Legal
Last updated: August 29, 2026
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with Recovered (the "App"), a Shopify application that helps merchants recover abandoned shopping carts and run post-purchase campaigns.
The App is operated by Dongguan Falaier Technology Co., Ltd. (东莞市法莱尔科技有限公司), a company incorporated in the People's Republic of China with its registered office at Room 402, Building 1, No. 7 Shenzhenzai Road, Tiesong Village, Qingxi Town, Dongguan, Guangdong, People's Republic of China ("Recovered", "we", "our", or "us").
This Policy applies to two distinct groups of people, and our legal role differs for each. Section 2 explains that distinction, and it matters for understanding the rest of this Policy.
This Policy covers:
If you are a Shopper and you have questions about how a particular Merchant uses your information, please contact that Merchant directly. We can also help you reach them — see Section 8.
For information about the Merchant itself (store domain, account settings, billing status, support correspondence, usage data), we determine the purposes and means of processing. We act as a data controller under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and equivalent laws.
For personal information about Shoppers, the Merchant decides what data enters the App, who receives messages, and on what legal basis. We process that information only on the Merchant's documented instructions, as given through the App's settings and features. In relation to Shopper data we act as a data processor (a "service provider" under US state privacy laws), and the Merchant acts as the controller.
This means we do not decide who is contacted, we do not use Shopper data for our own marketing, we do not sell or share it, and we do not combine it across Merchants to build profiles. Our processing of Shopper data is governed by the Data Processing Terms set out in Annex A of our Terms of Service, which form part of our contract with each Merchant.
When a shopper abandons a checkout or places an order on your Shopify store, Shopify sends us via webhook:
The App includes features that allow a Merchant to manually enter details of an abandoned cart or a completed order that originated on a sales channel other than their Shopify store. Where a Merchant uses these features, we receive and store the information the Merchant enters, which may include a name, email address, phone number, country, product details, order value, and the name of the originating platform.
We do not obtain this information from the Shopper, from Shopify, or from any third-party list. It is supplied by the Merchant. The Merchant is responsible for ensuring that it was obtained lawfully and that they have a valid legal basis to send commercial messages to that individual. Our Terms of Service require Merchants to warrant exactly this before using these features.
If you are a Shopper and you received a message from a Merchant using this feature and want to know how your details reached them, contact us at [email protected] and we will put you in touch with the Merchant and, at your request, delete your information from our systems.
If a Merchant enables our storefront widgets (the WhatsApp chat button or the Frequently Bought Together widget), those widgets run on the Merchant's storefront. They do not collect personal information from shoppers and do not store anything in the shopper's browser — see Section 11.
When the Frequently Bought Together widget requests product recommendations from our servers, the request carries only the store domain and a product identifier. As with any web request, our server logs record the originating IP address and browser user agent. We use these logs only for security, abuse prevention, and debugging, and we retain them for the period stated in Section 7.
| Purpose | Data used | Legal basis (EEA/UK) |
|---|---|---|
| Providing the App to Merchants, including account setup, configuration, and support | Merchant information | Performance of a contract (Art. 6(1)(b)) |
| Generating and sending recovery, upsell, and post-purchase messages on the Merchant's behalf | Shopper information | Determined by the Merchant as controller; we act on their instructions (Art. 28) |
| Detecting and filtering suspicious, fraudulent, or bot-generated cart activity | Shopper and cart information | Legitimate interests of us and the Merchant in preventing abuse and protecting deliverability (Art. 6(1)(f)) |
| Tracking message delivery and recovery outcomes for the Merchant's dashboard | Message and engagement data | Processor acting on Merchant instructions |
| Maintaining suppression and unsubscribe lists | Email addresses and opt-out records | Legal obligation and legitimate interests in honouring opt-outs (Art. 6(1)(c), 6(1)(f)) |
| Securing, monitoring, debugging, and improving the App's reliability | Technical logs, aggregated usage data | Legitimate interests (Art. 6(1)(f)) |
| Billing, accounting, and compliance with tax and legal obligations | Merchant information | Legal obligation (Art. 6(1)(c)) |
We do not use Shopper personal information to train artificial intelligence models, and we do not permit our AI provider to do so — see Section 5.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.
We use the following sub-processors to operate the App. Each is bound by contractual obligations to protect personal information and to process it only as instructed.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Contabo GmbH | Server and database hosting (self-managed PostgreSQL and application servers) | All data stored by the App | Singapore |
| OpenAI, L.L.C. | Generating personalised message content | Cart and product details, shopper first name, message context | United States |
| Twilio SendGrid | Email delivery, bounce and suppression handling | Recipient email address, message content, delivery events | United States |
| Shopify Inc. | App platform, authentication, billing, and source of merchant and shopper data | Merchant and shopper data | Canada / United States |
| Judge.me | Optional. Retrieves product reviews to enrich message content, only if the Merchant supplies an API token | Product identifiers | United Kingdom |
OpenAI processes data submitted through its API in accordance with its API data usage policies, under which API inputs and outputs are not used to train its models by default. We rely on those contractual commitments; we do not independently control OpenAI's practices.
We will give Merchants at least thirty (30) days' notice before adding or replacing a sub-processor that processes Shopper personal information, by email to the Merchant's registered contact address and by updating this page. Merchants may object on reasonable data-protection grounds as described in Annex A of our Terms of Service.
We may also disclose information where required by law, court order, or a valid request from a competent authority, or where necessary to establish, exercise, or defend legal claims.
