Data & privacy

Data retention and GDPR

How RevLogic handles data retention and GDPR, including store data deleted after uninstall, Shopify redaction webhooks honored, and customer deletion requests respected.

RevLogic stores a copy of your Shopify data so it can compute customer intelligence quickly. This article explains how long that data is kept, what happens when you uninstall, and how RevLogic handles the privacy requests Shopify sends on your behalf.

Where your data is kept

Synced orders, products, customers, and the profiles computed from them live in RevLogic’s encrypted database, scoped to your store. It’s used only to run the features you see in the app, and it’s never sold or shared with a third party, except one you connect yourself, like Klaviyo, and then only what that integration needs (see below). See What RevLogic can access for the full permissions picture.

What happens when you uninstall

When you remove RevLogic from your store, Shopify sends a shop redaction request as part of its privacy schedule. In response, RevLogic deletes all of your store’s data: orders, products and variants, customers, computed profiles, cross-sell data, merchandising settings, tasks and notes, snoozes, sync records, app settings, and your session. Nothing is retained.

If you had connected Klaviyo, RevLogic revokes its access to your Klaviyo account and deletes the stored credentials at the moment you uninstall, rather than waiting for the redaction. An authorization shouldn’t outlive the app that used it.

Shopify schedules this redaction to arrive a short time after uninstall (typically around 48 hours), and RevLogic acts on it as soon as it’s received. In other words, uninstalling doesn’t leave your data sitting with us; it’s cleared out on Shopify’s standard timetable.

Honoring GDPR requests

Shopify defines a set of mandatory privacy webhooks that every app must support, and RevLogic implements all of them:

  • Customer data request. When a customer asks what data you hold about them, Shopify notifies the app. RevLogic’s copy of a customer’s data is the orders, profile, and activity described throughout this knowledge base, all derived from your own Shopify records.
  • Customer redaction (right to be forgotten). When a customer requests deletion, Shopify sends a redaction request and RevLogic deletes that customer’s data: their synced orders, their synced customer record, their computed profile, and any CRM-side records tied to them (notes, calls, tasks, and snoozes). Specific orders flagged for redaction are removed even when the rest of the customer is retained. One thing survives it today: RevLogic keeps a small internal bookkeeping row per customer, used to work out which values have changed since the last time it wrote anywhere, and that row holds the customer’s email address and their last derived status values. It carries no orders, no spend figures, and no notes, and it’s deleted with everything else when you uninstall. Clearing it on redaction as well is a known gap and is being fixed.
  • Shop redaction. The full store cleanup described above, triggered after uninstall.

These requests are verified as genuinely coming from Shopify before RevLogic acts on them, and each one is processed automatically. You don’t have to do anything to stay compliant.

If you connected Klaviyo

Connecting Klaviyo means RevLogic sends each reachable customer’s email address plus seven derived values (reorder status, health score, revenue tier, spend trend, key-account status, expected reorder date, and last order date) into your own Klaviyo account, at your direction. Two consequences worth being clear about:

  • Those profiles live in Klaviyo, under Klaviyo’s retention and your Klaviyo settings. RevLogic can write properties onto them; it can’t delete a Klaviyo profile. A customer deletion request that has to reach Klaviyo is handled in Klaviyo, using Klaviyo’s own privacy tools, and a Shopify redaction request doesn’t travel there on its own.
  • Disconnecting takes back one value. RevLogic clears revlogic_expected_reorder_date on every profile it wrote to, so date-triggered flows stop firing. The other six keep their last values.

RevLogic’s Klaviyo credentials are stored encrypted and are deleted when you disconnect and when you uninstall. Full detail in RevLogic properties in Klaviyo.

Requesting deletion yourself

The cleanest way to trigger customer deletion is through Shopify itself: when you erase or request redaction for a customer in your Shopify admin, Shopify relays that to RevLogic and the corresponding data is removed. If you have a specific privacy request that isn’t covered by the standard Shopify flow, start a live chat from the Help page or email sean@revlogic.app and we’ll handle it.

Privacy and terms

Full details of how RevLogic handles data are in our published policies:

Next steps