Privacy policy
What Praisin keeps, why, for how long, and how to see it, correct it or have it deleted.
In force from 25 September 2026.
1. Who we are
Praisin is an app for Shopify stores that collects and shows product reviews and sends email and messages that customers have agreed to receive. It is made by AZOURANE OÜ, Järvevana tee 9, Tallinn 11314, Estonia ("Praisin", "we", "us"). For anything about privacy, write to support@praisin.app.
2. Our two roles
Praisin as controller. We decide how and why we use the data of the merchants who install Praisin (their account, billing and support data) and of visitors to praisin.app. Sections 3 and 4 describe this.
Praisin as processor. A shop's customers (the people who buy from a store that uses Praisin) are the shop's customers, not ours. The merchant decides why and how their data is used, and we process it only on the merchant's instructions, as set out in our Data Processing Addendum. Sections 5 to 7 describe this. If you are a shop's customer, the shop is your first contact (section 12).
3. Data we control
- Merchant account: shop domain and name, the plan, settings, the language chosen for the admin, and the shop owner's name and email address from Shopify, for service messages and the monthly report.
- Billing: the plan and charge status from Shopify. Shopify takes the payment; we never see card details.
- Support: the messages you send us and our replies.
- AI connections: when you connect an AI assistant or your own AI key, the connection, its permissions and a log of what it did.
- Website visitors: praisin.app sets no cookies and runs no analytics or advertising. Our host, Cloudflare, keeps short technical logs, including IP addresses, to keep the site secure.
4. Why we use it, and the legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing Praisin to the shop, including support and service messages | Contract, Art. 6(1)(b) |
| Billing through Shopify and keeping accounting records | Contract and legal obligation, Art. 6(1)(b) and (c) |
| Security, abuse prevention, protecting shared email sending | Legitimate interests, Art. 6(1)(f) |
| Improving Praisin from how the app is used, without customer data | Legitimate interests, Art. 6(1)(f) |
We never sell personal data and never use it for advertising.
5. Data we process for shops, feature by feature
Praisin only processes what each feature needs, and only when the shop has switched that feature on.
Reviews
Rating, text, the display name the reviewer chooses, language, product, order match (whether the review is verified), moderation status, the shop's reply, helpful votes and, if added, photos and videos. Location, camera and device data are removed from every photo and video before it is stored. If the reviewer ticks the box, their permission to show the review, name and photos on the site, in social posts and in emails is recorded with its wording and time.
Review requests and half written reviews
Order and product identifiers, product names, order, shipping and delivery dates, delivery status and, where the shop turns it on, carrier tracking. The customer's name and email address to send the request. Each request's steps (sent, opened, clicked, started, reviewed). A review someone starts and does not finish is saved so they can come back to it.
Newsletters and automated emails
Subscriber email address, name if given, status, groups, and the consent record: the exact wording shown, the time and a one way hash of the network address. For abandoned checkout, cart, browse and back in stock emails: the products viewed or left in the cart, only for visitors who are signed in or arrived from a Praisin email, and only when Shopify's customer privacy settings allow marketing.
WhatsApp, Viber and SMS
The phone number from the order, only when the shop switches on requests by phone. With the one tap buttons, the shop sends the message from its own phone; Praisin prepares the text and records that it was sent. With automatic WhatsApp (when the shop connects its own WhatsApp Business number), messages go through Meta, and delivery and read reports come back. Opt outs (for example STOP) are recorded so the number is never messaged again.
Store credit, reorder reminders and add to your parcel
For a store credit thank you: the Shopify customer, the review and the amount. For "running out soon" reminders: the products and pack sizes bought and the reminder dates, for subscribers only. For "add to your parcel": the unpaid order and the product added.
Results
Whether emails were delivered, opened and clicked, and the orders placed within the shop's chosen window after a click. Clicks keep the browser type and a hashed network address.
AI replies and translation
When the shop uses AI, the review text, the product name and the shop's tone settings are sent to the AI provider to draft a reply or translate a review. A person at the shop reads every draft before it is published. Review text is treated as data and never as instructions. Praisin never writes reviews.
Google and Trustpilot ratings
When the shop connects its own Google Business Profile or Trustpilot, Praisin shows the shop's public rating from that service with its label.
6. Legal basis for shop customer data
The shop, as controller, chooses the legal basis. In most cases: consent for newsletters and marketing messages (Art. 6(1)(a)); the shop's legitimate interest in asking a buyer about a product they received (Art. 6(1)(f)); and the purchase contract for order related messages (Art. 6(1)(b)). Praisin applies each customer's consent state before every marketing send, and every email carries a one click unsubscribe.
