1. Who we are
Croly is operated by maxcroly. Our website is www.maxcroly.com and the app is hosted at app.maxcroly.com. For privacy enquiries, email privacy@maxcroly.com.
For website, account administration and support information, maxcroly is responsible for determining how that information is used. For analytics collected from a merchant’s Shopify store, the merchant determines the purposes of that collection and Croly processes the data to provide the service on the merchant’s instructions. The merchant’s own privacy policy also applies to shopping on their store.
2. Information we handle
Website visits
Our marketing website does not use analytics or advertising trackers, contact forms, or website-managed cookies or browser storage. Our hosting infrastructure may process ordinary request information, such as IP address, browser information, requested URL and time of access, to deliver and secure the website.
Merchant accounts and store connection
Shopify provides store information such as the store domain, name and currency, and authentication information needed to connect the app. App sessions may include the Shopify administrator’s user ID, name, email, locale and account-role information, as well as access credentials, granted permissions and session expiry. Credentials are used to authenticate authorized requests, not for advertising.
Store funnel analytics
Croly’s web pixel subscribes to five event types: page viewed, product viewed, product added to cart, checkout started and checkout completed. Analytics include event IDs and timestamps, campaign UTM parameters, sanitized page paths and referring hostnames, pseudonymous session and conversion identifiers, and relevant purchase amounts and currency.
The pixel does not send customer names, email addresses, postal addresses or phone numbers. Linkable session, checkout and order identifiers are hashed before persistence; raw checkout and order identifiers are not stored as funnel identifiers. Hashing makes data pseudonymous, not necessarily anonymous. Merchants should not put personal information into campaign parameters or page paths.
Order reconciliation
When an authorized merchant reconciles purchases, Croly retrieves Shopify order identifiers, creation and update times, test-order and financial status, and totals and currency. Order identifiers are hashed for matching. This reconciliation does not request customer contact details.
Support and privacy correspondence
If you email us, we handle your email address, message, email metadata and any attachments you choose to send. Do not send passwords, API keys, payment-card details or unnecessary customer information.
3. How we use information
We use information to connect and administer the app, attribute UTM campaign traffic, display conversion funnels, diagnose potential conversion or tracking gaps, reconcile purchases with Shopify orders, respond to support and privacy requests, and protect and maintain the service. Croly does not automatically alter a store’s theme, checkout or advertising campaigns.
Where data-protection law requires a legal basis, account and support processing may be necessary to provide the requested service; service security and maintenance may rely on legitimate interests; and applicable legal obligations may require particular records. Store analytics are processed under the merchant’s instructions and the visitor privacy permissions supplied by Shopify. The merchant is responsible for the lawful basis and notices for their store’s analytics.
We do not sell personal information or use the pixel data for targeted advertising. The pixel is configured for analytics, not marketing or preference purposes, with sale-of-data processing disabled.
4. Visitor consent and browser storage
The pixel sends analytics only when Shopify indicates that analytics processing is allowed. It listens for Shopify privacy-permission updates and stops sending when that permission is withdrawn. It uses Shopify’s browser session-storage interface for a pseudonymous session, campaign attribution and a retry queue. A new analytics session begins after 30 minutes of inactivity; this session rule is not a database-deletion deadline.
Shoppers can use the store’s privacy controls to change their permissions. Browser restrictions, consent choices and interrupted connections can result in incomplete analytics. Withdrawing permission does not by itself delete previously stored data; contact the merchant or use the request process below for deletion.
The authenticated app also uses session and authentication mechanisms needed to sign you in. Shopify and other websites linked from our service have their own privacy and storage practices.
6. International processing
Our providers and support operations may process information outside your country, including in the United States. Data-protection rules may differ between locations. Where applicable law requires safeguards for an international transfer, those requirements apply to that processing. Contact privacy@maxcroly.com for information about current processing locations and applicable transfer arrangements.
7. Retention and uninstalling
We retain app information for as long as needed to provide the connected store’s service, handle requests, maintain security and meet applicable legal obligations. Retention depends on the type of record, whether the store remains connected, outstanding support matters and legal requirements. We retain support correspondence as needed to resolve and document the enquiry.
The plan’s reporting-history window limits which records are shown in reports; it is not a promise that older database records are automatically erased. Uninstalling Croly marks the store disconnected and removes the relevant app sessions; it does not immediately erase all historical analytics. To request deletion, email privacy@maxcroly.com from an authorized store contact and identify the store domain.
We review deletion requests, verify authority and remove applicable records subject to legal requirements. Where provider logs or backups exist, copies may remain subject to the provider’s retention and rotation processes and are not necessarily erased immediately with live records.
8. Security
We use HTTPS, authenticated app routes, permission-scoped Shopify access and hashed funnel identifiers to reduce unnecessary exposure. These safeguards do not guarantee that any system is completely secure. Keep store access credentials private and report suspected unauthorized access to support@maxcroly.com.
9. Your privacy rights
Depending on your location and applicable law, you may have rights to request access to, correction or deletion of personal information, restrict or object to processing, obtain a portable copy, or withdraw consent. You may also complain to your local data-protection authority. Available rights and lawful exceptions vary.
Merchants and app users: send your request to privacy@maxcroly.com, stating the store domain, your relationship to it and the request. We may need to verify your authority before disclosing or deleting information and will respond as required by applicable law.
Shoppers: contact the merchant whose store you visited first. Croly does not receive your name or email through the pixel, so an email address alone may not locate a pseudonymous analytics record. We can work with an authorized merchant to identify relevant records where possible. Do not send raw order details to us unless requested through a verified, appropriate channel.
Contacting us about a privacy right does not require buying a subscription. A legally required portable copy is separate from the app’s currently unavailable product export feature.
10. Children
Croly is a business app for Shopify merchants and is not directed at children. We do not knowingly request children’s personal information through the website or support process. Store operators are responsible for appropriate visitor notices and controls. If you believe a child’s information has been provided to us, contact us so we can review it.
11. Changes and contact
We may update this policy when our practices or requirements change. The updated version and effective date will be posted on this page; where applicable law requires additional notice, we will provide it.
Operator: maxcroly
Privacy: privacy@maxcroly.com
Support: support@maxcroly.com