1. Who we are and the two roles we play
WHOLEFRAME LLC, 5 Bartlett Street, Newton, NH 03858, United States, operates the Service. We handle personal information in two different roles:
- As a controller, for information about the people who use WholeFrame: account holders and their teammates, people who apply for early access, visitors to our website, and anyone who writes to us. Sections 2, 4 and 7 to 11 of this policy cover that information.
- As a processor (a “service provider” under US state law), for information we receive from the stores and platforms a merchant connects to WholeFrame. That includes information about the merchant’s own customers. The merchant is the controller of it, and our Data Processing Addendum governs how we handle it. Section 3 summarizes what that information is.
2. Information we collect about you
- Account information. When you create an account or accept an invitation: your name and email address; optionally a phone number, profile image, time zone, currency, language and date format; your organization’s name and your role in it; and your password, which we store only as a one-way hash.
- Store connection information. When you connect Shopify or another platform: the store’s name and domain, and the access credentials that platform issues to us, which we encrypt.
- Billing information. If you subscribe through the Shopify App Store, Shopify bills you and tells us your plan and subscription status. We never receive or store payment card numbers.
- Early-access requests. The work email address, store address and monthly ad-spend range you enter on our early-access form.
- Security and audit records. When you sign in, and when you or a teammate take an administrative action such as inviting a member, connecting or disconnecting a store, or exporting a customer’s data, we record the action, the time, the account involved, your browser’s user-agent string and your network address shortened to its network prefix (the last part of an IPv4 address is removed, and an IPv6 address is shortened to its first 48 bits).
- Server logs. Our servers and hosting providers record technical logs of each request, which include the IP address, browser user-agent and the address requested.
- Product analytics. In the app we count page views in aggregate with Vercel Web Analytics, which does not use cookies. Our marketing website uses no analytics.
- Messages. If you email us, your message and your contact details.
3. Information we process for merchants
When a merchant connects a store or platform, we retrieve data from it on the merchant’s behalf, using only the permissions the merchant grants, and we use that data only to provide the Service to that merchant.
- From Shopify: orders (order number, dates, status, totals, taxes, discounts, shipping charges, line items, refunds, and order and refund notes); products and inventory; and customer records identified by Shopify’s customer ID, with the customer’s email address, the number of orders, total spent, account state, tags, the country and region of the billing address, and email-marketing consent status. To attribute sales to marketing, we also keep each order’s landing page and the campaign parameters it carried, such as UTM values and advertising click identifiers.
- From affiliate platforms such as UpPromote: referral and commission records, including the referred customer’s email address and the affiliate’s name and email address, and the referral data the platform returns.
- From advertising platforms, when the merchant connects them: campaign, ad and spend metrics, which are aggregated and generally do not identify individuals.
Of the customer contact details Shopify protects, our Shopify app requests only email addresses. We use them to find a customer’s records when they make a privacy request and, when a merchant connects a marketing platform that sends email campaigns, to match those campaigns to the orders they produced. We do not request customers’ names, phone numbers or street addresses, so Shopify withholds them. Where a connected platform does provide contact details, we use them only to provide the Service to that merchant.
We do not sell this information, use it for advertising, combine one merchant’s information with another’s, or use it to develop, train or improve any product or service other than the Service we provide to that merchant. That includes artificial-intelligence models. If you are a customer of a store that uses WholeFrame, see section 9 for how to exercise your rights.
4. How we use information about you
- to provide and operate the Service, including signing you in and managing your organization and subscription;
- to answer your requests and send you service and security messages;
- to detect, investigate and prevent abuse, fraud and security incidents;
- to understand how the app is used, from aggregate page-view counts, so we can improve it;
- to review early-access requests and contact applicants;
- to comply with the law and enforce our Terms of Service.
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on these legal bases: performing our contract with you, for the account and the Service; our legitimate interests in securing the Service, understanding aggregate usage, running the early-access program and answering messages; compliance with legal obligations; and your consent, where we ask for it.
5. How we share information
- Service providers. We use a small number of service providers to host and run the Service: DigitalOcean (hosting, database storage, encrypted backups), Vercel (hosting of the app and this website, and cookieless page-view analytics) and GitHub (source code and deployment). The current list, with what each one does and where, is in Annex III of our Data Processing Addendum.
- Platforms you connect. When you connect a platform, we exchange data with it at your direction, for example to retrieve your orders from Shopify.
- Tools you authorize. If you create an API token and connect another tool, such as an AI assistant, that tool can read your organization’s analytics on your behalf.
- Legal and safety. When the law or legal process requires it, or to protect the rights, property or safety of WholeFrame, our users or the public.
- Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this policy.
We do not sell personal information and do not share it for cross-context behavioral advertising.
6. Where information is processed
We store and process information in the United States. Where we receive personal information from a merchant that is subject to the data protection laws of the European Economic Area, the United Kingdom or Switzerland, the Standard Contractual Clauses incorporated in our Data Processing Addendum apply.
7. How long we keep information
- Account information is kept while your account is open. If you ask us to close your account, we delete it, except what we must keep for legal, tax or security reasons; section 9 says how to ask and how quickly we act.
- Security and audit records are deleted after 365 days, except that a record of a change to your sign-in email is kept while your account exists, so that we can find and delete copies of your old address when you ask. The shortened network address and user-agent are removed from each record after 90 days.
- Early-access requests are kept until you ask us to delete them.
