Perkday Rewards
Privacy policy
Effective 2026-10-01
Data we process
Perkday receives the shop domain, store currency, time zone, tax-price setting, app permissions, billing status, and authenticated staff session information needed to install and operate the app. Staff session records can include the staff member's Shopify user ID, name, email address, locale, role indicators, access token, and token-expiration information.
For rewards, Perkday stores Shopify customer and order identifiers, eligible purchase and refund facts, point-ledger events, reward holds, discount references, program settings, and staff actions. Customer names and email addresses are read from Shopify when authorized staff search or review a customer; Perkday does not copy those fields into reward accounts or operational audit logs.
How we use data
We use this information only to run the merchant's loyalty program, calculate and reconcile balances, create customer-bound reward discounts, show authorized staff the correct customer and history, provide support and exports, verify billing, protect the service, and satisfy privacy or legal obligations. We do not sell personal information or use it for third-party advertising or unrelated profiling.
Shopify and service providers
Shopify provides the commerce platform, authentication, billing, and application APIs. DigitalOcean provides production hosting in San Francisco, California, United States. Backblaze B2 Cloud Storage stores encrypted recovery copies. These providers process data only to supply their contracted services. Their own terms and privacy commitments also apply to their processing.
Retention and deletion
While a merchant uses Perkday, we retain the reward ledger and the bounded order facts needed to keep balances accurate, handle refunds, investigate disputes, and provide exports. After uninstall, active application data is scheduled for deletion after 30 days unless an earlier verified deletion request applies or law requires a different period. Encrypted backup copies expire on a rolling schedule of no more than 42 days and are not returned to active use except through a controlled recovery process.
Shopify's mandatory customer-data and shop-redaction requests are authenticated and processed separately from the uninstall schedule. Perkday retains only minimal non-reversible evidence needed to prevent deleted identities from being recreated by delayed or replayed events.
Security and access
Perkday limits merchant data by shop, uses Shopify authentication for merchant staff, records protected-data access without copying the viewed personal information into the audit event, encrypts network traffic, and restricts production and backup access to authorized operators. No system can be guaranteed completely secure; suspected incidents are investigated and handled under the applicable notification requirements.
Your choices and requests
Merchants can export their Perkday data from the app and can contact us about access, correction, deletion, or other privacy questions. Customer requests should normally be directed to the Shopify merchant that operates the loyalty program; we assist the merchant and Shopify with verified requests.
Contact
Contact Two Way Street, LLC by email at privacy@example.com.