← Return to DFA demo store
Dollflow

Privacy at Dollflow

Privacy, without the mystery.

This policy explains what information Dollflow processes, why it is needed, who helps us provide the service, and how it is protected or deleted.

Last updated October 2, 2026
Never soldNo advertising or data-broker use.
Merchant controlledCustomer data follows the merchant’s instructions.
Time limitedBooking data is anonymized after 24 months.
01

Who this policy covers

Dollflow is an appointment-booking application operated by Great Big AB for Shopify merchants. This policy applies when a merchant installs or uses Dollflow, a customer books or manages an appointment, joins a waitlist, uses a membership credit, or receives a Dollflow notification.

Merchant and processor roles

The Shopify merchant decides why and how its customer information is used and normally acts as the controller. Dollflow processes that information on the merchant’s behalf to provide the service. Our Data Processing Addendum explains those responsibilities in more detail.

02

Information we process

Merchant and app data

Shop domain, Shopify app sessions and user details, settings, subscription plan, notification address, service catalog, prices, working hours, team members, and internal configuration.

Bookings and waitlists

Customer name, email, optional telephone number, locale, booking message, intake answers, requested service, specialist, date, time, status, recurrence details, and waitlist preferences or offers.

Payments and memberships

Shopify customer, order, line-item, transaction and refund references; recorded amounts and payment methods; membership product, credit, redemption, expiry, and verification records.

Communications and operations

Email or SMS delivery status, reminder attempts, support information a user provides, security events, and pseudonymous protected-data access records. Audit logs are designed not to contain raw customer contact details, notes, tokens, or message content.

Information comes from the merchant, the customer, Shopify, and—only when the merchant connects it—Google Calendar. Merchants should request only information reasonably necessary to provide the selected service and should avoid unnecessary sensitive information in free-text fields.

03

How information is used

  • Provide storefront booking, merchant administration, waitlists, recurring appointments, memberships, payments, and customer self-service.
  • Calculate real availability and prevent double bookings using working hours, existing appointments, active holds, and connected calendar conflicts.
  • Send confirmations, reminders, cancellation, rescheduling, membership, verification, and waitlist messages in the selected language.
  • Synchronize appointments with Google Calendar when the merchant enables that integration.
  • Provide operational analytics, payment review, accountant exports, support, fraud prevention, security, compliance, and service reliability.

We do not sell personal information, use it for interest-based advertising, or provide it to data brokers. For customer data processed on a merchant’s behalf, the merchant is responsible for identifying an appropriate legal basis and providing any notices or consents required by applicable law.

04

Google Calendar data

Optional merchant connection

Only the calendar access needed for scheduling

Dollflow requests Google’s calendar.freebusy and calendar.events permissions. They are used to check busy times and to create, update, or delete appointment events requested through Dollflow.

When connected, we process the merchant’s Google account email, selected calendar identifiers, encrypted OAuth access and refresh tokens, token expiry information, granted scopes, busy-time responses, and event identifiers. An appointment event can contain the service, customer name, contact details, booking message, start time, and end time so the merchant can manage the visit from its calendar.

Google data is used only to provide or improve Dollflow’s visible calendar features, secure the service, comply with law, or as otherwise permitted by the Google API Services User Data Policy. It is not used for advertising, credit decisions, surveillance, or sale. Human access is restricted to cases where the user authorizes support access, access is necessary for security or legal compliance, or the information is aggregated and contains no personal data. Merchants can disconnect Google Calendar at any time.

See the dedicated Google User Data Disclosure for scope, storage, disconnection, and Limited Use details.

05

Service providers and sharing

We disclose information only as needed to operate Dollflow, follow a merchant’s instructions, protect the service, complete a business transfer with appropriate safeguards, or comply with law. Current service providers include:

ShopifyCommerce platform, app authentication, orders, and payments
Fly.ioApplication hosting
SupabaseDatabase hosting
GoogleOptional Calendar connection
ResendTransactional email delivery
TwilioOptional SMS reminder delivery

These providers process information under their own terms and applicable contractual safeguards. The merchant and its authorized staff can access customer information belonging to their shop. See the current Subprocessors list.

06

Retention and deletion

24
months after the appointment or requested waitlist date

Personal booking information is anonymized and old waitlist records are deleted through automated retention controls.

When a booking is anonymized, customer contact details, messages, intake answers, reminder-delivery records, payment-provider references, and connected calendar-event references are removed. Non-personal appointment facts may remain for merchant reporting. Expired membership and verification records are removed according to their operational lifecycle; transaction or membership records may be retained while needed for the merchant account, refunds, accounting, fraud prevention, or legal obligations.

Customer information can be deleted earlier through Shopify’s mandatory customer-redaction process. After uninstall, shop data is deleted when Shopify sends its shop-redaction request, unless retention is required by law. Pseudonymous security logs and non-personal monthly archives are deleted with the shop or retained only while an active operational or legal need exists.

Our Data Retention Policy provides the record-by-record schedule and deletion details.

07

Your choices and rights

Depending on applicable law, a person may have rights to access, correct, delete, restrict, object to, or export personal information, and may be able to withdraw consent. Customers should first contact the Shopify merchant that collected their booking information. Dollflow assists merchants with verified requests and responds to Shopify’s customer data-request and redaction webhooks.

Merchants can change notification settings, disable optional SMS, disconnect Google Calendar, or uninstall Dollflow. Privacy requests sent directly to us may require identity and authority verification before we act.

08

Security and international transfers

Dollflow uses encrypted transport, access controls, merchant-data separation, encrypted Google OAuth tokens, hashed single-use verification and waitlist tokens, pseudonymous access logging, dependency maintenance, and tested retention and deletion procedures. No internet service can guarantee absolute security.

Service providers may process information in countries other than where it was collected. Where required, we use recognized safeguards such as adequacy decisions, data-processing agreements, or standard contractual clauses.

09

Contact and updates

Great Big AB may update this policy when Dollflow’s features, providers, or legal obligations change. Material changes will be communicated where required, and the date at the top of this page will be updated.

Privacy contactGreat Big AB · Dollflow
dollflowapp@gmail.com