Privacy Policy: BMT Customer Accounts Portal

    Effective date: 7 October 2026

    Who we are

    BlumacawTech (“we”, “us”) makes BMT Customer Accounts Portal, a Shopify app that adds content, pages, private documents and order buttons to a store’s customer accounts. You can reach us at admin@blumacawtech.com.

    If you shop at a store that uses the app, the store (the merchant) is the controller of your personal data; we process it on the merchant’s behalf and on Shopify’s instructions. For merchants’ own account data, we are the controller.

    Data we process for merchants

    • Store information from Shopify: the shop’s domain, name, time zone, currency, primary web address and whether it uses the new customer accounts, so the app can run.
    • Content merchants create: blocks, pages, segments (the rules), order action forms and settings, stored in our database.
    • Documents merchants upload (PDFs, images, office files): stored privately and given only to the customers the merchant chooses, through download links made for that customer that stop working after an hour.
    • Theme files, read only when a merchant scans a theme on the app’s Migration page. We keep the scan report (what was found, with short excerpts of theme code), not the theme.
    • Support conversations: if a merchant starts a chat or books a call with us from the app, what they send us and their contact details, to answer them.

    Data we process about a store's customers

    • For showing the right content: each customer’s tags, amount spent and number of orders, read from Shopify to work out which of the merchant’s segments they are in. We store only the result (short segment codes) on the customer’s record in the merchant’s own Shopify store. We don’t store customers’ names, email addresses, phone numbers or addresses.
    • Order requests: when a customer sends one of the merchant’s order forms (for example “Request an invoice”), we store the order and customer IDs, what they typed and the date, so the merchant can see the request in the app. If the merchant uses Shopify Flow, the same details go to their Flow workflows.
    • Usage counts: daily counts of views, clicks, downloads and requests for each block, page, document and order form. Counts only, without anything that identifies a customer.
    • Download links contain the customer’s Shopify customer ID so a link works only for them.

    We use this data only to provide the app to the merchant. We don’t sell it, use it for advertising, or combine it across stores.

    Where data is stored, and who helps us process it

    • Google Cloud (Cloud Run, Cloud Storage, Cloud Tasks, Cloud Logging), Mumbai, India (asia-south1): runs the app and stores uploaded documents.
    • MongoDB Atlas, on Google Cloud in Mumbai, India (asia-south1): the app’s database.
    • Shopify: the platform the app runs on.
    • tawk.to: the support chat available to merchants inside the app, used only when a merchant opens a chat.

    Retention and deletion

    • When a merchant uninstalls the app, Shopify asks us 48 hours later to delete the store’s data; we then delete everything we hold for that store, including uploaded documents.
    • When Shopify asks us to delete a customer’s data, we delete that customer’s order requests. Segment codes live in the merchant’s store and are removed with the customer’s record.
    • When a customer asks a store for their data, we send the merchant the order requests we hold for that customer.
    • Server logs are kept for up to 30 days.

    Security

    Data is encrypted in transit (HTTPS) and at rest by our providers. Uploaded documents are private and can only be downloaded through links made for the customer. Access to the app’s systems is limited to the people who maintain it.

    Your rights

    Depending on where you live, you may have rights to access, correct, delete or export your personal data. Customers of a store should contact that store, which can ask us through Shopify. Merchants can contact us at admin@blumacawtech.com about their own data.

    Changes to this policy

    When this policy changes, we update this page and its effective date. For significant changes, we tell merchants who use the app.