Legal

Privacy Policy

Effective date: July 14, 2026 · Last updated: July 29, 2026

Who we are

Poby is a product of AwesomeSoft ("we", "us"), and provides a post-purchase experience feedback app for Shopify stores. This policy explains what data the app handles and how. You can reach us at support@getpoby.com.

What Poby collects

Poby collects the feedback a shopper voluntarily submits: star ratings for stages of the shopping experience, an optional "how did you hear about us?" answer, and (on low ratings) the reason tags they select. The widget never asks the shopper for personal details — no name, email, address, or payment information is typed into it.

Customer name and email

So you can see who left a response and follow up on it, Poby attaches the customer’s first name, last name, and email address to each submission. These are read from the Shopify order behind the response using the read_orders and read_customers permissions you grant at install. Shopify classes these as protected customer data, and we use them for a single purpose: identifying the customer on the feedback detail page inside your Shopify admin so you can respond. They are never used for marketing, never sold, never shared with third parties, and are deliberately excluded from the CSV export. On a guest checkout with no customer account only the order email is available, and no name is stored. Poby requests no phone number and no address.

How data is used

Submitted feedback is aggregated into the analytics dashboard shown to you, the merchant — response trends, rating distribution, top issues, and traffic sources. Those aggregates are built from ratings and comments only, never from customer names or emails. We use all of it solely to provide the service. We do not sell feedback data or use it for advertising.

Authentication & security

Poby uses Shopify session-token authentication and communicates over encrypted connections. Data is encrypted in transit and at rest, and backups are encrypted. Test and production data are kept separate. Access to production data is limited to authorised staff under strong authentication, and every access to a customer’s name or email is recorded in an audit log capturing which record was viewed and when. We maintain a security incident response policy. Poby adds no blocking calls to your storefront and loads asynchronously.

GDPR & data requests

Poby implements Shopify’s mandatory GDPR compliance webhooks. When a customer data-request or data-erasure event is received from Shopify, the corresponding records are returned or deleted automatically. Merchants uninstalling the app trigger shop data redaction per Shopify’s schedule.

Data retention

Feedback records are retained while your store has Poby installed. If you uninstall the app, your store’s feedback records are deleted 30 days later — kept briefly so a reinstall doesn’t lose your history. Shopify’s shop-redaction webhook is honoured throughout.

Third parties & sub-processors

Poby runs on reputable cloud infrastructure providers that host the service and store feedback data on our behalf. These providers process data solely to operate Poby. We do not share feedback data beyond what is required to run the service.

Data Processing Agreement

Where Poby processes personal data relating to your customers, we act as your processor. The terms governing that — categories of data, security measures, sub-processors, breach notification, retention, and how we assist with data subject requests — are set out in our Data Processing Agreement, which forms part of the Terms of Service you accept by installing Poby.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above.
Questions about this policy? Email support@getpoby.com. Poby is built and operated by AwesomeSoft — awesomesoft.io.