OfferMe

Privacy Policy

Last updated October 8, 2026

OfferMe is a Shopify app that lets shoppers make a price offer on a product, and lets merchants review, accept, decline, or counter that offer. This policy explains what APPLR (“we”, “us”), the operator of OfferMe, collects, why we collect it, and how you can ask us about it. This page is public and does not require a Shopify login.

If you are a shopper, the merchant whose store you used is the controller of your customer data. OfferMe processes that data on the merchant’s behalf, on Shopify’s platform.

Information we collect

Merchants

When you install OfferMe we receive, from Shopify:

  • Your shop domain and shop name
  • An offline OAuth access token (and refresh token) so the app can run in your admin
  • Granted API scopes and your current OfferMe plan
  • Contact email, when Shopify provides one, used to seed merchant notifications and optional support chat

You may also store shop settings with us (notification email, offer email copy, a logo, whether login is required to submit an offer). Rules and most settings live as Shopify metafields on your shop; the logo file, if you upload one, is stored in OfferMe’s own object storage.

Shoppers

When a shopper submits an offer on a merchant’s storefront, we store that offer so the merchant can act on it:

  • Email address (entered as a guest, or resolved from the logged-in Shopify customer)
  • Shopify customer ID, when the shopper is logged in
  • Offered price, currency, and an optional comment
  • Product and variant identifiers, plus a snapshot of the product title and image at submit time
  • Merchant decisions (accept, decline, counter), including any counter price, swapped product, free-shipping flag, and checkout link for a Shopify draft order

We do not collect payment card numbers. Checkout happens on Shopify.

Support

If a merchant opens live chat from the OfferMe dashboard, Crisp (branded APPLR) receives the shop name, shop domain, plan, and merchant email when Shopify has one. Chat is not loaded on this privacy page, or for shoppers.

How we use information

  • To run OfferMe: offers inbox, rules, draft-order checkout, and email
  • To authenticate the embedded admin via Shopify session tokens
  • To send transactional email about new and decided offers
  • To enforce plan limits and keep billing state in sync with Shopify
  • To provide merchant support
  • To keep the app reliable (operational logs, webhook deduplication)
  • To honour Shopify’s mandatory GDPR webhooks

We do not sell personal information, and we do not use it for advertising.

Legal bases (EEA / UK)

Where GDPR or UK GDPR applies, we process personal data:

  • To perform our contract with the merchant who installed OfferMe
  • As a processor, on the merchant’s instructions, for shopper offer data
  • For legitimate interests in securing, operating, and supporting the app — balanced against your rights
  • To meet legal obligations, including Shopify’s privacy webhooks

Who we share information with

We share data with service providers who help us operate OfferMe, only as needed for that job:

  • Shopify. The platform the app runs on. OAuth, Admin API, metafields, draft orders, billing, and webhooks all go through Shopify.
  • Cloudflare. Hosting (Workers), database (D1), session cache (KV), logo storage (R2), and operational logs.
  • Resend. Transactional email to merchants and shoppers about offers.
  • Crisp. Merchant live chat on the OfferMe dashboard only.
  • HubSpot. APPLR's CRM. On install and uninstall we record the shop domain and merchant email so we know which shops use OfferMe.
  • Slack. An internal ping to APPLR's #offer-me-ops channel on install, uninstall, and when a shop sends a customer data-request webhook. Install/uninstall may include the shop domain and merchant email. A data-request ping includes only the shop domain. It is not a customer-facing notification.

We may also disclose information if required by law, or to protect OfferMe, our users, or the public.

Cookies

This privacy page does not set cookies. The embedded Shopify admin uses Shopify’s session-token authentication rather than a cookie we issue. Cloudflare may set strictly operational cookies on its network. We do not use advertising or cross-site tracking cookies. Crisp may set its own cookies if a merchant opens dashboard chat.

Retention

We keep a shop’s OfferMe data for as long as the app is installed. When the app is uninstalled we delete that shop’s Cloudflare records (session, offers, usage, webhook log, cached token, logo). Shopify also sends a shop-redact webhook about 48 hours after uninstall (or if the shop is closed); we run the same deletion unless the shop has already reinstalled.

When Shopify sends a customer-redact webhook, we delete that customer’s offers (and related usage rows) for that shop. Operational logs follow Cloudflare Workers Logs retention. We do not log access tokens, request bodies, cookies, or shopper emails.

Security

OfferMe runs on Cloudflare’s network. Access tokens are stored in the shop’s session record and a short-lived cache; they are never written to logs. Shopper logos are stored under an HMAC object name, not the raw shop domain. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

International transfers

We and our processors operate in more than one region, including Asia-Pacific (Resend email). Cloudflare serves the app from its global network. If you install OfferMe, your information may be processed outside your country.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export personal data, or to object to or restrict certain processing. Shoppers should start with the merchant whose store they used. Shopify then sends us a data-request or redact webhook. For a data request we ping APPLR's #offer-me-ops Slack channel with the shop domain so we can respond; we do not email an export. For a redact we delete that customer's offers. Customer identifiers and offer contents are not written to operational logs or Slack. Shoppers and merchants who want a copy of the offers we hold can email hello@applr.dev. Uninstalling OfferMe deletes the shop's data we store, as described above.

Children

OfferMe is a business app for Shopify merchants. It is not directed at children under 16, and we do not knowingly collect personal information from children.

Changes

We may update this policy as OfferMe changes. The “Last updated” date at the top will change when we do. Continued use of OfferMe after an update means you accept the revised policy.

Contact

Questions about this policy, or a request to access or delete data we hold, can be sent to hello@applr.dev. OfferMe is operated by APPLR.