Privacy Policy
Rinteo is an email marketing app for Shopify stores. This policy explains what personal data Rinteo processes, why, who it is shared with and how long it is kept.
1. Who we are
Rinteo is operated by Rinteo, operated by Arsen Tomyn, Warsaw, Poland (“Rinteo”, “we”). Contact: support@rinteo.com.
We act in two roles:
- Controller for data about merchants who install Rinteo (the store and its account with us).
- Processor for data about a merchant’s customers, which we process on the merchant’s instructions under our Data Processing Agreement. For that data the merchant is the controller; customers can also contact the store directly.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Store data | Shop name and myshopify.com domain, contact email, currency, locale, time zone, plan and billing status | Shopify |
| Customer data | Name, email address, address (the country of the default address only), email marketing consent, customer tags, time zone and lifetime order totals | The merchant’s Shopify store |
| Product and order data | Products, variants, collections, orders, order items, refunds and checkouts (with the buyer’s email and the items) | The merchant’s Shopify store |
| Email activity | Which emails were sent and delivered, bounces, spam complaints, unsubscribes, opens and clicks with the time and the browser’s user agent | Our sending and tracking systems |
| Content and settings | Email templates, campaigns, flows, lists, segments, sender name and address, sending domain | The merchant |
| Support | Messages you send to support@rinteo.com | You |
We do not store IP addresses for opens or clicks, we do not read customers’ phone numbers, and we do not use payment card data — Shopify bills paid plans.
3. Why we use it
- App functionality — syncing the store, building lists and segments, sending campaigns and flow emails, honouring unsubscribes and writing them back to Shopify, and preventing abuse (bounce and complaint monitoring).
- Analytics — reports for the merchant: deliveries, opens, clicks and attributed revenue (orders placed after a click in an email). Attributed revenue is a measurement, not a statement that an email caused a purchase.
- Personalization — filling an email with a customer’s name, their cart or order items and store products.
- Marketing — sending the merchant’s own email marketing to their customers on the merchant’s instructions, and our own service messages to merchants.
For data where we are the controller, the legal bases are performance of our contract with the merchant, our legitimate interest in running and securing the service, and consent where the law requires it. For customer data, the merchant determines the legal basis (for marketing email, usually consent).
4. Who we share it with
We do not sell personal data. We share it only with the service providers (subprocessors) that run Rinteo:
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, authentication, file storage and server functions |
| Vercel | Hosting of the app and this website |
| SendGrid (Twilio) | Email delivery and delivery events |
| Cloudflare | Network delivery and protection in front of our servers |
| Shopify | The platform Rinteo runs in: source of store data, app installation and billing |
We may also disclose data when the law requires it. Some providers process data outside the European Economic Area; where they do, transfers rely on the European Commission’s Standard Contractual Clauses or another lawful mechanism.
5. How long we keep it
- Store, customer, product and order data is kept while Rinteo is installed. After an uninstall Rinteo stops sending at once.
- When Shopify sends the shop/redact request (48 hours after an uninstall), we delete the store’s data: customers, orders, products, checkouts, lists, segments, templates, campaigns, flows and email activity.
- When Shopify sends customers/redact for a customer, we delete that customer’s profile, email activity and sends, and remove their email address from orders.
- When Shopify sends customers/data_request, we prepare an export of the data we hold about that customer for the merchant.
- Checkouts that never became orders are deleted after 30 days.
- To honour unsubscribes and complaints, a suppression entry (email address, reason and date) is kept for the store, also after its other data is deleted.
6. Security
Data is encrypted in transit. Shopify access tokens are encrypted at rest, and every store’s data is isolated at the database level. Access is limited to what is needed to run and support the service. If a security incident affects personal data, we notify Shopify within 24 hours and the affected merchants without undue delay.
7. Your rights
Depending on where you live, you can ask to access, correct, delete or export your data, object to or restrict its use, and withdraw consent. Merchants can write to support@rinteo.com. Customers of a store should contact the store first; requests made through Shopify reach us automatically. Every marketing email has an unsubscribe link. You can also complain to your data protection authority.
8. Children
Rinteo is a business tool and is not directed at children.
9. Changes
We will post changes on this page with a new effective date, and tell merchants in the app or by email about material changes.