Privacy Policy
1. Introduction
Gift Lift ("we", "our", or "us"), a certified Shopify application developed and managed by Helios Technology Solutions Inc., is committed to protecting your privacy and ensuring the security of your corporate data. This Privacy Policy explains how we collect, use, and safeguard information when you install and use the Gift Lift application (the "App").
The App is engineered as an enterprise-grade data migration pipeline, strictly designed to help high-volume Shopify merchants ("Merchants" or "you") safely transfer legacy gift card liabilities into their active Shopify ledgers.
2. Information We Collect
a. Merchant Information
When you authorize and install the App, we automatically collect specific contextual information from your Shopify account via the Shopify GraphQL API. This includes your store name, domain routing (myshopify.com), primary operational email address, timezone, and primary ledger currency.
b. Gift Card & Financial Data
To provide our deterministic migration service, you upload CSV files containing legacy gift card data. This payload typically includes alphanumeric gift card codes, numeric balances, and ISO currency identifiers. We do not require, scrape, or intentionally collect End-Customer Personally Identifiable Information (PII) such as names, physical addresses, or credit card data to execute these migrations.
c. System & Audit Telemetry
We dynamically generate and temporarily buffer line-by-line audit reports (success/error states) of your migrations. We also collect foundational application telemetry—such as originating IP addresses, browser agents, and API mutation latency logs—to ensure our GraphQL orchestrator respects rate-limit compliance and maintains 99.99% uptime.
3. How We Use Your Information
We process your data strictly to facilitate the functional operation of the application:
- Service Delivery: To parse, sanitize, validate (Dry-Run), and execute idempotent data mutations directly to your Shopify database.
- Audit & Compliance: To compile downloadable, cryptographically sealed audit logs stored in AWS S3 for your accounting and reconciliation teams.
- Operational Alerts: To dispatch critical notifications, including background sync completion receipts and throttling alerts.
- System Optimization: To monitor orchestration efficiency and autonomously prevent Shopify API (429) rate-limiting blocks.
4. Data Storage, Encryption, and Volatility
We enforce strict, bank-grade security protocols across our infrastructure. All data traversing the network is encrypted in transit using TLS 1.3.
Data Volatility Concept: We treat your data as transient. Files are processed securely in memory. Uploaded CSV artifacts and the resulting audit reports are housed in isolated, AES-256 encrypted AWS S3 buckets. We retain this data solely to provide historical audit logs, and these vaults can be permanently purged upon explicit Merchant request.
5. Shopify Mandatory Webhooks & GDPR
As an approved Shopify Partner, Helios Technology Solutions Inc. completely adheres to Shopify's mandatory data protection webhooks and global privacy frameworks (including GDPR and CCPA):
- Shop Redact: Upon application uninstallation or store closure, an automated webhook triggers the permanent deletion of your store's configuration and residual logs within 48 hours.
- Customer Redact: Should an end-customer exercise their "Right to be Forgotten," we automatically intercept the corresponding Shopify webhook and purge any cross-referenced data points in our isolated logs.
6. Third-Party Subprocessors
We fundamentally do not sell, rent, or trade your operational data. We deploy carefully vetted third-party cloud infrastructure (specifically Amazon Web Services) exclusively to host our computation engines and execute the secure storage of audit files.
7. Contact & Compliance Inquiries
Transparency is core to our infrastructure. If you have inquiries regarding this Privacy Policy, our data ingestion protocols, or require a custom Data Processing Agreement (DPA) tailored for your compliance or legal department, please contact our engineering team directly.
Email: privacy@heliotech.ca
Entity: Helios Technology Solutions Inc.
App: Gift Lift