Legal

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with Recovered (the "App"), a Shopify application that helps merchants recover abandoned shopping carts and run post-purchase campaigns.

The App is operated by Dongguan Falaier Technology Co., Ltd. (东莞市法莱尔科技有限公司), a company incorporated in the People's Republic of China with its registered office at Room 402, Building 1, No. 7 Shenzhenzai Road, Tiesong Village, Qingxi Town, Dongguan, Guangdong, People's Republic of China ("Recovered", "we", "our", or "us").

This Policy applies to two distinct groups of people, and our legal role differs for each. Section 2 explains that distinction, and it matters for understanding the rest of this Policy.

1. Who This Policy Covers

This Policy covers:

If you are a Shopper and you have questions about how a particular Merchant uses your information, please contact that Merchant directly. We can also help you reach them — see Section 8.

2. Our Role: Controller and Processor

2.1 Merchant data — we act as a controller

For information about the Merchant itself (store domain, account settings, billing status, support correspondence, usage data), we determine the purposes and means of processing. We act as a data controller under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and equivalent laws.

2.2 Shopper data — we act as a processor

For personal information about Shoppers, the Merchant decides what data enters the App, who receives messages, and on what legal basis. We process that information only on the Merchant's documented instructions, as given through the App's settings and features. In relation to Shopper data we act as a data processor (a "service provider" under US state privacy laws), and the Merchant acts as the controller.

This means we do not decide who is contacted, we do not use Shopper data for our own marketing, we do not sell or share it, and we do not combine it across Merchants to build profiles. Our processing of Shopper data is governed by the Data Processing Terms set out in Annex A of our Terms of Service, which form part of our contract with each Merchant.

3. Information We Collect

3.1 Merchant information

3.2 Shopper information received from Shopify

When a shopper abandons a checkout or places an order on your Shopify store, Shopify sends us via webhook:

3.3 Shopper information provided by the Merchant (Manual Cart and External Orders)

The App includes features that allow a Merchant to manually enter details of an abandoned cart or a completed order that originated on a sales channel other than their Shopify store. Where a Merchant uses these features, we receive and store the information the Merchant enters, which may include a name, email address, phone number, country, product details, order value, and the name of the originating platform.

We do not obtain this information from the Shopper, from Shopify, or from any third-party list. It is supplied by the Merchant. The Merchant is responsible for ensuring that it was obtained lawfully and that they have a valid legal basis to send commercial messages to that individual. Our Terms of Service require Merchants to warrant exactly this before using these features.

If you are a Shopper and you received a message from a Merchant using this feature and want to know how your details reached them, contact us at [email protected] and we will put you in touch with the Merchant and, at your request, delete your information from our systems.

3.4 Message and engagement data

3.5 Storefront widget data

If a Merchant enables our storefront widgets (the WhatsApp chat button or the Frequently Bought Together widget), those widgets run on the Merchant's storefront. They do not collect personal information from shoppers and do not store anything in the shopper's browser — see Section 11.

When the Frequently Bought Together widget requests product recommendations from our servers, the request carries only the store domain and a product identifier. As with any web request, our server logs record the originating IP address and browser user agent. We use these logs only for security, abuse prevention, and debugging, and we retain them for the period stated in Section 7.

4. How We Use Information and Our Legal Bases

PurposeData usedLegal basis (EEA/UK)
Providing the App to Merchants, including account setup, configuration, and supportMerchant informationPerformance of a contract (Art. 6(1)(b))
Generating and sending recovery, upsell, and post-purchase messages on the Merchant's behalfShopper informationDetermined by the Merchant as controller; we act on their instructions (Art. 28)
Detecting and filtering suspicious, fraudulent, or bot-generated cart activityShopper and cart informationLegitimate interests of us and the Merchant in preventing abuse and protecting deliverability (Art. 6(1)(f))
Tracking message delivery and recovery outcomes for the Merchant's dashboardMessage and engagement dataProcessor acting on Merchant instructions
Maintaining suppression and unsubscribe listsEmail addresses and opt-out recordsLegal obligation and legitimate interests in honouring opt-outs (Art. 6(1)(c), 6(1)(f))
Securing, monitoring, debugging, and improving the App's reliabilityTechnical logs, aggregated usage dataLegitimate interests (Art. 6(1)(f))
Billing, accounting, and compliance with tax and legal obligationsMerchant informationLegal obligation (Art. 6(1)(c))

We do not use Shopper personal information to train artificial intelligence models, and we do not permit our AI provider to do so — see Section 5.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.

