Who this policy covers
Dollflow is an appointment-booking application operated by Great Big AB for Shopify merchants. This policy applies when a merchant installs or uses Dollflow, a customer books or manages an appointment, joins a waitlist, uses a membership credit, or receives a Dollflow notification.
The Shopify merchant decides why and how its customer information is used and normally acts as the controller. Dollflow processes that information on the merchant’s behalf to provide the service. Our Data Processing Addendum explains those responsibilities in more detail.
Information we process
Merchant and app data
Shop domain, Shopify app sessions and user details, settings, subscription plan, notification address, service catalog, prices, working hours, team members, and internal configuration.
Bookings and waitlists
Customer name, email, optional telephone number, locale, booking message, intake answers, requested service, specialist, date, time, status, recurrence details, and waitlist preferences or offers.
Payments and memberships
Shopify customer, order, line-item, transaction and refund references; recorded amounts and payment methods; membership product, credit, redemption, expiry, and verification records.
Communications and operations
Email or SMS delivery status, reminder attempts, support information a user provides, security events, and pseudonymous protected-data access records. Audit logs are designed not to contain raw customer contact details, notes, tokens, or message content.
Information comes from the merchant, the customer, Shopify, and—only when the merchant connects it—Google Calendar. Merchants should request only information reasonably necessary to provide the selected service and should avoid unnecessary sensitive information in free-text fields.
How information is used
- Provide storefront booking, merchant administration, waitlists, recurring appointments, memberships, payments, and customer self-service.
- Calculate real availability and prevent double bookings using working hours, existing appointments, active holds, and connected calendar conflicts.
- Send confirmations, reminders, cancellation, rescheduling, membership, verification, and waitlist messages in the selected language.
- Synchronize appointments with Google Calendar when the merchant enables that integration.
- Provide operational analytics, payment review, accountant exports, support, fraud prevention, security, compliance, and service reliability.
We do not sell personal information, use it for interest-based advertising, or provide it to data brokers. For customer data processed on a merchant’s behalf, the merchant is responsible for identifying an appropriate legal basis and providing any notices or consents required by applicable law.
Google Calendar data
Optional merchant connection
Only the calendar access needed for scheduling
Dollflow requests Google’s calendar.freebusy and calendar.events permissions. They are used to check busy times and to create, update, or delete appointment events requested through Dollflow.
When connected, we process the merchant’s Google account email, selected calendar identifiers, encrypted OAuth access and refresh tokens, token expiry information, granted scopes, busy-time responses, and event identifiers. An appointment event can contain the service, customer name, contact details, booking message, start time, and end time so the merchant can manage the visit from its calendar.
Google data is used only to provide or improve Dollflow’s visible calendar features, secure the service, comply with law, or as otherwise permitted by the Google API Services User Data Policy. It is not used for advertising, credit decisions, surveillance, or sale. Human access is restricted to cases where the user authorizes support access, access is necessary for security or legal compliance, or the information is aggregated and contains no personal data. Merchants can disconnect Google Calendar at any time.
See the dedicated Google User Data Disclosure for scope, storage, disconnection, and Limited Use details.
Service providers and sharing
We disclose information only as needed to operate Dollflow, follow a merchant’s instructions, protect the service, complete a business transfer with appropriate safeguards, or comply with law. Current service providers include:
These providers process information under their own terms and applicable contractual safeguards. The merchant and its authorized staff can access customer information belonging to their shop. See the current Subprocessors list.
Retention and deletion
Personal booking information is anonymized and old waitlist records are deleted through automated retention controls.
When a booking is anonymized, customer contact details, messages, intake answers, reminder-delivery records, payment-provider references, and connected calendar-event references are removed. Non-personal appointment facts may remain for merchant reporting. Expired membership and verification records are removed according to their operational lifecycle; transaction or membership records may be retained while needed for the merchant account, refunds, accounting, fraud prevention, or legal obligations.
Customer information can be deleted earlier through Shopify’s mandatory customer-redaction process. After uninstall, shop data is deleted when Shopify sends its shop-redaction request, unless retention is required by law. Pseudonymous security logs and non-personal monthly archives are deleted with the shop or retained only while an active operational or legal need exists.
Our Data Retention Policy provides the record-by-record schedule and deletion details.
Your choices and rights
Depending on applicable law, a person may have rights to access, correct, delete, restrict, object to, or export personal information, and may be able to withdraw consent. Customers should first contact the Shopify merchant that collected their booking information. Dollflow assists merchants with verified requests and responds to Shopify’s customer data-request and redaction webhooks.
Merchants can change notification settings, disable optional SMS, disconnect Google Calendar, or uninstall Dollflow. Privacy requests sent directly to us may require identity and authority verification before we act.
Security and international transfers
Dollflow uses encrypted transport, access controls, merchant-data separation, encrypted Google OAuth tokens, hashed single-use verification and waitlist tokens, pseudonymous access logging, dependency maintenance, and tested retention and deletion procedures. No internet service can guarantee absolute security.
Service providers may process information in countries other than where it was collected. Where required, we use recognized safeguards such as adequacy decisions, data-processing agreements, or standard contractual clauses.
Contact and updates
Great Big AB may update this policy when Dollflow’s features, providers, or legal obligations change. Material changes will be communicated where required, and the date at the top of this page will be updated.