Our application servers and database are hosted in Singapore. Our operations, engineering, and support are carried out from the People's Republic of China, and our personnel may access data from there for the purposes described in this Policy. Certain sub-processors listed in Section 5 process data in the United States, Canada, and the United Kingdom.
This means personal information may be transferred outside the country in which the Merchant or Shopper is located, including outside the European Economic Area and the United Kingdom, to jurisdictions that have not received an adequacy decision.
Where we transfer personal information from the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum), together with supplementary technical and organisational measures including encryption in transit, encryption at rest, access controls, and least-privilege access for personnel. Merchants may request a copy of the relevant transfer mechanism by writing to [email protected].
We retain personal information only as long as necessary for the purposes described in this Policy.
| Category | Retention period |
|---|---|
| Abandoned cart, order, and message records containing Shopper personal information | Twelve (12) months from creation, then permanently deleted or anonymised |
| Unsubscribe and suppression records | Retained for as long as the Merchant uses the App, so that opt-outs continue to be honoured. Retained in a minimised form (email address and opt-out timestamp only) |
| Merchant account and configuration data | For the duration of the subscription |
| All store and Shopper data following uninstallation | Deleted at the point of uninstallation. In all cases deleted no later than 48 hours after uninstallation, on receipt of Shopify's shop redaction webhook |
| Billing and transaction records required for tax and accounting purposes | As required by applicable law |
| Server and application logs | Thirty (30) days |
Our application deletes store and Shopper data immediately when a Merchant uninstalls the App, without waiting for Shopify's redaction webhook. The 48-hour figure above is the outer limit set by Shopify's platform requirements.
Depending on where you live, you may have the following rights in relation to your personal information:
Contact us at [email protected]. We will respond within 30 days.
The Merchant whose store you shopped on is the controller of your information, so please contact them first where possible. If you contact us directly, we will either forward your request to the relevant Merchant or, where we are able to identify your records, action it ourselves and inform the Merchant. Either way we will respond within 30 days.
You can unsubscribe from any message sent through the App using the unsubscribe link in that message. Unsubscribing takes effect immediately across all message types sent by that Merchant through the App.
We do not charge a fee for exercising these rights. We may need to verify your identity before acting on a request; we will only ask for the minimum information necessary to do so.
The App uses automated logic to schedule message timing and to flag suspicious or bot-generated cart activity. These processes do not produce legal effects concerning you or similarly significantly affect you. Message content is generated by AI but is sent on the Merchant's instruction and configuration.
As a Shopify app, we implement Shopify's three mandatory privacy webhooks:
We maintain technical and organisational measures appropriate to the risk, including:
If we become aware of a personal data breach affecting Shopper information, we will notify the affected Merchant without undue delay and in any event within 48 hours of becoming aware, and provide the information they need to meet their own notification obligations.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
The App's merchant-facing interface does not set its own cookies. The Shopify admin in which it is embedded uses cookies as part of Shopify's standard embedded app framework, governed by Shopify's own privacy policy.
Our storefront widgets do not use cookies, local storage, session storage, IndexedDB, device fingerprinting, or any other technology that stores information on, or accesses information already stored on, a shopper's device.
Specifically:
Where the Frequently Bought Together widget records that a product was added to a cart from a recommendation, it does so by passing a line item property to Shopify's own cart API at the moment the shopper clicks. That value is held in the shopper's Shopify cart session, which is part of the store's own infrastructure, not something we place on the device.
Because our widgets do not store or access information on a shopper's terminal equipment, Article 5(3) of the EU ePrivacy Directive and its national implementations do not apply to them, and no cookie consent is required in respect of our widgets. Merchants remain responsible for consent relating to Shopify's own cookies and any other apps or scripts on their storefront.
The App is a business tool intended for use by merchants. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child's information has been provided to us, contact us and we will delete it.
[[NOT YET APPOINTED — REQUIRED BEFORE SERVING EEA/UK MERCHANTS. Under GDPR Article 27 and UK GDPR Article 27, an organisation established outside the EEA/UK that processes the personal data of individuals in those territories must appoint a representative there and publish their name and contact details. This must be a representative appointed under a written mandate specifically for data protection purposes. A product-safety responsible person appointed under the EU General Product Safety Regulation, or any similar product compliance agent, cannot fulfil this role. Replace this paragraph with the appointed representative's name, postal address, and contact email once appointed.]]
Where we process Shopper personal information, we act as a service provider (California) or processor (Virginia, Colorado, Connecticut, Utah, and other states) on behalf of the Merchant. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not retain, use, or disclose it for any purpose other than performing the services specified in our contract with the Merchant.
We are established in the PRC and comply with the Personal Information Protection Law where applicable to our processing activities.
We may update this Policy from time to time. Where changes are material, we will notify Merchants by email to their registered contact address at least 30 days before the change takes effect, in addition to updating the date at the top of this page. Continued use of the App after a change takes effect constitutes acceptance of the updated Policy.
Previous versions are available on request.
For any question about this Policy, or to exercise your privacy rights:
Dongguan Falaier Technology Co., Ltd. (东莞市法莱尔科技有限公司)
Registered office: Room 402, Building 1, No. 7 Shenzhenzai Road, Tiesong Village, Qingxi Town,
Dongguan, Guangdong, People's Republic of China
Correspondence address: 2/F, No. 6 Shixin Chuangye Street, Zhangmutou Town,
Dongguan, Guangdong, People's Republic of China
Privacy enquiries: [email protected]
General enquiries: [email protected]
Website: getrecovered.app