- Server logs. Our servers keep operational logs, for example the time of a request, the store it concerns, the IP address and browser it came from, any error, and, for a store installation or a customer privacy request, the email address or customer identifier involved. They stay on the server that wrote them and are not copied to any separate log store, except that we may keep a copy of the logs relevant to a security incident while we investigate it. They are deleted when the server process that wrote them is replaced, which happens with every release for our application servers, or overwritten once they reach a fixed size. Our hosting providers’ own request logs stay within their infrastructure. We use logs only to operate and secure the Service.
Information we process for merchants is kept while the store is connected, and then:
- Notifications from Shopify. We clear the contents of each notification Shopify sends us 30 days after we process it. A privacy instruction from Shopify that we have not yet been able to carry out is kept until we carry it out.
- Disconnected stores. If a Shopify store stays disconnected for 90 consecutive days, whether the app was uninstalled from it or Shopify was disconnected in WholeFrame, we erase its customers’ personal information. Thirty days later we permanently delete the store’s remaining records, including affiliate records filed under that store. Reconnecting the store before day 90 stops this.
- Deletion on request. When disconnecting Shopify in WholeFrame, a merchant can choose to delete the imported data now. Customers’ personal information is then erased immediately for every Shopify store in the merchant’s organization, and the stores’ remaining records are permanently deleted 30 days later.
- Disconnected advertising platforms. When a merchant disconnects an advertising platform such as Meta Ads in WholeFrame, we delete the access credential immediately and stop importing from it. The campaign, ad set and spend metrics already imported are kept while the merchant’s workspace is open and are deleted with the stores’ records when it is closed (section 9).
- Backups. Our nightly database backups are encrypted and are deleted automatically 28 days after they are taken, so information deleted from our database leaves our backups within 28 days.
These schedules are not a waiting period for privacy requests. We act on erasure and access requests forwarded by Shopify when we receive them.
8. Security
All traffic between your browser, the platforms you connect and our servers is encrypted with TLS. Our hosting provider encrypts the storage volumes our database runs on, so everything we store is encrypted at rest. On top of that, we encrypt customers’ names, phone numbers, street addresses, the email addresses Shopify sends us and every platform access credential with AES-256-GCM before storing them. Backups are encrypted before they are uploaded, never written to disk unencrypted, kept in a separate region, and restored automatically every week to prove they work. Every request for an organization’s data checks that the signed-in user is a member of that organization. Passwords must be at least 12 characters, are checked against a list of common and breached passwords, and are stored only as a one-way hash. Access to production systems is limited to the WholeFrame staff who operate the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights and choices
If you have a WholeFrame account, you can ask us to give you a copy of your personal information, correct it, delete it, restrict or object to how we use it, or close your account. Email support@wholeframe.io. We will confirm your identity and respond within 30 days. You can also change your name, preferences and password yourself in Settings.
If you connected Meta Ads or another advertising platform, you can remove our access at any time: disconnect the platform on the Integrations page in WholeFrame, which deletes the access credential immediately, or remove WholeFrame under Business Integrations in your Facebook settings. The campaign metrics we imported are deleted with the stores’ records when an organization admin closes the workspace in Settings, and the connection itself with the rest of the workspace; or email support@wholeframe.io and we reply to the address on file, end access at once and delete your data within 28 days.
Closing a workspace or deleting your account. An organization admin can close the workspace in Settings. That cancels the subscription and erases the customer information of its stores at once, and the rest of the stores’ records the next night. The team, settings and history are kept for 30 days so that an admin can reopen the workspace, and are then deleted, or deleted the next night if the admin chooses “Delete now”.
An organization admin can ask support@wholeframe.io to close the workspace; any user can ask us to delete their own account. We reply to the address on file, end access at once and delete your data within 28 days. Encrypted backups expire 28 days after they are taken.
If you are a customer of a store that uses WholeFrame, that store is responsible for your information, so please contact the store first. When a store receives your request through Shopify, Shopify forwards it to us and we act on it: an erasure request removes your identifying information from our records (a server log line about the request can keep the customer identifier until that log is deleted, as section 7 describes), and for an access request we give the store a copy of the information we hold about you to pass on to you. If you contact us directly, we will pass your request to the store if we can identify it, and tell you how to contact the store.
California residents have the right to know what personal information we collect and how we use it, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information. We will not treat you differently for exercising any of these rights, and you may use an authorized agent to make a request.
If you are in the European Economic Area, the United Kingdom or Switzerland, you may also complain to your data protection supervisory authority.
10. Cookies and browser storage
Our marketing website sets no cookies. The WholeFrame app stores your sign-in tokens in your browser’s local storage to keep you signed in, and remembers display preferences, such as whether the sidebar is open and which banners you dismissed, in local storage and one preference cookie. While you install WholeFrame from Shopify, the app sets two short-lived security cookies that complete the installation and your account setup. When you sign in with your password, the app also sets a security cookie that lets this browser skip sign-in waits caused by other people’s wrong guesses at your password; it lasts 90 days, and signing out removes it. We use no advertising or tracking cookies. Blocking browser storage will stop you from signing in.
11. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
12. Changes to this policy
We will update the “Last updated” date above whenever we change this policy. If a change is material, we will tell account holders by email or in the app before it takes effect.
13. Contact us
WHOLEFRAME LLC
5 Bartlett Street
Newton, NH 03858
United States
support@wholeframe.io