DataBay Privacy Policy

Last updated: 28 August 2026

DataBay is a Shopify app operated by DataBurst ("we", "us"). It syncs a merchant's store data into a private analytics warehouse and renders dashboards on top of it. This policy explains what we collect, why, and how a merchant or their customers can have it deleted.

Who controls the data

The merchant who installs DataBay is the data controller for their store's data. We act as a data processor on their behalf: we only process store data to provide the analytics service the merchant asked for.

What we collect from your Shopify store

Only what the granted access scopes allow, and only for the data streams the merchant enables:

We do not collect payment card numbers, and we do not receive Shopify customer passwords.

What we collect from you as a user

Why we process it

To load your store and advertising data into your isolated warehouse, to compute the metrics shown in the dashboards, to answer your natural-language queries, to send you sync and pipeline alerts, and to secure and support the service. We do not sell your data and we do not use it to train third-party models.

Where it is stored and who can see it

Store data is loaded into a ClickHouse warehouse, isolated per organisation, hosted on our servers in the European Union. Access is restricted to the merchant's own users and to DataBurst staff who need it for support and operations. Subprocessors we use are limited to our hosting provider, Shopify itself, and any advertising platform you explicitly connect.

Retention

We keep synced data for as long as the app is installed. When the app is uninstalled, Shopify sends us a shop/redact request and we delete the store's warehouse data and configuration.

Deletion and access requests

We implement Shopify's mandatory compliance webhooks:

Merchants can also request access, correction, export, or erasure at any time by emailing us. We respond within 30 days.

Your rights

Depending on where you live (GDPR, UK GDPR, CCPA/CPRA), you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Merchants should route their customers' requests through Shopify so the compliance webhooks above are triggered.

Security

Data is encrypted in transit (TLS) and connector credentials are encrypted at rest. Access to production systems is restricted and authenticated.

Changes

We will update this page when our processing changes, and update the "last updated" date above.

Contact

DataBurst — info@databurst.tech