Legal

Privacy policy

One policy for the website and every Ninety9 Shopify app — including Reviso — covering what we collect, what we do not, and how to exercise your rights.

Last updated: August 17, 2026

This Privacy Policy explains how Ninety 9 LTD ("we", "us", "our") collects, uses, stores and shares information when you visit ninety9.dev and when you install or use any of our Shopify apps (Addy, Addly, Goalify, Monet and Reviso).

By installing or using an app, you acknowledge that information may be processed as described here. This policy applies to merchants, store staff, customers whose data is processed through an app (where applicable), and visitors to our website.

1. Who we are and the roles we play

When an app processes customer personal data on behalf of a Shopify merchant, the merchant is the data controller and Ninety 9 LTD acts as a data processor / service provider for that data.

For data relating to our own business operations — merchant account records, billing records, support communications, security logs and legal compliance records — Ninety 9 LTD acts as an independent controller.

We access and process data only as permitted by Shopify, by our agreements with merchants, and by applicable law.

2. This website

The current ninety9.dev website is a set of static files. There is no login, no comment system and no newsletter form.

Cookies

This is the full record of cookies and similar storage on the website. The banner only asks for a choice; the detail lives here. You can change your analytics choice at any time via the Cookies link in the footer.

Necessary (no consent required). Two values may be stored locally in your browser and never leave your device: n9-theme, which remembers whether you chose light or dark mode, and n9-consent, which remembers your analytics cookie choice. Theme is removed the moment your choice matches your operating system preference again. Consent is kept so we do not ask on every visit. These are not sent to us and are not used to identify you.

Analytics (consent required). Google Analytics 4 is used by Ninety 9 LTD to understand which pages merchants actually read. If you accept, Google may process page path, device type, approximate region, referrer, and a client identifier. Until you accept — and if you reject — the Google Analytics script is never loaded, no analytics cookies are set, and no page-view is sent. Google acts as a processor for this purpose. The measurement ID lives in one site configuration file; it is not pasted into individual pages.

Google Search Console verification, when configured, is a static meta tag used to prove we own the domain. It is not a tracking pixel and does not set cookies.

The site loads the Inter typeface from Google Fonts. Google receives your IP address as part of that request. A content blocker will stop it and the site falls back to your system typeface with no loss of function.

Our hosting provider keeps standard server logs (IP address, user agent, requested URL, timestamp) for security and abuse prevention. These are retained for a short period and are not used to build a profile of you.

The contact form on this website does not submit anything to a server. It assembles a draft in your own email client. Your message reaches us only if you choose to send it, and only through your own email provider.

3. Information we collect through the apps

Each app requests only the Shopify API scopes it needs to function, and each scope is disclosed on the app's Shopify App Store listing before you install. Depending on the app, that can include:

  • Shopify store information — store name, store domain, store owner or staff contact details, and identifiers needed to connect requests to the correct merchant account.
  • Store and catalogue data — products, collections, variants, discounts, theme and locale settings, used to render offers and calculate discounts correctly.
  • Order data — order identifiers, line items, product or variant data, prices, fulfilment or shipping status, typically limited to what the app needs to function. Addy, Addly, Goalify and Monet do not store customer names, emails, phone numbers or addresses on our servers.
  • Customer information (Reviso only) — customer name, email address, shipping or contact information and other order-related fields necessary to process, validate or communicate an approved post-purchase change. Reviso cannot provide self-serve order editing without this access.
  • Merchant and audit information — configuration, edit-request history, changed fields, timestamps, approval events and other records needed for traceability, dispute handling, support and compliance.
  • Usage and technical information — app interactions, session activity, browser type, device information, IP-related security signals, crash reports and technical logs. Device and browser information used for security monitoring is read from the Shopify platform; we do not persist payment-card or login-secret data.
  • Billing information — records relating to the merchant's Shopify App Store subscription or usage charges, where applicable. All charges are processed by Shopify; we do not collect, process, store or have access to full payment card numbers or card security codes (CVV/CVC).
  • Support and communication records — emails, in-app chat, support requests and related troubleshooting information.

4. Information we do not collect

  • We do not collect, process, store or have access to full payment card numbers or card security codes.
  • We do not collect, process, store or have access to Shopify account passwords, authentication credentials or login secrets.
  • Apps other than Reviso do not store customer personal data (names, emails, phone numbers, billing or shipping addresses) on our servers.
  • Each app only accesses data that Shopify makes available through authorised APIs, and only to the extent necessary to provide that app's functionality.

Merchant means a business owner or authorised staff member of a Shopify store that installs or uses one of our apps. Customer means an individual whose order or account data may be processed through a merchant's use of an app (in practice, this applies to Reviso).

5. Legal bases for processing

Where applicable under data protection law, we process personal data on one or more of the following legal bases:

  • Performance of a contract — to provide the apps, maintain merchant accounts, enable the advertised functionality and deliver requested support.
  • Legitimate interests — to secure the apps, prevent fraud or abuse, maintain logs, improve reliability, provide support and protect our business and users.
  • Legal obligation — to comply with applicable laws, lawful requests, tax or accounting requirements and regulatory obligations.
  • Consent — where consent is specifically required by law, including analytics cookies on this website. Google Analytics runs only after you accept the cookie banner.

