Revoco - Privacy Policy

Last updated: 31 August 2026

Who we are

Revoco ("the app", "we", "us") is a Shopify app operated by OkayScale ApS. Revoco helps merchants offer and manage an online right-of-withdrawal flow, records submitted requests and their processing history, and sends acknowledgements and merchant notifications. This policy explains what data the app processes and why.

Data we process

When a shopper submits a withdrawal request on a merchant's storefront, Revoco stores the information the shopper enters (name, order or contract number, email address, selected items and quantities, eligibility answers, and optional reason or note), the server timestamp of receipt, and the declaration and messages shown at submission. To verify and process a matched request, Revoco reads the Shopify order's identifier, name, email, line-item details, fulfilment status and available delivery timestamps through the Shopify Admin API. Revoco also stores processing outcomes and errors, the merchant's app settings, an activity history, and the Shopify session needed to call the Admin API on the merchant's behalf.

How we use it

Shopper data is used to provide the withdrawal service: to record and acknowledge the declaration, verify it against a real order where possible, present it to the merchant for review, and—only for a verified matched order and where the merchant has enabled the relevant function—to cancel the order, issue a refund, create a Shopify return, or generate an evidence pack. Merchant and technical data is also used to operate, secure, support and administer Revoco, including billing and the limited affiliate attribution described below. We do not sell personal data, and we do not use shopper, order or declaration data for advertising, profiling or affiliate attribution.

Legal basis

Shopper-data processing is undertaken on the merchant's instructions to support the merchant's legal obligations under applicable right-of-withdrawal law and performance of the contract between the shopper and the merchant. The merchant is the data controller for shopper data; Revoco acts as a data processor on the merchant's instructions. We process limited merchant and technical data where necessary to provide the service and for legitimate interests such as security, support, billing and administration of our affiliate programme, subject to applicable law.

Sub-processors and service providers

We use a small number of providers to run the service: Shopify (the platform and Admin API), Railway (application hosting and the PostgreSQL database, hosted in the EU), and Amazon Web Services (Amazon SES in eu-north-1/Stockholm) for transactional email delivery. Each provider processes data only for the service it supplies. Appal Chat is our shared in-house support system served from the Loyalino-hosted service at app.loyalino.io; it is not an independent advertising or analytics provider. Its merchant-identity data flow is described below.

In-app support (Appal Chat / Loyalino)

When Appal Chat is enabled for an authenticated merchant, Revoco creates a signed identity token so the shared support service can associate a conversation with the correct app and store. Depending on what the merchant has configured, that token contains the app identifier (revoco), the shop's *.myshopify.com domain and store handle, contact name and email, plan, default locale, and a link back to Revoco in Shopify admin. Revoco may also send the shop domain and install or subscription status to keep the support context current. Messages submitted in the widget, and replies routed to the Revoco support inbox, are processed by Appal Chat and made available to authorised support staff. This support data is not shopper order or withdrawal-request data unless the merchant chooses to include such information in a support message.

Affiliate attribution (Shoffi)

Revoco participates in an app-referral programme administered by Shoffi, an independent service operated by Avit Tech, LLC. On the first eligible authenticated merchant visit, Revoco may send Shoffi the merchant store's *.myshopify.com domain and the originating IP / X-Forwarded-For value supplied with that merchant request, together with Revoco's app identifier. This is used only to match and administer a programme referral. Revoco marks the event as sent only after Shoffi accepts it and then does not send it again for that shop; a failed delivery may be retried. No shopper identity, shopper email, order data, withdrawal declaration or selected-item data is sent to Shoffi. Shoffi's processing is described in the Shoffi privacy policy.

Retention

While the app remains installed, request records remain available unless the merchant configures a retention period in Settings → Compliance. When that period expires, Revoco replaces the shopper's name and email, removes the reason, internal note and selected-item JSON, and scrubs occurrences of the name, email and reason from the stored declaration; a reduced timestamped request record and order reference remain. A verified Shopify customer-deletion request triggers the same type of anonymisation for matching records. When Shopify sends the shop-redaction webhook after uninstall (normally about 48 hours later), Revoco deletes that shop's request records, settings, activity entries and sessions. Revoco implements Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) to support data-subject and shop deletion requests.

Your rights

Shoppers have the right to access, correct, or delete their personal data and to restrict or object to its processing. Because the merchant is the controller, please direct such requests to the merchant whose store you used; the merchant can action them through Revoco, and we will assist the merchant as their processor.

Security

Data is transmitted over TLS and stored in a managed PostgreSQL database. App-proxy requests are verified with an HMAC signature, and admin actions are authenticated with Shopify session tokens. Access to production systems is limited to authorised personnel.

Support access

To provide support, authorised Revoco staff may view and adjust a shop's Revoco app settings (such as appearance, email and compliance options) on the merchant's behalf — for example to apply a change a merchant has asked us to make. This access is limited to the app's own configuration, is protected by separate authenticated, time-limited access, and never includes signing in to the merchant's Shopify admin. Every change made this way is recorded in the shop's audit log.

Contact

For any privacy question or request, contact us at support@appal.io. We will respond within a reasonable time and, where applicable, coordinate with the merchant acting as data controller.