Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how One Nine Media Group Limited (“we”, “us”, “our”) collects, uses, shares and protects personal data in connection with Storeloop (the “Service”), our order-editing and post-purchase application for Shopify merchants. We are the data controller for the personal data described in this policy, except where we act as a data processor on behalf of a merchant as set out below.
One Nine Media Group Limited
Registered in England & Wales, company number 15597358
Registered address: 167-169 Great Portland Street, London, Greater London, England, W1W 5PF
Contact: info@storeloop.io
1. Who this policy applies to
This policy applies to (a) merchants who install and use Storeloop, and (b) the customers of those merchants whose order information passes through the Service. For merchants’ end customers, we generally act as a data processor on behalf of the merchant, who remains the data controller of their customers’ personal data.
2. Personal data we collect
From merchants, we collect the account and contact details provided on sign-up (such as name, business email, store domain) and billing status held by Shopify.
To provide order-editing and upsell features, the Service processes order and customer data made available by the Shopify store, which may include: customer name, email address, shipping and billing address, contact details, order contents, order totals and fulfilment status. We access this data only to the extent needed to deliver the features the merchant has enabled.
We also collect limited technical data (such as IP address, browser type and usage logs) to operate, secure and improve the Service.
3. How we use personal data
- To provide the Service, including applying customer-requested edits, upsell offers and receipts back to the Shopify order.
- To authenticate requests, prevent fraud and abuse, and keep the Service secure.
- To provide support, respond to enquiries and send service-related communications.
- To manage billing and subscriptions (handled by Shopify).
- To analyse and improve the Service and produce aggregate, non-identifying statistics.
4. Legal bases
Where we act as a controller, we rely on: performance of a contract (to provide the Service you have signed up for); our legitimate interests (to secure, support and improve the Service); and, where required, consent. Where we act as a processor, the merchant is responsible for establishing the lawful basis for processing their customers’ data.
5. Sharing and sub-processors
We do not sell personal data. We share data only with service providers who help us run the Service, under contractual confidentiality and data-protection obligations. These include:
- Shopify — the platform the Service is built on and the source of order data.
- Vercel — application and website hosting.
- Supabase — database hosting for Service configuration and order-edit records.
We may also disclose data where required by law or to protect our rights, users or the public.
6. International transfers
Some of our providers may process data outside the UK/EEA. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
7. Data retention
We retain merchant account data for as long as the account is active and as needed to comply with legal obligations. Order-edit records are retained only for the period necessary to provide the Service and support merchants, after which they are deleted or anonymised. When a merchant uninstalls Storeloop, we delete or anonymise associated store data in line with Shopify’s data-protection requirements, typically within 30 days.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. If you are a merchant’s customer, please contact the merchant in the first instance, as they control your data. To exercise any right with us, email info@storeloop.io. You also have the right to complain to the UK Information Commissioner’s Office (ICO).
9. Cookies
The Storeloop marketing site uses only essential cookies needed for the site to function. We do not use advertising cookies. The Storeloop application operates within the Shopify admin and checkout and uses tokens strictly to authenticate and secure requests.
10. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls and signed, time-limited tokens for sensitive actions. No method of transmission or storage is completely secure, but we work to protect your data and review our measures regularly.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to merchants.
12. Contact
Questions about this policy or our data practices can be sent to info@storeloop.io.