Version 1.0 · Effective 23 September 2026
1. Scope and roles
This policy applies to Navelis Gift, its Shopify app and storefront integration, its product pages, and Gift support requests. The operator is Navelis, the registered trade name of Maxime Alain Brun, entrepreneur individuel (EI), 15 Quai du Pothuis, 95300 Pontoise, France, registered under 107 856 791 R.C.S. Pontoise. Contact us through the Gift privacy form.
The merchant decides whether to configure Gift campaigns and which shoppers receive them. For shopper and order data processed to provide those campaigns, the merchant is normally the controller or business and Navelis is the processor or service provider under the Gift data protection agreement. Navelis determines its own purposes for limited account, support, security and operational information.
2. Data we process
Gift receives the shop identity, authenticated app sessions, plan and configuration, campaign rules, gift product and inventory information, merchant actions and diagnostic records. Shopify order counts support plan limits.
For a merchant's new-versus-returning-shopper rule, Gift reads the Shopify-authenticated customer ID and number of orders. It does not request the shopper's name, email, phone number or postal address for that rule. If a merchant does not enable that rule, Gift does not need that customer lookup for eligibility.
Shopify paid-order webhooks are processed to count orders with gifts and calculate campaign metrics. The webhook payload is handled transiently. Gift stores the shop, date, campaign, currency, quantities, gift value and a shop-scoped hashed order identifier to deduplicate and support redaction; that identifier is pseudonymous data, not anonymous data. Gift does not persist a full order or customer profile for this reporting.
When Shopify Customer Privacy permits analytics, the storefront integration can send gift views, choices and declines for aggregate reporting. Gift also receives information submitted in support or privacy requests. Hosting and security systems may produce limited technical logs.
3. Purposes and limits
We use these data to authenticate the merchant, configure and enforce gift eligibility and Shopify discounts, preserve shopper gift-removal choices, count plan usage, show gift performance, prevent duplicate records or misuse, diagnose failures, support merchants, and handle data-subject requests. We do not use shopper data from Gift for advertising, unrelated profiling or sale. Gift does not make automated decisions with legal or similarly significant effects; its automated outcome is eligibility for a merchant-configured promotional gift.
4. Consent and shopper choices
Each storefront analytics event is sent only when Shopify's Customer Privacy API reports that analytics processing is allowed. If permission is not available or is refused, Gift does not send those interaction events. Operational processing required to deliver a merchant's gift offer or handle an order is separate from optional analytics. The merchant remains responsible for its storefront privacy notice, lawful basis, consent configuration and applicable shopper choices.
Gift does not sell customer data. A shopper may decline or remove a gift in the storefront. That choice is respected within the offer context described in the Gift guide.
5. Providers and transfers
Shopify provides the commerce platform and API. Navelis hosts Gift's application and database with OVHcloud in France; encrypted backup copies are retained on the production server and on an operator-controlled off-site computer. Limited support, contact and security providers may process only the information needed for those functions. Contact us for the current provider list. Shopify or support providers may process information outside the EEA under their applicable contractual transfer mechanisms.
6. Retention and erasure
Gift retains campaign settings while installed. Gift order metrics and storefront funnel observations are pruned after 90 days. Audit records and completed privacy-request records are pruned after 365 days. A minimal order fingerprint may remain until app uninstall to prevent erased data being reintroduced by webhook replay; associated reporting fields are cleared after their retention period. Pending requests remain while they are being resolved.
Uninstall or Shopify redaction webhooks trigger deletion of live shop or affected customer/order records. Encrypted server backups expire after 30 days and encrypted off-site backups after 90 days. Older backup copies cannot be selectively edited; documented restore controls reconcile known erasures before a restored copy can be promoted. These limits also apply to a later deletion request.
7. Security
Gift uses HTTPS in transit, restricted production access, encryption for sensitive tokens, a dedicated encrypted data volume and encrypted backups. Access is limited to persons who need it to run and support the service. No system can guarantee absolute security.
8. Privacy rights
Shoppers should normally contact the merchant where they shopped. Merchants can request help with access, export, correction and deletion. Gift handles Shopify's mandatory customer data-request, customer-redaction and shop-redaction webhooks. Contact us through the Gift privacy form for assistance.
9. Changes
Material changes will receive a new effective date and appropriate notice to merchants. This policy is part of the Gift terms.
10. Contact
Navelis, 15 Quai du Pothuis, 95300 Pontoise, France. Privacy and support: contact Navelis Gift.