5. Sub-processors and Third-Party Services

We use the following sub-processors to operate the App. Each is bound by contractual obligations to protect personal information and to process it only as instructed.

Sub-processorPurposeData involvedLocation
Contabo GmbHServer and database hosting (self-managed PostgreSQL and application servers)All data stored by the AppSingapore
OpenAI, L.L.C.Generating personalised message contentCart and product details, shopper first name, message contextUnited States
Twilio SendGridEmail delivery, bounce and suppression handlingRecipient email address, message content, delivery eventsUnited States
Shopify Inc.App platform, authentication, billing, and source of merchant and shopper dataMerchant and shopper dataCanada / United States
Judge.meOptional. Retrieves product reviews to enrich message content, only if the Merchant supplies an API tokenProduct identifiersUnited Kingdom

OpenAI processes data submitted through its API in accordance with its API data usage policies, under which API inputs and outputs are not used to train its models by default. We rely on those contractual commitments; we do not independently control OpenAI's practices.

We will give Merchants at least thirty (30) days' notice before adding or replacing a sub-processor that processes Shopper personal information, by email to the Merchant's registered contact address and by updating this page. Merchants may object on reasonable data-protection grounds as described in Annex A of our Terms of Service.

We may also disclose information where required by law, court order, or a valid request from a competent authority, or where necessary to establish, exercise, or defend legal claims.

6. Where Data Is Stored and International Transfers

Our application servers and database are hosted in Singapore. Our operations, engineering, and support are carried out from the People's Republic of China, and our personnel may access data from there for the purposes described in this Policy. Certain sub-processors listed in Section 5 process data in the United States, Canada, and the United Kingdom.

This means personal information may be transferred outside the country in which the Merchant or Shopper is located, including outside the European Economic Area and the United Kingdom, to jurisdictions that have not received an adequacy decision.

Where we transfer personal information from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum), together with supplementary technical and organisational measures including encryption in transit, encryption at rest, access controls, and least-privilege access for personnel. Merchants may request a copy of the relevant transfer mechanism by writing to [email protected].

7. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy.

CategoryRetention period
Abandoned cart, order, and message records containing Shopper personal informationTwelve (12) months from creation, then permanently deleted or anonymised
Unsubscribe and suppression recordsRetained for as long as the Merchant uses the App, so that opt-outs continue to be honoured. Retained in a minimised form (email address and opt-out timestamp only)
Merchant account and configuration dataFor the duration of the subscription
All store and Shopper data following uninstallationDeleted at the point of uninstallation. In all cases deleted no later than 48 hours after uninstallation, on receipt of Shopify's shop redaction webhook
Billing and transaction records required for tax and accounting purposesAs required by applicable law
Server and application logsThirty (30) days

Our application deletes store and Shopper data immediately when a Merchant uninstalls the App, without waiting for Shopify's redaction webhook. The 48-hour figure above is the outer limit set by Shopify's platform requirements.

8. Your Privacy Rights

Depending on where you live, you may have the following rights in relation to your personal information:

8.1 If you are a Merchant

Contact us at [email protected]. We will respond within 30 days.

8.2 If you are a Shopper

The Merchant whose store you shopped on is the controller of your information, so please contact them first where possible. If you contact us directly, we will either forward your request to the relevant Merchant or, where we are able to identify your records, action it ourselves and inform the Merchant. Either way we will respond within 30 days.

