Skip to content

Legal

Privacy policy

This policy explains what personal data the DiGiMAA apps process on behalf of a Shopify merchant, and what we process about merchants ourselves.

Last updated 27 August 2026

TODOThis is a structural draft written by the DiGiMAA team and has not yet been reviewed by legal counsel. It describes how the apps actually work, but it is not final. If you need a signed, counsel-reviewed version for procurement, email support@digimaa.in.

1.Who we are

DiGiMAA is a commerce-software brand owned and operated by Binary Technology Solutions, Mumbai, India ("we", "us"). DiGiMAA develops, publishes and supports the apps referenced in this document.

For data submitted by shoppers through an app installed on a merchant's store, the merchant is the data controller and DiGiMAA is a processor acting on the merchant's instructions. For merchant account, billing and support data, DiGiMAA is the controller.

2.Data each app accesses

Each app requests only the data it needs to do its one job. Nothing below is collected for advertising, resale or profiling.

  • Store Locator — store/location records you enter or import, and the search terms and approximate location a shopper submits to find a store. No shopper account data is required.
  • QwikAns AI — product questions submitted by shoppers, the answers published in reply, the product the question relates to, and the email address of a shopper who asks to be notified.
  • QuickForms — the form fields a merchant defines and the submissions shoppers send through them, including any contact details and file attachments the merchant chooses to collect.
  • SupportHub Helpdesk — ticket content, the messages exchanged on a ticket, and the Shopify order and customer reference the ticket is linked to.

3.Shopify permissions we request

Permissions are requested per app at install time and shown to you before you approve them.

  • Shop profile: shop name, domain, plan, country, currency and contact email — used to configure the app and contact the merchant.
  • Products and collections: read access where an app displays product context (question threads, ticket order lines).
  • Orders and customers: read access only for apps that link a conversation to an order, and only for the orders involved.
  • Theme app block surfaces: the app renders through a theme app block; we do not write to your theme files.

4.Data we process about merchants

  • Account and shop identifiers received from Shopify at install.
  • Support correspondence, including anything you attach to a support request.
  • Billing records, which are processed by Shopify Billing — we do not receive or store card details.
  • Product analytics limited to feature usage and error diagnostics; we do not build advertising profiles.

5.Where data is stored

App data is stored in managed cloud infrastructure with encryption in transit (TLS) and at rest. Access is restricted to named DiGiMAA personnel who need it for support or maintenance, and access is logged.

TODOTODO — confirm and publish the exact hosting regions per app before this policy is finalised. Do not state a region here until it is verified against the deployed infrastructure.

6.Sub-processors

We use a small number of sub-processors. Each is bound by a data processing agreement and processes data only to deliver the service.

  • Shopify — the platform the apps run on, and the source of shop, product and order context.
  • Cloud hosting and managed database provider — application hosting and data storage.
  • Transactional email provider — notification and support email delivery.
  • Error and performance monitoring provider — diagnostics.
  • AI model provider — used by QwikAns AI to draft answers; question text sent for inference is not used to train third-party models.

TODOTODO — replace the categories above with the named sub-processor entities and their processing locations, and publish a change-notification process for additions.

7.Retention

  • Active app data is retained while the app is installed, so that history stays available to you.
  • On uninstall, app data is retained for 48 hours to allow accidental-uninstall recovery, then deleted within 30 days.
  • Support correspondence is retained for 24 months.
  • Aggregate, non-identifying counts may be retained for capacity planning.

8.Deletion on uninstall

We implement Shopify's mandatory compliance webhooks: shop/redact, customers/redact and customers/data_request. A shop/redact request triggers deletion of that shop's app data, including backups on their normal expiry cycle. You can also request immediate deletion at any time by emailing us.

9.Shopper and merchant rights

Under the GDPR, the UK GDPR and India's Digital Personal Data Protection Act, individuals may request access, correction, deletion, restriction, portability or objection. Shoppers should contact the merchant whose store they used; the merchant may forward the request to us and we will assist within the statutory period.

10.Data protection contact

Email privacy requests to support@digimaa.in with the shop domain and the app name. Postal contact: Binary Technology Solutions, Mumbai, India.

TODOTODO — appoint and name a data protection contact (and an EU/UK representative if required) before publication.

11.Changes to this policy

Material changes will be announced in the app admin and on the changelog before they take effect. The last-updated date above always reflects the current version.