Privacy Policy

How Seny handles information for Shopify merchants, storefront visitors, and website users.

Last updated: September 17, 2026. Questions? support@seny.app

Home/Privacy

Who we are

Seny is a Shopify app operated by MB Klero, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania. For anything in this policy, contact us at support@seny.app.

Seny lets a merchant describe a storefront feature in plain language, generates working code for their Shopify store, and reports how those features perform.

This policy covers the Seny app, the Seny website, and the code Seny runs on a merchant's storefront.

Our two roles

We are a processor for personal data reached through a merchant's store — order data, shopper submissions to app features, and storefront analytics. The merchant is the controller: they decide what is collected and why, and we act on their instructions.

We are a controller for the merchant's own account, billing and support data.

If you are a shopper and want your data accessed or deleted, contact the store you bought from — see Section 10.

Merchants: your data processing agreement

Our Data Processing Addendum governs everything we process on your behalf, and takes effect when you install Seny. It sets out the categories of data, our security measures, our subprocessors, and how we handle erasure requests and breaches.

Data we process for merchants

Order data

We read a merchant's orders to attribute revenue to the features Seny built for them. We request only money amounts, line items, discounts and the cart attributes Seny itself writes — never customer email, phone number, or full addresses.

We store the Shopify order id, the attributed amounts, and which line items Seny influenced. No customer contact details from orders are stored.

Customer first name and city — sales notifications only

If a merchant enables the sales-notification popup, we read the customer's first name and the city and region of the shipping address so the popup can say "Anna in Berlin bought this", together with the product purchased and when. That data is held in server memory for at most five minutes and is never written to our database. If the merchant turns those options off, the popup reads "Someone purchased this" instead.

We do not use this data for anything else, and it is not combined with any other record.

Storefront analytics

When a Seny feature is shown on a storefront, we record that it was viewed, clicked, or used to add something to a cart, along with the page path and a random session identifier held in the browser's sessionStorage.

  • Our storefront code does not set cookies.
  • We do not store IP addresses or user agents in these analytics records.
  • The session identifier is random, expires after 30 minutes of inactivity, and is not linked to any customer account.

This is gated on consent. Nothing is transmitted, and no session identifier is created, until Shopify's Customer Privacy API confirms that analytics processing is permitted for that visitor. If a visitor declines, we transmit nothing and store nothing about their browsing. A purchase they make is still counted toward the merchant's revenue reporting, but it is not linked back to a browsing session.

Shopper submissions

Some features collect data directly from shoppers — a product review, a back-in-stock email address, a newsletter signup. What is collected is defined by the merchant's own app configuration. We store it on the merchant's behalf; it remains their data.

Technical data

Like any web service, our servers receive the IP address, request time and browser user agent of requests made to them. We use this to deliver the service, to rate-limit abusive traffic, and to investigate errors. IP addresses are held only transiently in server and CDN logs and in short-lived rate-limiting counters — they are not stored in our database and are not part of the analytics described above.

Shopify permissions we request

When a merchant installs Seny, Shopify asks them to approve the permissions ("access scopes") below. We request only what a shipped feature actually uses, and each permission is used only for the purpose listed.

PermissionWhat we accessWhy we use it
read_productsProducts, variants, collections — titles, prices, images, handles, availabilityTo show real products in features such as upsells, bundles and product badges; to let the merchant pick products in the builder; and so generated features fit the store's catalog
read_themesThe store's themes and theme filesTo match a feature to the store's design and place it on the right pages. We only read the theme — we never change it. Features are added through Shopify's theme app extension, which the merchant controls in the theme editor
read_metaobjects, write_metaobjectsOne app-owned entry per Seny app (its name and id); the store's own metaobjects when a feature is built to display themSo the merchant can choose their Seny apps by name in the theme editor. We create, update and delete only the entries that belong to Seny
read_ordersOrder amounts, line items, discounts and the cart attributes Seny writes; customer first name and shipping city/region only for the sales-notification popupRevenue attribution and the sales-notification popup, exactly as described under "Order data" and "Customer first name and city" above. We never read customer email, phone number or full address from orders
read_customers, write_customersOnly the customer matching an email address a shopper submits to a Seny featureWhen a shopper signs up through a feature such as a newsletter form or spin-to-win wheel, we find or create that customer in Shopify, record their email marketing consent, and tag them with the feature they used. The email goes straight into the merchant's Shopify store and is not stored in our database. We do not browse or export the merchant's customer list
read_discounts, write_discountsDiscounts that Seny createsTo create the discounts a merchant configures in a feature — automatic discounts for bundles and volume pricing, and single discount codes for prizes such as spin-to-win — and to update or remove them when the feature changes or is deleted
read_contentPage, blog and article titles, handles and summariesSo a feature can link to or appear on the right pages of the store
read_files, write_filesFiles the merchant uploads through SenyTo store logos, badges and icons the merchant uploads in the builder in their own Shopify Files, and to list those uploads for reuse
read_localesThe store's published languagesTo offer and show a feature in each language the store sells in

Seny does not request permission to change products, orders or themes.

