Privacy Policy
Workify helps small commerce brands understand their own profitability by reading the sales and marketing data they choose to connect - and nothing else. This policy explains, in plain language, what data we process, why, how we protect it, and the rights you have. We don't sell your data, we don't run ads, and we don't use your data to train or fine-tune AI models.
1. Who we are, and our role
Workify is operated by Workify ApS, CVR 46607031, Strandvejen 34, 4. tv, 8000 Aarhus C, Denmark - in the European Union. You can reach us at privacy@workify.io. We act in two distinct roles, and the rules differ for each:
- For the data you connect from your stores and ad accounts (Shopify, Meta, and - when activated - Google Analytics), you are the data controller and Workify is a data processor. We process that data only on your documented instructions, for one purpose: showing you your own business. A Data Processing Agreement (DPA) governs this and is available to every customer.
- For your Workify account itself (your name, work email, login, and billing details), Workify is the data controller, and this policy is your information notice under Articles 13-14 GDPR.
2. What data we process
- From Shopify (when you connect a store): orders, products, inventory, refunds, and a pseudonymous customer identifier(a Shopify customer GID). This is "Protected Customer Data" at Level 1. We deliberately do not read or store customer names, email addresses, phone numbers, or postal addresses(Shopify's protected customer fields / Level 2) - we never receive them. The pseudonymous identifier is obtained from the connecting merchant's Shopify store records, not from the individual directly, and we process it as the merchant's processor.
- From Meta (when you connect an ad account): aggregate ad-account insights only - ad spend, impressions, clicks, and purchase/conversion counts - via the read-only
ads_readpermission. These are aggregate numbers, not data about individual people. - From Google Analytics (a future option, not yet active): aggregate traffic and session metrics via the read-only
analytics.readonlyscope. - Your account data: the name and work email you register, and organisation and billing identifiers. Providing this is necessary to enter into and perform our contract with you - without it we cannot create or operate your account.
- Automatically: authentication/login data and basic logs - including security and diagnostic logs (e.g., IP address, timestamps) and basic records of how you use the app (feature usage, request timestamps) - generated to operate, secure, and improve the service.
- Access tokens: the credentials that let us read your connected data are stored encrypted and are never shown to anyone.
3. Why we process it, and our legal basis
- To provide the service - connecting your data and showing you your dashboards and insights. Legal basis: performance of our contract with you (Art. 6(1)(b)).
- To secure and improve Workify - preventing fraud and abuse, keeping the service reliable, and improving it using our own account and product-usage data (the data for which Workify is the controller). Legal basis: our legitimate interests (Art. 6(1)(f)) in running a safe, working product; we balance these against your rights and can share our assessment on request.
- To meet legal obligations, such as keeping accounting records. Legal basis: legal obligation (Art. 6(1)(c)).
- Optional marketing emails or non-essential cookies. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
The store and ad-account data you connect is processed only on your documented instructionsunder the DPA, to deliver your analytics - never for Workify's own product improvement and never to train or fine-tune AI or machine-learning models. We do not sell your data or share it for anyone else's marketing.
Automated decisions: we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR). Our insights and anomaly flags are decision-support for you - not automated decisions about individuals.
4. Who we share it with (sub-processors)
We share data only with the infrastructure providers needed to run Workify, each under a data-processing contract:
- Supabase - database hosting and encrypted token storage, in Frankfurt, EU.
- Vercel - application hosting (EU region).
- Resend - sending transactional emails (sign-in confirmations and notifications).
- Zoho Mail - our business email inboxes (e.g., support@ and invoice@ workify.io) used to correspond with you.
We also name the sources you connect (Shopify, Meta, and - when activated - Google) for transparency. We do not sell or rent your data to anyone, and we never share it for third-party advertising. A current, dated list of sub-processors is available on request, and we give notice before adding a new one so you can object.
5. Where your data is processed
The data you connect is hosted and processed in the European Union (Supabase, Frankfurt; Vercel EU region). Our email providers - Resend (transactional emails) and Zoho Mail (our support and billing inboxes) - may process email correspondence outside the EU/EEA; where they do, we rely on an approved transfer mechanism (the EU-US Data Privacy Framework or the European Commission's Standard Contractual Clauses) together with appropriate safeguards. You can request a copy of the relevant safeguards at privacy@workify.io.
6. How long we keep it, and how to delete it
We keep connected data only as long as needed to provide the service. When you disconnect a store or ad account, or remove our app, we purge the associated data and destroy the encrypted access token - completed permanently within 30 days. You can also ask us to delete your data at any time by emailing privacy@workify.io, with the same 30-day window. Security and diagnostic logs are retained for up to 12 months and then deleted.
Accounting records (e.g., invoices) are kept for the statutory bookkeeping period required by Danish law (currently 5 years). This 5-year retention applies only to accounting records - never to the sales and marketing data you connect, which is purged as described above.
How to request deletion. Email privacy@workify.io at any time. For Meta-connected data you can also remove Workify from your Facebook / Meta settings, which triggers our automatic purge of the associated ad-insights data and destruction of the token; this section also serves as our Data Deletion Instructions for Meta. For Shopify, we act on Shopify's mandatory data-request and erasure webhooks (customers/data_request, customers/redact, shop/redact) and complete any webhook-driven erasure within the same 30-day window.
7. How we protect it
We encrypt data in transit (TLS) and at rest, store access tokens encrypted in a dedicated secrets vault, restrict access to what's necessary, and minimise the personal data we process - we stay at Shopify Protected Customer Data Level 1, with no customer names, emails, phone numbers, or addresses.
Because we never receive a store's customer contact details, and never market to or make automated decisions about a store's customers, we do not override any customer consent or data-sharing opt-out - we respect the consent state the merchant maintains in their store.
8. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, and port your data, and to object to processing; where we rely on consent, you can withdraw it at any time. To exercise any of these, email privacy@workify.io- it's free and we respond within one month. For data you connected from your store or ad account, we act as processor and will assist you (the controller) or forward your request as appropriate.
You always have the right to lodge a complaint with a data protection authority. In Denmark this is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby · dt@datatilsynet.dk · +45 33 19 32 00 · datatilsynet.dk.
9. Google API Services - Limited Use
When you connect Google Analytics, Workify integrates with Google APIs. The use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide the analytics features visible in Workify; we do not transfer or sell it, do not use it for advertising, and do not use it to train or fine-tune AI or machine-learning models.
10. Cookies
We use only the cookies and local storage needed to keep you signed in and to keep the service secure. We don't use advertising cookies. If we ever add optional analytics, we'll ask for your consent first.
11. Children
Workify is a business tool, not intended for children, and we do not knowingly collect data from anyone under 16.
12. Changes to this policy
If we change how we handle your data, we'll update this page and the "last updated" date and - where the law requires it - ask for your consent before the new use takes effect.
13. Contact
Privacy questions, requests, or concerns: privacy@workify.io. Workify ApS, CVR 46607031, Strandvejen 34, 4. tv, 8000 Aarhus C, Denmark (EU).