When you install Flockly, it requests four read-only Shopify scopes. These provide access to products, orders, older orders and files, plus the store domain and access tokens needed to run the app. The older-order permission lets the selected Analytics period include orders beyond Shopify's standard 60-day window.
How data is used
Flockly synchronizes Shopify orders into a privacy-minimal attribution record so changing an Analytics range does not download a large order history again. It stores the Shopify order ID, timestamps, current order value and currency, normalized attribution method and platform, and safe campaign/content identifiers when available. It does not store customer names, contact details, addresses, payment information, raw referrers or raw journey payloads, and it does not create or maintain customer profiles.
Shopify's customer privacy webhooks keep this store scoped. For a customer data request, Flockly records the Shopify request ID, store domain and one-way hashes of the requested order IDs, plus a point-in-time copy of only matching normalized attribution fields. This limited request record can remain long enough to answer the request even if a later shop-redaction event erases the active store dataset. It never includes the customer object or direct customer contact details. Completing the request immediately removes the point-in-time disclosure; the completed request ID and hashes are deleted after 30 days. A customer-redaction request removes matching active attribution rows, while shop redaction removes the remaining active store data described in the Privacy Policy. Social and content data is used for the features you enable.
Your content and AI
Flockly does not sell personal information and does not use your content or metrics to train its own models. AI Assist only sends the material you submit for that request to OpenAI to generate or rewrite a caption.
Full policy and data requests
Read the Privacy Policy for the complete list of data, processors, retention and your rights. For a privacy or deletion request, use the contact details in that policy. For other account questions, use the Contact Us page.