FlowMailer Privacy Policy

Effective Date: 10th August 2026

Welcome to FlowMailer-Workflow Email ("FlowMailer", "we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you install, access, or use the FlowMailer Shopify application (the "App") and any related services (collectively, the "Services").

FlowMailer enables Shopify merchants to send transactional and workflow emails from Shopify Flow using their own email providers (for example SMTP, SendGrid, Postmark, Brevo, Mailgun, Microsoft 365, or similar). Depending on how you interact with the Services, you may be a Merchant (store owner or staff using the embedded admin app) or an End User / Recipient (a customer or other person who receives an email sent through a Merchant's Flow workflow).

We are committed to complying with global data‑protection and privacy laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), the Singapore Personal Data Protection Act (PDPA), the India Digital Personal Data Protection Act 2023 (DPDP Act), the Australian Privacy Act 1988, and other applicable regional legislation across the United States (US), Europe (EU & UK), and Asia‑Pacific (APAC).

If you have any questions or concerns, please contact us at apps@seventhtriangle.com.


1. Who We Are

FlowMailer is a Shopify application developed and maintained by Seventh Triangle Consulting. We act as a data processor when processing information on behalf of Shopify merchants ("Merchants") including recipient email addresses, message content, and related Flow/send metadata and as a data controller for information we collect about visitors to our marketing materials, prospective merchants, or our own operational and security logs.

Merchants remain responsible for their own privacy notices to End Users and for ensuring that emails sent through FlowMailer comply with applicable law. FlowMailer is designed primarily for transactional and workflow emails configured by the Merchant in Shopify Flow.


2. Information We Collect

Category

Examples

Source

Purpose

Merchant Account Data

Store name, store URL (myshopify.com domain), contact email, Shopify plan, Shopify Admin API access tokens, locale & currency, subscription/plan status

Directly from Merchant via Shopify OAuth

• Provide, maintain & improve the App

• Authenticate admin sessions

• Billing (via Shopify where applicable)

Merchant Configuration & Usage Data

Email templates and design settings (layout, colors, fonts, header/footer, custom HTML), Flow step configuration, app settings (enable/disable, default CC/BCC, failure-alert preferences), onboarding status, in‑App feature interactions, support communications

Merchant input in the admin dashboard; automatic in‑App events

• Operate email sending from Shopify Flow

• Render templates and apply Merchant branding

• Product analytics & roadmap planning

• Fraud & abuse detection

Sender Identity & Credential Data

From name/email, reply-to, provider type, SMTP host/port/username/password, API keys or tokens for connected providers (e.g. SendGrid, Postmark, Brevo, Mailgun, Resend), Microsoft 365 / Azure app credentials where configured

Merchant input in the App (Sender identities)

• Authenticate to the Merchant's chosen email provider

• Send email on the Merchant's behalf

• Verify sender configuration

Recipient & Message Data

Recipient email address; optional CC/BCC; subject, heading, body text, CTA label/URL, reply-to; Shopify customer identifiers and related customer/order fields used for personalization when provided by Flow or fetched via Shopify Admin API; send status and error messages; workflow / Flow action identifiers

Shopify Flow action inputs; Shopify Admin API on behalf of the Merchant; Merchant-configured templates and settings

• Deliver the Merchant's workflow emails

• Personalize content with customer/order variables

• Provide sent history, reports, and delivery stats to the Merchant

Shopify Customer & Order Data (as needed for sending)

Customer id, email, first/last name; order id, order name/number, order email, and limited order totals when referenced by a Flow action

Shopify Admin API on behalf of the Merchant

• Resolve the correct recipient email

• Substitute template variables in outbound messages

Sent Email Logs & Analytics

Per-send records (recipient, subject, heading, body text snapshot, template/sender metadata, status, timestamps, workflow labels); aggregated counts for reports and usage limits

Automatically via Flow send processing

• Merchant reporting and troubleshooting

• Service improvement and plan/usage enforcement

We do not sell personal data. Recipients do not need a FlowMailer account. Email content and recipients are determined by the Merchant's Shopify Flow configuration and template design.

Payment / cardholder data: Any Shopify billing or checkout is handled by Shopify's PCI‑DSS‑compliant infrastructure. We do not process payment card data.


3. Cookies & Similar Technologies

We use necessary Shopify session mechanisms and local browser storage to:

  • Authenticate Merchants into the embedded App dashboard.
  • Remember Merchant preferences and temporary editor state within the admin app (for example, unsaved template/HTML editor drafts in browser sessionStorage).

We do not use third‑party advertising cookies in the App. Where consent is required for non‑essential cookies on Merchant storefronts, Merchants remain responsible for their own storefront cookie notices; FlowMailer itself operates primarily inside Shopify Admin and Shopify Flow rather than as a storefront tracking pixel.


4. Legal Bases for Processing (GDPR/UK GDPR)

We rely on the following legal grounds:

  1. Contractual Necessity – to provide the Services the Merchant requests by installing the App, including connecting senders, storing templates, and sending emails from Shopify Flow.
  2. Legitimate Interests – to improve and secure our Services, provide sent logs and analytics to Merchants, communicate with Merchants about the App, and prevent fraud or abuse.
  3. Consent – where the Merchant or applicable law requires consent for certain communications (the Merchant, as the sender and store operator, is typically responsible for obtaining and documenting any required consent for emails to End Users/Recipients).
  4. Legal Obligation – to comply with applicable law, tax, accounting, and regulatory requirements, including Shopify mandatory privacy webhooks.