Data we process about merchants

Shop domain, store name and timezone; the name and email address of staff who open the app, as provided by Shopify's OAuth; plan, credit balance and transaction history; the prompts and generated code in the builder; and support correspondence. We use this to operate the app, bill for it, support it, and to tell merchants about changes that affect them.

Artificial intelligence

Seny sends the merchant's prompts and the app's own generated code to Anthropic and OpenAI in order to generate storefront code. So that the result fits the store, it may also send store information that is not personal data: product and collection details, page titles, the store's languages, and theme files and styles.

No shopper data, order data, or customer data is ever sent to an AI provider. Prompts are not used to train those providers' models.

Merchants should not type personal, confidential, payment, health or other sensitive information into the builder. Nothing in Seny requires it, and prompts are stored with the app so the merchant can see their own build history.

How long we keep data

DataRetention
Storefront analytics events395 days, then deleted automatically
Session identifiers inside attributed ordersRemoved after 395 days; the amounts are kept as financial records
Attributed order amountsKept as accounting records while the account exists
Customer first name and city (sales notifications)Up to 5 minutes in memory; never stored
Shopper submissions (reviews, signups)While the merchant keeps the feature; deleted when the app is uninstalled
Staff sessionsDeleted 7 days after they expire
Server and CDN logsShort-lived operational logs, rotated automatically
Merchant account and billing recordsWhile the account exists, then as long as tax and accounting law requires

These periods run automatically on a daily schedule — they are not a policy we apply by hand.

When a merchant uninstalls Seny, Shopify sends us an erasure request and we delete that shop's apps, generated files, builder history, analytics and shopper submissions. Billing records are retained as accounting records with the shop's identity removed.

We honour Shopify's customer data request and customer redaction webhooks automatically. A redaction anonymises the shopper's identity in what we hold while preserving content that belongs to the merchant, such as a published review's rating and text.

What we never do

  • We do not sell or share personal data, in the ordinary sense or as those terms are defined under the CCPA.
  • We do not pool one merchant's data with another's, or use it to build any cross-store profile or benchmark.
  • We do not make automated decisions about shoppers that produce legal or similarly significant effects.
  • We do not use shopper or order data to train AI models.

Subprocessors

WhoWhat forWhere
Shopify Inc.The platform Seny runs on and reads fromGlobal
HostingerApplication servers and databaseUnited States (Boston)
Cloudflare, Inc.CDN, TLS, and edge caching of storefront codeGlobal
Anthropic PBCCode generation — no shopper or order dataUnited States
OpenAI, L.L.C.Code generation — no shopper or order dataUnited States
Functional Software, Inc. (Sentry)Error monitoringUnited States

Our in-app feedback and roadmap tool, Klero, is operated by MB Klero — the same company that operates Seny — so feedback you submit is not disclosed to a third party.

Merchants are given at least 30 days' notice before we add or replace a subprocessor, as set out in the DPA.

Your rights

Shoppers. Your relationship is with the store you bought from. Contact that merchant to access, correct, or delete your data — they are the controller, they will reach us, and we act on their instruction. Erasure requests that Shopify sends us are honoured automatically.

Merchants and staff. Email support@seny.app to access, correct, export or delete your data, or to object to or restrict how we process it. We respond within 30 days. You may also complain to your local data protection supervisory authority; ours is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, ada.lt).

Security

All traffic uses TLS 1.2 or higher, including everything we exchange with Shopify and with each subprocessor. Our database is on a private network with no ports exposed to the internet. Backups are encrypted before they are written to disk. Access to production systems is limited to people who need it. Every webhook we receive from Shopify is cryptographically verified before it is processed.

International transfers

MB Klero is established in Lithuania, but our servers and database are hosted in the United States. Personal data processed through Seny is therefore transferred outside the European Economic Area. Our other subprocessors — Shopify, Cloudflare, Anthropic, OpenAI and Sentry — also process data in the United States or globally.

For every such transfer we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), or on an adequacy decision where the recipient is certified under the EU–U.S. Data Privacy Framework. Merchants can request details of the safeguards in place by emailing support@seny.app.

Children

Seny is a tool for businesses and is not directed at children.

Changes to this policy

We will post material changes here and announce them in the app before they take effect.

Contact

MB Klero V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania support@seny.app

Frequently asked questions

Still have questions? Reach us at support@seny.app