Last updated 27 July 2026
RedeemWise is a Shopify app published by MALVI. This policy explains what the app stores, what it does not store, and how to reach us.
RedeemWise does not store customer names, addresses, phone numbers or email addresses — it does not even request access to them, so Shopify redacts them from our API responses. Its own database holds no customer identifiers of any kind. Points balances live in Shopify, on the customer record, not on our servers.
If you are a merchant evaluating the app, the Data Processing Agreement sets out our obligations to you in full.
For each shop that installs the app, our database holds:
The audit record is keyed on the order, never on the customer, and contains no direct customer identifier — no name, email address, phone number, postal address, or customer ID. An order ID can be linked back to a customer by the merchant within their own Shopify admin, so we treat it as personal data and delete it as described below.
To apply and reconcile a redemption, the app reads a customer's points balance and, when an order is paid, cancelled or refunded, that order's customer reference and discount total. This data is used in the moment and is not written to our database. Under Shopify's protected customer data framework this is Level 1 access; the app does not request name, address, phone or email.
Our logs record shop domains, order IDs, and — for the Flow actions that credit or debit a balance — customer IDs, so that a merchant's question about a specific balance can be answered. They contain no names, email addresses, phone numbers or addresses. Logs are held by Cloudflare under their retention period and are used only to diagnose faults.
A customer's balance is stored as an app-owned metafield on the customer record inside your Shopify store. You can view and edit it in your Shopify admin. It is your data, held by Shopify, and it is not copied to our servers.
While the app is installed we keep the redemption audit record for the life of the installation. It is the only record of what the app did to a balance, and it is what a merchant needs when a customer disputes one.
shop/redact — 48 hours after uninstall, Shopify asks us to erase everything for your shop, and we delete all remaining records including the redemption audit log.customers/redact — we hold no customer data, so there is nothing to erase. We log the request and confirm receipt.The app runs on Cloudflare Workers with a Cloudflare D1 database. Cloudflare is our only sub-processor. We do not sell or share data with anyone else, and there are no third-party analytics or advertising scripts in the app or its storefront blocks.
Questions, data requests, or anything else: dev@mal-vi.com.