How We Handle Your Customer Data on the Essential Loyalty Program & Rewards
How We Handle Your Customer Data on the Essential Loyalty Program & Rewards
A loyalty program has to store customer information — a points balance has to belong to someone, and rewards have to still be there when a customer comes back three months later. This article explains what we store, who else is involved, how long we keep it, and what happens when a customer asks to be deleted.
🔒 What we store and why
Customer data we store:
- ✅ Email address, first and last name, phone number — to identify the customer and attach their points
- ✅ Order totals, dates, and status — to work out how many points to award
- ✅ Points balances, activity history, tiers, referrals, and reward redemptions
- ✅ Birthday, language, and marketing-consent status — for birthday rewards, emails in the right language, and consent checks
- ✅ Program totals (members, points issued, rewards redeemed)
What we never store:
- ❌ Card, bank, or any payment details — payments are handled entirely by Shopify
- ❌ Customer addresses — we don't ask for or keep street addresses, cities, or postal codes
- ❌ Browsing activity on your storefront, and no tracking cookies
Why we need these fields: a points balance has to belong to a person, so we need something to identify them by. Email and phone are also how we match customers when you upload a CSV of balances from another loyalty app. Name is used in the widget greeting and in loyalty emails. If a field isn't used by a feature, we don't ask for it.
Watch out — email tracking. Loyalty emails we send for you (reward redeemed, points expiring, birthday) count opens and clicks, so you can see how they performed. That's tracking on our own emails only — not on your storefront.
🤝 Who else is involved
Running the app means using a few established service providers. Under GDPR these are our sub-processors, and this is the full list:
- Shopify — your store, and where all customer and order data comes from
- UpCloud — hosting and the database where your program data is stored
- Google Cloud — passes store events (like a new order) from Shopify to the app
- Cloudflare — security and performance layer in front of the app
- Postmark — sends the loyalty emails to your customers
- Sentry — alerts us to technical errors so we can fix them; customer personal data is removed before anything is sent
- Help Scout — this help centre and our support inbox
Your loyalty program data is stored in the United States. Store events travelling from Shopify to the app pass through Google Cloud data centres in the United States and Europe.
Integrations you switch on yourself
These stay off unless you connect them in Settings → Integrations, and they run under your own account with that provider:
- Klaviyo — receives the customer's email plus their loyalty details (points, tier, referral code, birthday) and loyalty events, so you can build automations
- Omnisend — receives the customer's email and the same loyalty details
- Postscript — no customer data is sent at present
- Judge.me — sends review information to us so we can award review points; we don't send it customer data
When a customer is deleted, we clean up your integrations too. We remove them from our database and delete their profile from Klaviyo and Omnisend automatically. You don't have to do it by hand.
We also add your store's contact email to our own mailing list so we can send product updates. That's your address as a merchant — never your customers'.
🗄️ Security
- Data is encrypted both in transit and at rest
- Access to customer data is limited to named staff accounts, on a need-to-know basis, protected by multi-factor authentication
- Test and live systems are kept separate
- Systems are monitored continuously and kept up to date
We maintain a written Information Security Policy covering access control, device security, incident response, and vendor management. It's available to merchants and partners on request — email support@essential-apps.com.
⚖️ Your compliance position
We act as a data processor on your behalf. You're the controller: it's your store, your customers, and your privacy policy that applies to them. Our processing is governed by the Shopify Partner Program Agreement and API Terms together with our privacy policy.
- GDPR (EU/UK). We store only what a loyalty feature actually uses, use it only to run your loyalty program, and never sell customer data or use it for our own marketing. Access, correction, deletion, and export requests are supported.
- CCPA/CPRA and other regions. We never sell customer personal information, and we support your responses to know, delete, and opt-out requests. The same protections apply everywhere.
🙋 Customer data requests
When a customer exercises their rights, Shopify passes the request to us automatically and we act on it. Nothing is needed from you.
| Request | What we do |
|---|---|
| Customer asks for their data | We put together everything we hold on them — profile details, points, activity, rewards, orders — as a file and email it to your store's contact address, so you can pass it on |
| Customer asks to be deleted | We erase their email, phone, name, language, birthday, and consent records, remove their email from other customers' referral history, and delete their profile from Klaviyo and Omnisend if connected. The points record stays but is no longer linked to a person, so your program totals don't change |
| You uninstall the app | See the timeline below |
These run even if your store is paused or already uninstalled.
🗑️ How long we keep data after you uninstall
We hold on to data briefly so that reinstalling brings your program back with points, tiers, and history intact instead of empty. After that it's deleted — records are removed, along with any images you uploaded. Nothing is kept in an archive.
| When | What happens |
|---|---|
| About 48 hours after uninstall | Shopify asks us to delete your store's data, and we do |
| From 48 hours, checked daily | Our own daily clean-up deletes any store confirmed as uninstalled, in case Shopify's request doesn't reach us |
| Day 30 | If the uninstall was never confirmed, transactional data is removed |
| Day 60 | Anything remaining is deleted |
In practice a normal uninstall is fully deleted within about two to three days.
Why not straight away? Merchants often reinstall within the same week, and a short window means the program comes back intact. Before deleting anything we also re-check with Shopify that the store really is uninstalled and that no new orders or points have arrived — and stop rather than delete if we can't confirm it. A working store is never deleted by mistake.
📌 In short
- We store the minimum a loyalty program needs — no payment details, no addresses
- Seven service providers, listed above, plus Klaviyo or Omnisend if you connect them
- Program data stored in the United States, encrypted in transit and at rest
- Data requests and deletions are handled automatically through Shopify, including cleaning up your connected integrations
- A normal uninstall is fully deleted in about two to three days, and by day 60 in every case
Last updated August 2026