Privacy Policy
Effective 1 September 2026
Who we are
PriceWave (“the app”) is a Shopify app built and operated by Reliova Commerce, based in India. References to “we”, “us” and “our” mean Reliova Commerce as the operator of PriceWave. You can reach us at privacy@reliovacommerce.com. Merchants who need our full legal entity details for their own compliance records can request them at that address.
The app schedules product price changes in a Shopify store on the instructions of the merchant who installs it.
Our role, and the merchant’s
Reliova Commerce operates PriceWave from India. The merchant who installs PriceWave decides what data enters their Shopify store and why. Where privacy laws apply to that store’s customers or to the merchant (for example GDPR or UK GDPR for merchants serving Europe, or similar laws in other markets), that merchant is typically the controller of their store’s data and we act as a processor on their behalf: we process store data only to deliver the features the merchant has configured, and only for as long as they keep the app installed. Those laws are about where merchants and shoppers are — not about where the app is developed.
If you are a shopper who bought from a store using PriceWave, that store is responsible for your personal data. Please see the store’s own privacy policy, and read Order data below, which explains why we almost certainly hold nothing that identifies you.
Data we collect from the merchant
- Store domain, Shopify store ID, store timezone and store currency.
- The access scopes granted to the app, and the OAuth access token Shopify issues so the app can act on the store’s behalf.
- Subscription state from Shopify Billing: the current plan, the charge identifier, whether the charge was approved, and a history of plan changes.
- Support requests you send us: the store domain, the subject and the message body.
Data we collect from the store
- Products and variants relevant to a campaign: identifiers, titles, current prices, product status and publication state.
- The audit history our own writes create — for each change, the old price, the new price, the campaign step, when it happened, and whether it succeeded.
- Discounts and price rules, read so the app can warn about discount stacking and about prices falling through a floor.
- The campaign configuration you create: schedules, step percentages, price floors and ceilings, budget caps, and products you add to Product Shield (excluded from sequences until the shield is removed).
Order data: what we receive and what we do not
We request the read_orders access scope. We do not request
read_customers, read_all_orders or write_orders.
Every order and refund notification we subscribe to is restricted by an explicit field allowlist, which means Shopify sends us only the listed fields and nothing else. Those fields are:
- For an order: the order ID, the order’s API identifier, the time it was updated, and for each line item its ID, variant ID, quantity and unit price.
- For a refund: the refund ID, the order ID it belongs to, and for each refunded line its ID, quantity, subtotal, variant ID and unit price.
We therefore do not receive, and cannot store:
- customer names, email addresses or phone numbers;
- shipping or billing addresses;
- Shopify customer IDs;
- payment card numbers or any payment credentials;
- shopper IP addresses, device identifiers, cookies or browsing behaviour.
The only order-linked values we retain are the Shopify order ID and, for refunds, the refund and refunded-line identifiers. We keep them for exactly two reasons: so a discount is counted against your budget cap once and only once even if Shopify delivers the same notification twice, and so a refund reverses the correct line. If your plan does not include budget caps, or if no variant on the order belongs to a running campaign, the notification is discarded without anything being written to our database.
Why we process this data
We process the data above only to:
- write the prices you scheduled, at the times you scheduled them;
- enforce the price floors you set, and detect prices changed outside the app so we can alert you;
- count discount spend against a budget cap you configured;
- show you an audit trail of every price the app wrote;
- run your subscription through Shopify Billing, and answer your support requests.
We do not use any of this data for advertising, profiling, cross-merchant benchmarking, resale, data brokerage, or training machine-learning models. We do not sell or rent personal data, and we have never done so.
PriceWave does change prices automatically, but those decisions apply to products, not to people. The app does not show different prices to different shoppers, does not segment or score individuals, and takes no personal characteristic as an input, so no automated decision is made about any individual.
Who else handles the data
- Shopify — the origin and the destination of all store data. Shopify’s own privacy policy governs their processing.
- Our cloud hosting provider — runs the application servers and background workers.
- Our managed PostgreSQL provider — hosts the database and job queue in which the data described above is stored.
When we say we use no analytics services, we mean no third-party advertising, attribution, or session-recording vendors on the app. In-product “analytics” features, if offered on your plan, are reports about your own store’s campaign activity, not sale of personal data. We use no third-party error-tracking service. No storefront script, pixel or cookie is installed in the merchant’s shop by this app. Current provider names are available on request at privacy@reliovacommerce.com, and we will give installed merchants at least 30 days’ notice before adding or replacing one.
How long we keep it
- On uninstall. Before you uninstall, complete or stop every active sequence. Shopify typically invalidates the Admin API access token as soon as the app is removed, and the uninstall webhook may arrive after that. We attempt, on a best-effort basis, to restore prices where we still can; that attempt often fails with an unauthorized response once the token is gone. We then cancel every scheduled job and stop all further price writes. We do not promise that uninstall always restores product prices. Prices already written to your store may remain at their last written values until you change them in Shopify yourself.
- On erasure. Shopify sends a shop redaction request approximately 48 hours after uninstall. On receiving it we delete every record belonging to that store — campaigns, audit history, notifications, alerts, risk snapshots, budget records and the store record itself.
- Audit history, while installed. The audit trail is trimmed automatically on a rolling window set by your plan: 30 days on Orbit, 90 days on Nova, 365 days on Galaxy, and retained for the life of the installation on Supernova. The same windows are listed on the PriceWave pricing page.
- Order-derived budget records, while installed. Retained for 13 months, then deleted automatically.
- You may also ask us to delete your store’s data before the 48-hour window elapses — write to privacy@reliovacommerce.com and we will action it.
We keep no backup copy of a redacted store’s data beyond the routine backup retention of the providers named above, after which it expires.
Security
- All traffic to and from the app uses HTTPS. The application refuses unencrypted connections.
- Every notification from Shopify is verified against a cryptographic signature before it is processed, so forged webhooks are rejected.
- Access tokens are held in a database that is not reachable from the public internet and is encrypted at rest at the storage layer.
- We request only the access scopes the features need. The app holds no permission to write orders or to read customers.
- Access to production systems is limited to the app’s operator, under confidentiality.
- Application logs record error classes and messages, not request bodies.
Your rights
Depending on where you are, you may have the right to access, correct, export or delete personal data we hold, to object to or restrict processing, and to complain to a data protection authority. Merchants can exercise all of these by writing to privacy@reliovacommerce.com; we respond within 30 days.
Shopper requests. Shoppers should contact the store they bought from, since the store is the controller of their data. Where Shopify forwards a customer data or customer redaction request to us as well, there is nothing for us to return and nothing for us to erase, because we hold no record that identifies a customer. We acknowledge the request and take no further action, and merchants may rely on this statement when answering their own customers.
International transfers
Because we operate from India, store data may be stored and processed there and in the countries in which our hosting and database providers operate, which may differ from the merchant’s country. Where a transfer is subject to the GDPR or UK GDPR (because the merchant or their customers are in the EEA or UK), it relies on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism. Merchants who require a signed data processing agreement may request one at privacy@reliovacommerce.com.
Children
PriceWave is a business tool sold to merchants. It is not directed at children, and we do not knowingly collect personal data of anyone under 16.
Changes to this policy
If we change how we handle data in a way that materially affects merchants, we will update this page, change the effective date above, and notify installed merchants inside the app before the change takes effect. Continuing to use the app after that notice means you accept the updated policy.
Contact
PriceWave, operated by Reliova Commerce (India) — privacy@reliovacommerce.com. See also our Terms of Service.
Questions about this document? privacy@reliovacommerce.com