Last updated July 20, 2026
Privacy policy
RiffRoff uses only the Shopify data needed to operate a merchant’s referral program, prevent abuse, issue rewards, and honor privacy requests.
Who this policy covers
This policy explains how RiffRoff processes information when a Shopify merchant installs the app, when the merchant’s staff use it, and when customers participate in that merchant’s referral program. The merchant remains responsible for its own customer-facing privacy disclosures and referral-program terms.
Information we process
- Store and authorized-user information supplied through Shopify, including the shop domain, access credentials, staff identifiers, name, email, locale, and authorization status.
- Referral settings, public referral tokens, discount and store-credit transaction identifiers, and referral status history.
- Customer and order information needed for referral eligibility and attribution, such as Shopify customer IDs, email address, order ID, order total, currency, payment status, cancellation or refund status, and order-risk indicators returned by Shopify.
- Masked email addresses and keyed, one-way digests of email, customer, IP-address, and user-agent signals used to prevent duplicate or abusive claims. RiffRoff does not store raw IP addresses or raw user-agent strings for this purpose.
How we use information
We use the information to authenticate stores and staff, create and manage referral links and offers, verify first-order eligibility, attribute paid orders, flag possible abuse for merchant review, reverse pending rewards after refunds or cancellations, issue Shopify store credit, provide support, secure the service, and comply with law and Shopify’s mandatory privacy webhooks.
RiffRoff does not sell personal information or use merchant customer data for independent advertising.
Sharing and service providers
Information is exchanged with Shopify to provide the app’s features. We may also use infrastructure providers to host the application and encrypted database. Those providers may process information only to deliver services to RiffRoff. We may disclose information when required by law or to protect the security and rights of merchants, customers, Shopify, or RiffRoff.
Retention, deletion, and security
Hashed request signals are scheduled for deletion after 90 days. Hashed merchant-staff access records are retained for no more than 12 months to maintain a security audit trail. Active referral and accounting records are retained while the app is installed and as needed to operate the merchant’s program. Shopify’s customer-redaction webhook removes or anonymizes records associated with a customer. Shopify’s shop-redaction webhook deletes the shop’s app data after uninstall.
We use TLS in transit, access controls, keyed hashing for referral identities and request signals, and Shopify-authenticated requests. No method of storage or transmission is completely risk-free.
Your choices and contact
Customers should normally submit access or deletion requests to the Shopify merchant they interacted with. Merchants and customers may also contact support@riffroff.comwith privacy questions. We process verified requests through the applicable merchant and Shopify privacy workflows.