Skip to content

Privacy policy

BuyTrail Privacy Policy

This policy explains what information BuyTrail processes, why it is needed, how long it is retained, and the choices available to merchants and customers.

Effective July 21, 2026

1. Who we are and when this policy applies

TechImprovement Inc. ("TechImprovement," "we," "us," or "our") operates BuyTrail - Purchase History. This policy applies when a Shopify merchant installs or uses BuyTrail and when a customer interacts with the BuyTrail block on that merchant's online store.

A merchant generally decides why and how its customer data is used. For that data, we act as the merchant's service provider or data processor. We separately use limited merchant account, security, and operational information to provide and protect the service and meet our legal obligations.

2. Information we process

Shopify shop and administrator information
Shop domain, Shopify installation and session identifiers, granted access scopes, access tokens, shop time zone, and app installation status. Shopify authentication sessions may also include the administrator's user ID, name, email address, locale, and account role.
Customer purchase information
Shopify customer, order, line-item, product, and variant IDs; purchase time; selected product options; variant title; and selling-plan name. BuyTrail derives a purchase count and most recent purchase date from these records.
Service and privacy-request records
Webhook identifiers, synchronization status and errors, processing timestamps, and records needed to fulfill Shopify customer data requests and redactions.
Technical request information
The production web server logs the IP address, requested path without its query string, HTTP method and status, response size, browser user agent, and timestamp for security and reliability. BuyTrail also uses a customer ID briefly in memory to limit excessive storefront requests.

BuyTrail does not intentionally request or store storefront customer names, email addresses, phone numbers, postal addresses, or payment information. Merchant administrator details included in Shopify authentication sessions are separate from storefront customer data.

3. How information is collected

  • Shopify provides shop, authentication, order, product, and privacy data through its APIs and signed webhooks.
  • Merchants initiate history synchronization and configure the theme block. Theme-block settings remain in the Shopify theme.
  • Signed Shopify app-proxy requests provide the logged-in customer ID and the product or purchase reference needed for a lookup.
  • Hosting infrastructure creates limited security and request logs as described above.

BuyTrail uses only authentication and security mechanisms needed to operate the embedded app and signed storefront requests. It does not use advertising cookies or track customers across stores. Shopify and the merchant's storefront may use cookies under their own privacy policies.

4. Why we use information

  • Authenticate and authorize app installations and administrators.
  • Synchronize available order history and maintain the purchase index.
  • Show a signed-in customer only their own purchase count, latest purchase date, selected options, and matching account order.
  • Operate, secure, rate-limit, monitor, troubleshoot, and improve the reliability of BuyTrail.
  • Respond to privacy requests, prevent deleted data from being recreated, and comply with applicable law.

Where data-protection law requires a legal basis, processing may be necessary to perform our agreement with the merchant, support our legitimate interests in operating and securing BuyTrail, follow the merchant's documented instructions, or comply with law.

5. When information is disclosed

We disclose information only as needed to:

  • Work with Shopify, which supplies the commerce platform, APIs, authentication, app proxy, and webhook delivery.
  • Use infrastructure providers that host the application, database, network, and security logs on our behalf.
  • Comply with law, enforce our agreements, protect rights and safety, or respond to valid legal process.
  • Complete a merger, acquisition, financing, reorganization, or sale of the app, subject to appropriate confidentiality protections.

We do not sell personal information, share it for cross-context behavioral advertising, use it for third-party advertising, or use it to make decisions with legal or similarly significant effects.

6. Retention and deletion

  • Purchase records, shop state, and Shopify sessions are retained while needed to provide BuyTrail and are deleted after we receive an app-uninstall or shop-redaction notice.
  • Records linked to a customer or order are deleted when Shopify sends the applicable customer- or order-redaction instruction.
  • Completed or failed synchronization jobs and completed privacy request records are normally removed after 30 days.
  • Access logs rotate daily with seven archived files, normally limiting retention to approximately eight days including the current log.
  • One-way keyed deletion markers may be retained as needed to stop a delayed webhook or synchronization from recreating deleted data. These markers do not contain the raw shop, customer, or order ID.

We may retain information longer only when required by law, needed to resolve a dispute, or necessary to protect the service. When data is no longer required, we delete it or render it non-identifying.

7. Security

We use administrative, technical, and organizational safeguards designed to protect information. These include HTTPS in transit, Shopify-signed proxy and webhook verification, scoped API access, server-side token storage, restricted database access, minimized logging, rate limiting, and controlled deletion workflows. No method of transmission or storage is completely secure.

To report a suspected security issue, email info@techimprovement.net.

8. International processing

TechImprovement Inc. is established in the United States, and information may be processed and stored in the United States or other locations where our service providers operate. Where required, we use contractual or other recognized safeguards for international transfers.

9. Privacy choices and requests

Depending on location, a person may have rights to request access, correction, deletion, restriction, portability, or objection, and to complain to a privacy regulator. We may need to verify a request before acting on it.

Storefront customers should first contact the Shopify merchant from whom they purchased, because the merchant controls the customer relationship and can submit the appropriate Shopify privacy request. Merchants may contact us directly at info@techimprovement.net. We process Shopify's mandatory customer data request, customer redaction, and shop redaction webhooks.

10. Children

BuyTrail is a business service for Shopify merchants and is not directed to children. We do not knowingly use the app to collect personal information directly from children.

11. Changes to this policy

We may update this policy to reflect changes to BuyTrail, our data practices, or legal requirements. We will update the effective date on this page and provide additional notice when required by law.

12. Contact us

Privacy questions can be sent to info@techimprovement.net. General support questions can be sent to info@techimprovement.net.

TechImprovement Inc.
965 Frankford Ave, Unit 307, Philadelphia, PA 19125, United States