7. How long we keep it
| Data | Kept for |
|---|---|
| Everything about a shop and its customers | While Praisin is installed. After uninstall, Shopify sends a deletion request about 48 hours later, and we then erase that shop's data, media and exports. |
| Unfinished review drafts on our servers | 30 days after the last change (the shop can choose a different period) |
| Products viewed and carts (for reminder emails) | 30 days |
| Abandoned checkouts | 60 days |
| Finished automated email runs | 180 days |
| Phone numbers | Until the request is finished, and at most 60 days after the last message. A one way hash stays so an opt out keeps working. |
| Click records (browser type, hashed network address) and email event details | 13 months |
| Unsubscribed or undeliverable email addresses | The address is blanked 24 months after it left the list; a one way hash stays so it is never added again. |
| Review imports that were never applied | 14 days. An applied import can be undone for 30 days. |
| Copies of a shop's Google Business Profile reviews | At most 30 days. Google Places data is not stored. |
| AI assistant activity logs | 90 days; usage counts 400 days |
| Encrypted backups | Overwritten within 30 days |
| Merchant billing and accounting records | As long as Estonian accounting law requires (currently 7 years) |
8. Shopify's privacy requests
Praisin handles Shopify's mandatory privacy webhooks automatically:
- customers/data_request: we prepare an export of everything Praisin holds about that customer for the shop.
- customers/redact: we erase that customer's reviews, review requests, messages, phone numbers, subscription, consent records, purchase facts, reminders, rewards and social permissions, keeping only a one way hash so they are not contacted again.
- shop/redact: we erase all of the shop's data, media and exports.
9. Who helps us (sub processors)
| Provider | What for | When | Where |
|---|---|---|---|
| Cloudflare, Inc. | App hosting, database, file storage, queues, image conversion, this website | Always | Global network, EU and US |
| Shopify | Store data, the app inside the admin, billing | Always | Canada, Ireland, US |
| Amazon Web Services (Amazon SES) | Sending email | When sending is on | Frankfurt, Germany |
| Resend | Sending email | When sending is on | United States |
| Anthropic | AI reply drafts and translation | Only if the shop turns AI on | United States |
| Meta Platforms (WhatsApp Business Platform) | Automatic WhatsApp messages | Only if the shop connects WhatsApp | United States and global |
| Google (Business Profile, Places) | Showing the shop's own Google rating | Only if the shop connects it | United States and global |
| Trustpilot | Showing the shop's own Trustpilot widget | Only if the shop connects it | Denmark |
If a shop connects its own AI key (OpenAI, Anthropic or Google), that provider works under the shop's own agreement with it. We tell merchants inside the app at least 30 days before adding a new sub processor.
10. Transfers outside the EU
Some providers process data outside the European Economic Area. Where they do, the transfer relies on the European Commission's standard contractual clauses, or on the EU US Data Privacy Framework where the provider is certified under it, together with the provider's own security measures.
11. Security
- Encryption in transit (HTTPS only) and at rest. Each shop's Shopify access token is encrypted again with its own key.
- Every record carries its shop, and every query is limited to that shop; tests check that one shop can never read another's data.
- Admin access needs a verified Shopify session. Staff access to customer data is limited and logged, and accounts use strong passwords and two factor sign in.
- Sending can be stopped for one shop or for everyone in one step. We keep an incident response plan and tell affected merchants without undue delay if their data is involved in a breach.
- Test systems use invented data, never real customers.
12. Your rights
Under the GDPR you can ask to access, correct, delete, restrict or export your data, and object to its use. Where we rely on consent, you can withdraw it at any time.
- If you bought from a shop that uses Praisin, contact that shop. It can answer through Shopify, which passes the request to Praisin, and we carry it out automatically. Every email has a one click unsubscribe, and you can reply STOP to an automatic WhatsApp message. You can also write to us and we will pass your request to the shop.
- If you are a merchant or a website visitor, write to support@praisin.app. We answer within one month.
You can also complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, aki.ee. You may also contact the authority where you live.
13. Cookies and browser storage
This website sets no cookies. It saves one item in your browser: your choice of light or dark mode.
The Praisin widgets on a shop's pages set no cookies. They use the browser's own storage for:
- a review you started, so it is still there when you come back (text in local storage, photos in the browser's database), removed when you send it or when it expires;
- which reviews you already marked helpful;
- when you closed the newsletter form, so it does not reappear too soon;
- how many small activity cards you saw in this visit (session storage);
- only if the shop's cookie banner allows marketing: a code from a Praisin email link, and a summary of your cart in this visit, so a reminder email can show the right products.
14. Children
Praisin is a tool for businesses. It is not directed at children, and shops must not use it to market to children.
15. Changes
If we change this policy, we update the date at the top. For important changes we tell merchants inside the app at least 30 days before they take effect.