Segmented — Privacy Policy
Last updated: July 14, 2026
Segmented (“the App”) provides customer segmentation and storefront personalization to Shopify merchants. This policy describes what personal data the App processes, why, and how it is protected.
Data we process
When a merchant installs the App, we access Shopify data through the Admin API, limited to the scopes granted at install:
- Customer profile (name, email, phone, default address, tags, marketing consent) — segment evaluation, merchant-facing profile pages, storefront content personalization (e.g. first-name greetings).
- Order history (line items, totals, discounts, statuses) — segment conditions based on purchase history, evaluated on the fly and not copied to our database.
- Storefront behavioral events (product viewed, added to cart, checkout started) — real-time and historical segment conditions. Stored with the Shopify customer ID only — no name, email, or address.
- Anonymous engagement metrics (views/clicks on App content) — merchant analytics. May reference a customer ID when the visitor is logged in.
We do not sell personal data, use it for advertising, or process it for any purpose other than providing the App's features to the merchant.
Data storage and retention
- Behavioral events and metrics: retained 24 months, then automatically deleted.
- Personal-data access logs: retained 12 months.
- Merchant configuration (segments, sections, workflows): retained while the App is installed.
- On uninstall, sessions and integration credentials are deleted immediately; all remaining shop data is deleted upon Shopify's
shop/redactwebhook (48h after uninstall).
GDPR / privacy requests
We honor Shopify's mandatory privacy webhooks:
customers/data_request— we can produce every event stored for a customer.customers/redact— the customer's stored events are deleted and metrics are anonymized.shop/redact— all data for the shop is deleted.
Security
- Data in transit is encrypted (TLS).
- Databases are backed up daily with AES-256-encrypted backups.
- Access to personal data through the App is logged.
- Staff access is limited to the App's operators.
Third parties
If the merchant connects Klaviyo, the App reads campaign/flow engagement events from the Klaviyo API using the merchant's own API key. No data is pushed to Klaviyo.
Contact
Privacy questions: nathi.hayoun@gmail.com