SMS Flow · Legal
Privacy Policy
1. Who we are
SMS Flow is a Shopify app that lets merchants send SMS messages to their customers from Shopify Flow workflows. It is operated by LevLocal (“we”, “us”). This policy explains what information the app collects when a merchant installs it, how that information is used, and the choices merchants and their customers have.
Merchants are the data controllers for their customers' personal data. SMS Flow processes that data on the merchant's behalf and only to deliver the messages the merchant configures.
2. What we collect
From the merchant (on install and in Settings)
| Data | Source | Notes |
|---|---|---|
| Store domain, store name, store contact email | Shopify, at install | Identifies the installation and lets us contact you about the service. |
| Shopify access token | Shopify OAuth | Used only to call the Shopify Admin API for this store. Deleted on uninstall. |
| SMS provider credentials (Vodafone Web2SMS or SMS Misr username, password or API token, sender name) | Entered by the merchant | Stored encrypted (AES-256-GCM). Used solely to send messages through the merchant's own provider account. |
| App settings (quiet hours, rate limits, time zone, provider environment) | Entered by the merchant | Controls when and how messages are sent. |
| Plan and subscription status | Shopify Billing | Which plan is active and when the billing period ends. We never see payment card details; Shopify handles all charges. |
From Shopify Flow (each time a workflow runs the Send SMS action)
| Data | Notes |
|---|---|
| Recipient phone number | Provided by the merchant's workflow (for example the order's phone field). Stored so the message can be sent and, if delivery fails, retried. Shown only in masked form (first three and last two digits) in the app and in logs; a one-way hash is used for rate limiting and de-duplication. Deleted with the message record after 90 days. |
| Message text | Composed by the merchant in Flow; may contain the customer's first name, order number, totals or links the merchant chose to include. Stored so the merchant can review what was sent and retry failures. |
| Tag, Flow run identifier, timestamps | Used for reporting, filtering and idempotency (so one workflow run never sends twice). |
| Delivery outcome | Status (sent, failed, skipped), the provider's message identifier and any error code returned by the provider. |
Technical data
Our servers keep standard request logs (IP address, user agent, timestamps, request path) for security and troubleshooting. If error monitoring is enabled, crash reports may include a redacted request context. We do not use advertising trackers or sell any data.
3. Why we collect it
- To send the SMS messages the merchant configures in Shopify Flow, through the merchant's chosen provider.
- To enforce the merchant's own safeguards: quiet hours, per-store and per-number rate limits, monthly plan quota.
- To show the merchant delivery status, history, analytics and CSV exports inside the app.
- To retry temporarily failed messages and let the merchant retry permanently failed ones.
- To operate billing through Shopify and keep the app secure and reliable.
We do not use customer phone numbers or message contents for any purpose other than delivering and reporting the merchant's messages. We never message a merchant's customers on our own behalf.
4. Your customers' data
If you are a customer of a store that uses SMS Flow: the store decided to send you an SMS and wrote its contents. SMS Flow only carries it. We store your phone number together with the message and its delivery status for up to 90 days so the store can see what was sent and retry failures; the number is shown to the store only in masked form. To exercise any privacy right regarding these messages, contact the store first; we will assist the store with any request it forwards to us, and we honour every data request Shopify sends on your behalf (see section 8).
5. Who we share it with
| Recipient | What | Why |
|---|---|---|
| The merchant's SMS provider (Vodafone Egypt or SMS Misr) | Recipient phone number, message text, sender name | They deliver the SMS. The merchant has a direct contract with the provider; the provider's own privacy policy applies to that delivery. |
| Shopify | Install, billing and workflow data | The app runs inside the Shopify platform and uses Shopify Billing. |
| Hosting and database provider (Railway) | All application data, encrypted at rest and in transit | Infrastructure. |
| Error monitoring (Sentry), when enabled | Redacted crash reports | To detect and fix failures. |
We do not sell personal data and do not share it with advertisers. We may disclose data if required by law or to protect the rights and safety of merchants, customers or the service.
6. How long we keep it
- Message records (phone number, message text, status): 90 days, then deleted automatically by a daily job. Aggregated counts (how many messages were sent in a month) are kept for billing history.
- Provider credentials and settings: for as long as the app is installed. Deleted within 48 hours of uninstall.
- Store record and billing history: retained after uninstall so that a reinstall restores the plan and so we can meet accounting obligations; store-specific data is removed on request or when Shopify sends a
shop/redactrequest. - Server logs: 30 days.
7. How we protect it
- All traffic between Shopify, our servers and the SMS providers is encrypted with TLS.
- Provider passwords and API tokens are encrypted at rest with AES-256-GCM using a key that is stored separately from the database.
- Full phone numbers are never written to logs or shown in the app; only masked values appear.
- Access to production systems is limited to the people operating the service and is protected by authentication and audit logs.
- Each store can only ever see its own data; every request is authenticated through Shopify.
8. Your rights and Shopify requests
Depending on where you are, you may have the right to access, correct, export, restrict or delete personal data, and to object to certain processing. Merchants can exercise these rights by contacting us at support@levlocal.com. Customers should contact the store, which can forward the request to us.
SMS Flow implements Shopify's mandatory privacy webhooks:
- customers/data_request — we compile the message records associated with the customer's phone number and make them available to the merchant.
- customers/redact — we delete the message records associated with the customer's phone number.
- shop/redact — 48 hours after uninstall, we delete the store's settings, credentials and message records.
9. Billing
Plans are billed through Shopify Billing on the merchant's regular Shopify invoice. We never receive or store card numbers. The cost of each SMS is charged by the merchant's provider under the merchant's own agreement with that provider; SMS Flow adds no per-message fee.
10. Changes and contact
If we make material changes to this policy we will update the effective date above and notify merchants inside the app or by email. Questions, requests or complaints can be sent to support@levlocal.com.
LevLocal · SMS Flow for Shopify