6. How we use information

We use personal data to:

  • Provide and operate the apps, including cart drawers, bundles, progress bars, upsell popups and (for Reviso) self-serve post-purchase order editing.
  • Validate, process, log and maintain a history of configuration and, where relevant, edit requests.
  • Communicate with merchants and, where relevant to a Reviso workflow, customers regarding order changes or confirmations.
  • Provide customer support, troubleshoot problems and respond to inquiries.
  • Monitor performance, maintain service quality and improve reliability and security.
  • Detect, prevent and investigate fraud, abuse, unauthorised activity and security incidents.
  • Comply with Shopify requirements, contractual obligations and applicable law.
  • Send service-related notices, updates and security communications.

We do not sell personal data, we do not rent or trade it, we do not share it with advertising networks, and we do not use merchant store data to train third-party models.

7. Sharing of information

We may share information only where necessary and appropriate with:

  • Shopify, where required for app functionality, platform integration, billing, compliance or support.
  • Google, if you accept analytics cookies on this website — Google Analytics 4, used to understand aggregate page use. The script is not loaded unless you accept.
  • Infrastructure and service providers — hosting, database, monitoring, email, support-chat and security providers that process data on our behalf under contractual protections requiring confidentiality, security and data-protection measures.
  • Professional advisers such as lawyers, accountants, auditors or insurers, where needed.
  • Authorities or regulators, when required by applicable law, legal process, or to protect rights, safety, property or the integrity of the service.
  • Corporate-transaction parties, in connection with a merger, financing, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality and legal safeguards.
  • Authorised contractors or subprocessors, bound by confidentiality and data-protection obligations.

A current list of subprocessors is available on request at [email protected].

8. Data security

We implement reasonable technical and organisational safeguards designed to protect personal data, including access controls, role-based access limitation, encryption in transit where appropriate, secure storage practices, logging and monitoring.

No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.

9. Hosting, storage and international transfers

We use third-party cloud hosting services to store databases, applications and collected data. Data may be stored or processed in jurisdictions different from the merchant's or customer's country of residence, including transfers that may involve the United States where a data-centre relocation or provider requires it.

Where personal data is transferred internationally, we take steps intended to ensure that such transfers comply with applicable data-protection laws. Depending on the circumstances, these safeguards may include contractual protections such as standard contractual clauses, or reliance on recognised adequacy mechanisms where available.

10. Retention

We retain personal data only as long as reasonably necessary to provide the service, maintain records required for support, security, dispute resolution and compliance, and meet legal, tax, accounting and contractual obligations.

App configuration and analytics are retained while your subscription is active. After uninstall, Shopify sends us the mandatory shop/redact webhook and we delete store data within 48 hours of the retention window Shopify specifies. Customer redaction requests are processed within 30 days. When personal data is no longer required, we delete, anonymise or securely dispose of it unless continued retention is required or permitted by law.

11. Your rights and choices

Depending on your location and applicable law (including the GDPR in the EEA and UK, and the CCPA/CPRA in California), you may have the right to:

  • Request access to personal data, or a copy of it.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of personal data, subject to legal and contractual obligations and to what is necessary for the app to function.
  • Object to, or request restriction of, certain processing.
  • Request portability of personal data, where applicable.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a competent data protection authority.
  • Not be discriminated against for exercising these rights (CCPA/CPRA).

These rights may be subject to legal, technical and contractual limitations, including where processing is necessary to provide the service, protect legal claims or comply with law.

If you are a customer of a merchant using Reviso, please contact the relevant merchant first — the merchant is usually the controller of your customer data. If needed, we may assist the merchant in responding to verified requests.

Where required by Shopify and applicable privacy laws, we support merchants in addressing verified privacy-related requests, including access and deletion. Write to [email protected] and we will action it.

12. Shopify privacy compliance

We process Shopify-related personal data only as necessary to provide app functionality and to operate in accordance with Shopify platform requirements, our agreements and applicable law. Mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) are implemented for every app.

13. Third-party links

The apps or this website may contain links to third-party websites or services, including Shopify. We are not responsible for the privacy practices, security or content of those third parties. Review their terms and privacy policies before interacting with them.

14. Children's privacy

Our apps are business software sold to merchants. They are not directed at children. We do not knowingly collect personal data directly from anyone under 16. If we become aware that we have unintentionally received such data, we will take reasonable steps to delete it.

15. Changes

We may update this Privacy Policy from time to time to reflect legal, technical, operational or business changes. If we make material changes, we will update the date at the top and, for changes that affect how app data is handled, notify merchants inside the app, on this website, or by email where appropriate. Continued use of the apps after an update constitutes acceptance of the revised policy.

16. Contact

Ninety 9 LTD
ul. "27-mi yuli", No 23
Center Odesos, 9000 Varna
Bulgaria
[email protected]

Older URLs for this policy (/privacyPolicy.html and /reviso-privacy-policy.html) redirect here. This is the single privacy policy for the website and for every Ninety9 Shopify app, including Reviso.