Privacy Policy
AtAstro is a Shopify app that shows on-site popups, recognizes returning shoppers, and connects to a merchant's email and SMS platform. AtAstro is operated by Audens Media LLC ("Audens Media", "we", "us"). This policy explains what data the app processes, why, and the choices available to merchants and their shoppers.
1. Who is responsible for the data
Shopper data (data about visitors to a merchant's store) is controlled by the merchant. Audens Media processes it on the merchant's behalf, as a processor or service provider, under the Data Processing Addendum in our Terms.
Merchant account data (the store's details and how the merchant uses AtAstro) is controlled by Audens Media.
If you shopped at a store that uses AtAstro, the store's own privacy policy also applies, and the store is your first point of contact for requests about your data.
2. Data we process
From the merchant's storefront (only after cookie consent)
AtAstro reads the store's Shopify cookie-consent settings. It runs only when the shopper has allowed both analytics and marketing processing. In regions where Shopify does not require consent, the store's default settings apply. When consent is declined, AtAstro does not run and deletes any AtAstro data stored in that browser.
| Data | Purpose |
|---|---|
| A random visitor ID and session ID, stored in the browser | Recognize a returning visitor on that store |
| Pages viewed, product views, add-to-cart actions, scroll depth, time on page, exit intent, referring page | Decide whether to show, suppress, or change a popup |
| Popup interactions (shown, clicked, dismissed, submitted) | Frequency limits and performance reporting |
| Email address, and phone number only when the shopper ticks the SMS consent box, entered into an AtAstro popup | Deliver the offer, and sync the signup to the merchant's email/SMS platform |
| Discount codes issued | Deliver offers and attribute orders to popups |
| IP address | Briefly, for rate limiting and abuse prevention. It is not stored in visitor profiles. |
From Shopify
| Data | Purpose |
|---|---|
| Store domain and an encrypted access token | Operate the app for that store |
| Order ID, totals, currency, discount codes used, test flag, order date, refund status | Attribute revenue to popups. We do not read customer names, emails, phone numbers, or addresses from Shopify. |
| Discounts created by the app | Issue one-time discount codes |
From merchants
Popup designs, settings, and the credentials for any email/SMS platform the merchant chooses to connect. These credentials are encrypted.
3. How we use data
- To show the right popup, or no popup, to each visitor on that merchant's store.
- To issue discount codes and report popup performance to the merchant.
- To send signups, segments, and related events to the email/SMS platform the merchant has connected, so the merchant can message shoppers who opted in.
- To secure, maintain, and support the service, and to meet legal obligations.
We do not sell personal data. We do not share it for cross-context behavioral advertising. We do not combine data across different merchants' stores. Each store's data is kept separate. We do not use data for automated decisions with legal or similarly significant effects.
4. Who we share data with
| Recipient | Why |
|---|---|
| Cloudflare, Inc. | Hosting, compute, and data storage |
| Shopify | App platform, installation, and billing |
| The merchant's chosen email/SMS platform (for example Klaviyo or Redo) | Only when the merchant connects it, and only to carry out the merchant's instructions |
We may also disclose data if required by law, or as part of a merger or acquisition, subject to this policy.
5. How long we keep data
| Data | Retention |
|---|---|
| Raw event log | 30 days |
| Visitor profiles (activity counters, segment, email if provided) | 180 days after the visitor's last activity |
| Attributed order records | 365 days |
| Visitor ID in the shopper's browser | Until the shopper clears it, or immediately if consent is declined |
| All data for a store | Deleted when Shopify sends the store-deletion request after the app is uninstalled |
6. Security
Data is encrypted in transit (TLS) and at rest. Store access tokens and email/SMS platform credentials get an extra layer of encryption (AES-256-GCM, with keys held separately from the data). Internal tools are behind authenticated access. Each store's data is isolated from every other store's.
7. Your rights and choices
- Shoppers can decline cookies in the store's consent banner, unsubscribe using the link in any email or by replying STOP to texts, and ask the store to access or delete their data. Stores pass these requests to us through Shopify, and we act on them.
- Depending on where you live, including the EU, UK, and US states such as California, you may have rights to access, correct, delete, or port your data, and to object to or limit processing. You can also contact us at privacy@atastro.io. We will route your request to the right merchant or handle it directly.
- Merchants can uninstall the app at any time. That triggers deletion of the store's data as described above.
8. International transfers
Audens Media is based in the United States, and data may be processed wherever Cloudflare operates. Where the law requires it, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Children
AtAstro is not directed at children under 16, and we do not knowingly collect their personal data.
10. Changes
We will post any changes here and update the effective date. If a change is material, we will notify merchants through the app or by email.
11. Contact
Audens Media LLC, Ohio, United States.
privacy@atastro.io