5. How We Use Your Information

  • To deliver, operate, maintain, and update the App.
  • To authenticate Merchant access and secure admin sessions.
  • To store and use Merchant-provided sender credentials to transmit email through the Merchant's chosen provider.
  • To render email templates (including custom HTML) and substitute Flow / Shopify variables.
  • To send transactional/workflow emails initiated by Shopify Flow actions.
  • To maintain sent history, reports, and delivery statistics for the Merchant.
  • To answer support requests and resolve delivery or configuration issues.
  • To comply with legal obligations, respond to data subject requests, and enforce our Terms of Service.

6. How We Share Information

We do not sell personal data. We only share information:

  • Within Seventh Triangle Consulting and its subsidiaries on a need‑to‑know basis;
  • With Service Providers acting on our behalf under appropriate safeguards, including:
    • Shopify – hosting of the embedded app experience, OAuth, Admin API, Flow runtime, webhooks, and related infrastructure;
    • MongoDB – secure database hosting for merchant configuration, sender credentials, templates, settings, and send logs;
    • Application hosting providers used to run the FlowMailer backend (for example our production host at flowmail.stc-apps.com);
    • Merchant-chosen email providers (such as SMTP servers, SendGrid, Postmark, Brevo, Mailgun, Resend, Microsoft Graph / Microsoft 365, or Gmail/Google Workspace via SMTP) message content and recipient details are transmitted to the provider selected and configured by the Merchant in order to deliver email;
  • With the Merchant whose store generated the data Merchants can view templates, settings, sent logs, and reports in the admin dashboard;
  • For Legal Reasons such as responding to lawful requests from regulators or to protect our rights, property, or users.

Where data is transferred outside the EEA/UK, we rely on approved transfer mechanisms such as Standard Contractual Clauses (SCCs) or an adequacy decision, and we require subprocessors (and expect Merchants' chosen email providers) to maintain appropriate safeguards.


7. International Data Transfers

FlowMailer is operated by Seventh Triangle Consulting. Application data is stored in MongoDB and processed on our application servers. Merchant-selected email providers may process message data in the regions those providers operate (for example, Mailgun US or EU endpoints when chosen by the Merchant). Depending on your location, personal data may be transferred to and processed in countries other than your own. We implement safeguards including:

  • Encryption in transit (TLS 1.2+) between clients, Shopify, and our Services.
  • Encryption at rest using industry-standard mechanisms on our database and cloud infrastructure where available.
  • Access controls limiting internal access to production systems.

8. Data Subject & Consumer Rights

Depending on where you reside, you may have rights to:

  • Access, correct, or delete personal data;
  • Object to or restrict processing;
  • Data portability;
  • Opt‑out of marketing communications;
  • Withdraw consent at any time without affecting the lawfulness of prior processing;
  • Lodge a complaint with a supervisory authority (e.g., ICO in the UK, DPA in your EU member state, or local privacy regulator).

Recipients who received an email from a Merchant's store should contact that Merchant first. Merchants may forward requests to us at apps@seventhtriangle.com. We will respond within the deadlines mandated by applicable law (e.g., 30 days under GDPR).

FlowMailer supports Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, and shop/redact). Merchants may also request deletion of stored configuration or send-log data by contacting us directly.


9. Security Measures

  • TLS encryption (HTTPS) for App traffic and API communications.
  • Shopify OAuth for Merchant authentication; Admin sessions managed via Shopify's embedded app model.
  • Credentials for Merchant email providers are stored in our database solely to send on the Merchant's behalf and are deleted when the App is uninstalled or shop data is redacted.
  • Principle of least privilege & role‑based access controls for internal systems.
  • Monitoring, logging, and anomaly detection for operational security.

Although we implement industry‑standard safeguards, no system is 100% secure. Merchants should keep Shopify credentials and email-provider API keys/passwords confidential, rotate secrets if compromised, and immediately notify us of any security incidents at apps@seventhtriangle.com.


10. Data Retention

We retain Merchant account, sender, template, settings, and Flow configuration data for as long as the App is installed on the store.

Active sent-email logs used for the Sent page, reports, and usage statistics are retained for approximately 30 days, after which they may be archived. Archived send records may be retained until uninstall, a deletion request, or completion of Shopify shop-redact processing.

Upon uninstall, we delete Merchant records, sender credentials, templates, settings, Flow configuration, sessions, and related send logs/archives as part of shop cleanup. Shopify's shop/redact webhook triggers a further wipe to ensure residual shop data is removed.

Test emails sent from the App are used to verify configuration and are not treated as ordinary Flow send history; related onboarding timestamps may be stored in settings.


11. Children's Privacy

Our Services are not directed to children under 16. We do not knowingly collect personal data from minors through the App. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such data.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated "Effective Date" and, where required, provide notice (e.g., via the App dashboard or email). Continued use of the Services after such changes constitutes acceptance.


13. Contact Us

If you have any questions, requests, or complaints regarding this Privacy Policy or our privacy practices, please contact:

Privacy Team
FlowMailer / Seventh Triangle Consulting
Second Floor, The Berry Coworks, Plot No 15, Sector-142, Noida, Uttar Pradesh - 201304
Email: apps@seventhtriangle.com
Data Protection Officer (EU/UK): Sushant Gupta, sushant@seventhtriangle.com


© 2026 Seventh Triangle Consulting. All rights reserved.