Smaily Connect — Privacy Policy
Smaily Connect (“the app”) connects an e-commerce store (Shopify, WooCommerce, and other supported platforms) to the merchant’s own Smaily email-marketing account and, optionally, to Smaily Campaign Intelligence. This policy explains what data is processed, why, where it goes, and how it is protected, on every platform Smaily Connect supports; where the mechanics differ by platform, this policy says so explicitly. The app is operated by Sendsmaily OÜ.
Data we process
- Customer name and email address — to sync the merchant’s subscribers and customers to the merchant’s own Smaily account, and (only when the merchant uses the Campaign Intelligence add-on) as Campaign Intelligence’s per-customer identity.
- Order and product / catalog data — to power automations (welcome, first order, abandoned cart) and, when enabled, product recommendations.
- Anonymous browse events — collected through a consent-gated mechanism specific to each platform: on Shopify, a sandboxed Web Pixel gated by Shopify’s customer-privacy (consent) API; on WooCommerce, a first-party script gated by the WordPress Consent API, off by default.
We request only the customer fields the app needs — name and email. We do not request phone numbers or postal addresses.
How we use it
- Syncing the merchant’s subscribers and contacts to their Smaily account, gated by marketing consent.
- Triggering the merchant’s chosen Smaily automations.
- Generating personalized product recommendations (optional paid add-on).
We do not sell personal data, and we do not use it for any purpose beyond those stated above.
Where data goes
- Always (core): the merchant’s own Smaily account.
- Conditional (paid add-on): Smaily Campaign Intelligence — only if the merchant subscribes to the Campaign Intelligence service. It is not enabled by default. The Campaign Intelligence API key is never exposed to the storefront.
Security
- Credentials and API keys are encrypted at rest (AES-256-GCM).
- All data is transmitted over HTTPS.
- Each store’s data is strictly isolated from every other store.
Data retention and deletion
How local data is stored and removed depends on how the platform is deployed:
- Shopify (hosted app): the app stores merchant and integration data in its own hosted database. Uninstalling triggers Shopify’s
shop/redactrequest, which purges all of the app’s hosted records for that store. The app also prunes its own operational records automatically (event logs and transient queue / checkout records are kept only for a limited period). - WooCommerce (self-hosted plugin): the plugin runs on the merchant’s own server, so there is no equivalent Smaily-side hosted app storage for this platform — the plugin’s local data (recommendation-engine markers on orders and users, and, if enabled, abandoned-cart session data) lives only in the merchant’s own WordPress database. Uninstalling the plugin removes that locally-stored data from the merchant’s WordPress database.
- Uninstalling (on any platform) does not automatically delete the merchant’s data held in Smaily or Campaign Intelligence — a merchant may uninstall only to switch e-commerce platforms while keeping their Smaily account and history. That data is retained under Smaily’s retention policy and is removed when the merchant explicitly closes those services, or on request (see “Your rights” below).
- Recommendation-engine retention (Smaily Campaign Intelligence, where enabled): anonymous browse events and visitor tokens are kept for up to 90 days and then automatically deleted; computed recommendations and attribution records are kept for up to 730 days; email-interaction signals are kept for up to 365 days. Order and customer data is kept for the duration of the merchant’s relationship with Smaily, or until erasure is requested.
Your rights
A specific individual’s data can be erased at any time, whether or not the app or plugin is currently installed. The mechanism depends on the platform:
- Export: on Shopify, the
customers/data_requestwebhook returns an export of the data we hold for that customer; on WooCommerce, the merchant runs WordPress’s native Privacy Tools (Export Personal Data), which export both the plugin’s own locally-stored data and the corresponding recommendation-engine data. - Erasure: on Shopify, the
customers/redactwebhook, or a direct request, deletes that customer’s data from Campaign Intelligence and from Smaily; on WooCommerce, the merchant runs WordPress’s native Privacy Tools (Erase Personal Data), which erase both the plugin’s own locally-stored data and the corresponding recommendation-engine data via the engine’s GDPR deletion API.
To exercise access, correction, or deletion rights, contact us at info@smaily.com.
Contact
Sendsmaily OÜ — info@smaily.com