. Shopify access tokens and Android signing keys are encrypted at rest with a key held outside the database. Merchant passwords, where a password is used at all, are stored as salted hashes and never in plain text. Access to production systems is limited to the engineers who operate the service, and every administrative action taken on a store is written to an audit log.
We describe the controls we actually run. We hold no SOC 2, ISO 27001, or PCI certification, and we do not claim one.
Children
Atrox - Mobile App Builder is a business tool sold to merchants, and the apps built with it are not directed at children under 13, or under 16 where local law sets that age. We do not knowingly collect data from a child. If you believe a child has used an app built with Atrox - Mobile App Builder and given us data, write to [email protected] and we delete it.
Changes to this policy
When this policy changes in a way that affects what we collect or how we use it, we update the date at the top of this page and email the address on your Atrox - Mobile App Builder account at least 14 days before the change takes effect. Continuing to use Atrox - Mobile App Builder after that date means the new version applies.
This policy is governed by the laws of India, and the courts of Gurugram, Haryana have jurisdiction over any dispute arising from it. Nothing here removes a right you hold under the mandatory law of the country you live in.
Questions about this page can go to [email protected].