You can unsubscribe from any message sent through the App using the unsubscribe link in that message. Unsubscribing takes effect immediately across all message types sent by that Merchant through the App.

We do not charge a fee for exercising these rights. We may need to verify your identity before acting on a request; we will only ask for the minimum information necessary to do so.

8.3 Automated decision-making

The App uses automated logic to schedule message timing and to flag suspicious or bot-generated cart activity. These processes do not produce legal effects concerning you or similarly significantly affect you. Message content is generated by AI but is sent on the Merchant's instruction and configuration.

9. How We Handle Shopify Privacy Webhooks

As a Shopify app, we implement Shopify's three mandatory privacy webhooks:

10. Data Security

We maintain technical and organisational measures appropriate to the risk, including:

If we become aware of a personal data breach affecting Shopper information, we will notify the affected Merchant without undue delay and in any event within 48 hours of becoming aware, and provide the information they need to meet their own notification obligations.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Cookies and Similar Technologies

11.1 Merchant admin interface

The App's merchant-facing interface does not set its own cookies. The Shopify admin in which it is embedded uses cookies as part of Shopify's standard embedded app framework, governed by Shopify's own privacy policy.

11.2 Storefront widgets

Our storefront widgets do not use cookies, local storage, session storage, IndexedDB, device fingerprinting, or any other technology that stores information on, or accesses information already stored on, a shopper's device.

Specifically:

Where the Frequently Bought Together widget records that a product was added to a cart from a recommendation, it does so by passing a line item property to Shopify's own cart API at the moment the shopper clicks. That value is held in the shopper's Shopify cart session, which is part of the store's own infrastructure, not something we place on the device.

Because our widgets do not store or access information on a shopper's terminal equipment, Article 5(3) of the EU ePrivacy Directive and its national implementations do not apply to them, and no cookie consent is required in respect of our widgets. Merchants remain responsible for consent relating to Shopify's own cookies and any other apps or scripts on their storefront.

12. Children's Privacy

The App is a business tool intended for use by merchants. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has been provided to us, contact us and we will delete it.

13. Region-Specific Disclosures

13.1 EEA and UK representatives

[[NOT YET APPOINTED — REQUIRED BEFORE SERVING EEA/UK MERCHANTS. Under GDPR Article 27 and UK GDPR Article 27, an organisation established outside the EEA/UK that processes the personal data of individuals in those territories must appoint a representative there and publish their name and contact details. This must be a representative appointed under a written mandate specifically for data protection purposes. A product-safety responsible person appointed under the EU General Product Safety Regulation, or any similar product compliance agent, cannot fulfil this role. Replace this paragraph with the appointed representative's name, postal address, and contact email once appointed.]]

13.2 California and other US states

Where we process Shopper personal information, we act as a service provider (California) or processor (Virginia, Colorado, Connecticut, Utah, and other states) on behalf of the Merchant. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not retain, use, or disclose it for any purpose other than performing the services specified in our contract with the Merchant.

13.3 People's Republic of China

We are established in the PRC and comply with the Personal Information Protection Law where applicable to our processing activities.

14. Changes to This Policy

We may update this Policy from time to time. Where changes are material, we will notify Merchants by email to their registered contact address at least 30 days before the change takes effect, in addition to updating the date at the top of this page. Continued use of the App after a change takes effect constitutes acceptance of the updated Policy.

Previous versions are available on request.

15. Contact Us

For any question about this Policy, or to exercise your privacy rights:

Dongguan Falaier Technology Co., Ltd. (东莞市法莱尔科技有限公司)
Registered office: Room 402, Building 1, No. 7 Shenzhenzai Road, Tiesong Village, Qingxi Town,
Dongguan, Guangdong, People's Republic of China
Correspondence address: 2/F, No. 6 Shixin Chuangye Street, Zhangmutou Town,
Dongguan, Guangdong, People's Republic of China

Privacy enquiries: [email protected]
General enquiries: [email protected]
Website: getrecovered.app