oorava

Privacy Policy

Effective date: September 22, 2026

This Privacy Policy explains how Tim Ambi, operating as oorava ("oorava," "we," "us," or "our"), collects, uses, shares, and deletes information when a Shopify merchant installs or uses the oorava application.

Information we collect

oorava processes the information needed to provide customer progression through Shopify Flow:

  • Merchant store domain, app configuration, billing status, and Shopify app session information, including account identifiers, contact fields, locale, access scopes, and authentication tokens supplied by Shopify.
  • Shopify customer identifiers supplied to oorava actions and order identifiers supplied through actions and order-created webhooks.
  • Points balances, levels, achievements, pending points, rewards, and related activity history.
  • Custom level names, achievement names and descriptions, and reward names mirrored to Shopify so merchants can manage their translations.
  • Reasons, reward codes, expiry dates, and other details a merchant submits through oorava actions.
  • Optional customer image metafield values and image URLs used by the customer-account extension when configured by the merchant. The extension reads these values directly from Shopify to display the image, or displays a merchant-configured fallback image. This feature does not store the customer image or metafield value in oorava's database.
  • Roadmap request titles and descriptions, votes, and related timestamps submitted through oorava.
  • Technical logs needed to secure, diagnose, and operate the application, which may include store identifiers, event identifiers, and error details.

Current progression features use Shopify customer and order identifiers rather than customer names or email addresses. oorava does not require customer payment details or shipping addresses.

Cookies

oorava uses a first-party cookie for up to one year to remember the application language determined from your selection, the page URL, or your browser settings. Authentication is handled through Shopify and does not rely on this preference cookie.

How we use information

We use this information only to:

  • Provide, secure, maintain, and troubleshoot oorava.
  • Process Shopify Flow actions and return progression results.
  • Display progression and activity to the merchant that controls the store and to the associated authenticated customer.
  • Operate the shared product roadmap and allow merchants to submit requests and vote.
  • Prevent duplicate processing, measure created-order billing usage, and comply with legal and Shopify requirements.

We do not sell merchant or customer information or use it for advertising.

How we share information

We share information with Shopify as required to operate the app, including translatable level, achievement, and reward definition content, and respond to Shopify's mandatory privacy processes. Our application and database are hosted by Google Cloud in Tokyo, Japan. Roadmap request titles, descriptions, dates, and vote totals are visible to other oorava merchants. We do not display the identity of the store that submitted or voted for a request alongside it, but identifying information included in a request's title or description is visible to other merchants. Please do not include personal or confidential information in roadmap submissions. Service providers may process information only to provide their contracted services to us. We may also disclose information when required by law or to protect rights, safety, and application security.

Retention and deletion

We retain information while the app is installed and as needed to provide oorava. We delete Shopify app sessions when the app is uninstalled. Uninstalling does not immediately delete other stored shop data, including customer progression and activity history; that data is deleted through Shopify's shop redaction process described below. We delete affected customer data when Shopify sends a customer redaction request, and delete shop-scoped data when Shopify sends a shop redaction request, unless applicable law requires retention. Roadmap requests may remain as anonymous product feedback after their association with a store and that store's votes are deleted. When Shopify sends a customer data request, oorava records the request so the authenticated merchant can download the related customer progression data in the app. Request records are deleted with the affected customer or shop.

Security and international processing

We use reasonable administrative and technical safeguards designed to protect information. No method of storage or transmission is completely secure. Information may be processed in Tokyo, Japan, and other locations where our service providers operate, subject to applicable data-protection requirements.

Your choices and rights

Merchants can uninstall oorava at any time. Merchants and customers may request access, correction, export, or deletion of personal information, subject to applicable law. Customers may contact the Shopify merchant they interacted with or contact us directly. Requests are handled through Shopify's mandatory privacy webhooks or through the contact address below. We may need to verify a request before completing it.

Changes to this policy

We may update this policy when our practices or legal obligations change. We will publish the updated policy here and revise its effective date.

Contact us

Questions or privacy requests can be sent to [email protected].