← AlliDesk

Privacy policy

Last updated 10 September 2026.

What AlliDesk is

AlliDesk is a Shopify app that gives a store’s customers an account portal (orders, wishlist, loyalty points, referrals, returns, reviews) and gives the merchant the tools to run those programs. The merchant installs it on their store; AlliDesk processes data on the merchant’s behalf.

What we collect

From Shopify, only what the features need: customer name, email, phone and addresses; orders and their items, payment status, fulfilment and tracking; product titles and prices for saved items; inventory levels for alerts. From the portal: what the customer saves, redeems, requests and reviews. From the merchant: their account email, name and the settings they choose. We do not collect payment card details.

How we use it

To show customers their own orders and account, to calculate and record loyalty points, to run returns and exchanges, to send the messages the merchant has switched on (order updates, points, reminders, review requests), to alert the merchant, and to count monthly orders for billing. We do not sell data, and we do not use it for our own advertising.

Who else sees it

Only processors needed to deliver the service: our hosting and database provider, the email provider (Resend), and, when the merchant connects them, their WhatsApp (Meta), SMS (MSG91) and courier accounts, which receive only what a message or a pickup needs.

How long we keep it

The merchant’s own records — orders, invoices, reviews, points, memberships and warranties — are kept for as long as the store has the app installed, because they are the books the merchant is asking us to keep. When a store uninstalls, all of its data is deleted within 48 hours of Shopify’s shop-redact request, and customer data-request and redact webhooks are honoured automatically.

Everything else exists only so the app can run, and is deleted on a schedule by a job that runs every day:

Security

Data travels over HTTPS, and the database and job queue sit on an encrypted volume (LUKS2, AES-256-XTS), so personal data is encrypted at rest as well as in transit. Backups are separately encrypted with AES-256 and every backup is proved decryptable in the run that makes it. The database and its server are reachable only from the application; the database publishes no port at all, and administrative access is by SSH key, limited to the people who operate the service. Requests to the service are logged, and we keep a written procedure for handling a security incident.

Contact

Questions or requests about your data: privacy@allidesk.com.