Last updated: August 14, 2026
ScanFlow is a Shopify app that lets merchants create QR code marketing campaigns and track the sales they drive. This policy explains what information ScanFlow collects, how it's used, and how it's protected -- both for merchants who install the app and for shoppers who scan a ScanFlow QR code.
From merchants who install ScanFlow:
From shoppers who scan a ScanFlow QR code:
ScanFlow requests the minimum Shopify Admin API access it needs to work:
ScanFlow's data is stored on Google Cloud (Firebase) infrastructure in the us-central1 region, in a project used exclusively for ScanFlow. Access is restricted through Google Cloud IAM, and sensitive credentials such as your store's API secret are kept in Google Cloud Secret Manager rather than stored as plain text.
We keep your campaign and analytics data for as long as ScanFlow is installed on your store. When you uninstall ScanFlow, Shopify notifies us and we permanently delete all data associated with your store -- campaigns, QR codes, scan records, analytics, reports, and your access token -- typically within 48 hours.
Because ScanFlow never stores a shopper's name, email, phone number, or Shopify customer ID, there is no shopper-identifying data to export or erase when Shopify's data request or redaction webhooks fire for an individual shopper.
ScanFlow shares data only with Shopify (the platform it's built on) and Google Cloud / Firebase (its hosting and database provider). We do not sell data, and we do not share it with advertisers or other third parties.
Merchants can remove all of their ScanFlow data at any time by uninstalling the app. Shoppers with questions about a store's use of ScanFlow should contact that store directly -- ScanFlow has no way to identify or contact individual shoppers, since it never collects their personal information.
If this policy changes, we'll update the date at the top of this page.
Questions about this policy or ScanFlow's data practices can be sent to cygentechnologieslimited@gmail.com.