Data Processing Policy

This page describes everything we do with Customer Personal Data and End User data, including how we use it and for what purpose and how long we keep it.

Platform and Third Party Services

Our Service can be integrated into certain Platforms. They are:

  • Shopify
  • Wix

Here is the information about how your Personal Data is collected or used through those Platforms and Third Party Services:

Shopify.

Our Service is intended to work with the Shopify platform, which collects your information, including your Personal Data and processes it for Customers that use the Shopify platform. As a third party developer, we are bound by the Shopify Partner Program Agreement. Shopify is also a Controller in common of your Personal Data. This means that they have their own policies as to how they use your Personal Data as a customer of theirs. If you would like to know more about Shopify’s privacy and data protection practices, please refer to their privacy policy or contact their Data Protection Officer at privacy@shopify.org or at the addresses below:

Shopify Residents outside of the European Economic Area:

Shopify Inc.
Attn: Chief Privacy Officer
150 Elgin St., 8th Fl
Ottawa, ON K2P 1L4
Canada

Shopify Residents of the European Economic Area:

Shopify International Limited
Attn: Data Protection Officer
c/o Intertrust Ireland
2nd Floor 1-2 Victoria Buildings
Haddington Road
Dublin 4, D04 XN32
Ireland

Wix.

We partner with Wix to enable and support certain functions, including the collection of Personal Data and End User data, through the Wix platform. As a third party developer, we are bound by the Wix App Market Partner Agreement. If you would like to know more about Wix’s privacy and data policy practices, please refer to their privacy policy at https://www.wix.com/about/privacy or

By mail at:

  • 40 Namal Tel Aviv St., Tel Aviv, Israel; or
  • 500 Terry A. Francois Boulevard, 6th Floor, San Francisco, CA, 94158.

For the purposes of GDPR (Article 27), you may contact the Wix EU representative at Wix Online Platforms Limited, 1 Grant’s Row, Dublin 2 D02HX96, Ireland.

For the purposes of UK GDPR (Article 27), you may contact the Wix UK representative at Wix.Com (UK) Limited, Tower Bridge House, St Katharine's Way, London E1W 1DD, United Kingdom.

End Use Data Collection and Retention

Data about your customers that you collect through use of the Service (“End Users”) may be collected and stored. Below is a list of the End User data that may be collected, used and stored through our Service by us directly or through our subprocessors, in connection with use of the Service through Platforms and Third Party Services:

Source End User Data Collected
Bonify
  • End User profile (name, email, phone, address)
  • Order history
  • Order information
Shopify
  • End User profile (name, email, phone, address)
  • Order history
  • Order information
Wix
  • End User profile (name, email, phone, address)
  • Order history
  • Order information
  • Contact information
  • Booking information
  • Inbox message information

For Arigato Automation and InstaSheets, End User data is collected and stored to process the data for the Customer’s workflow. Log data is retained for 14 days and database backups are stored per our data retention policy or as otherwise required under our agreements with those Third Party Services.

For Bonify Customer Account Fields, End User data may be stored until the Customer deletes the information or discontinues use of the Service.

Third Party Sub-Processors Integrated into Services

The following third party sub-processors collect, use or store Personal Data and/or End User data as directed by you through your use of one or more of the Services:

Arigato InstaSheets Custom Fields/Bonify Custom Fields Customer Account Fields/Bonify Customer Account Fields
Google X (Gmail; Oauth) X (Google Sheets; Oauth)
IFTTT X
Twilio X
Sendgrid X X X X
Zapier X
Klaviyo X
Trello X
Slack X
MailChimp X
Zendesk X

Third-Party Provider: Google

Location of the Processing: United States

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Transmits Personal Data and End User data to Customer accounts associated with Google products and services, such as Gmail/GSuite, Google Sheets, and for authentication. In order to process and authorize workflows we use OAuth protocols and Google. Our access to your Google Sheets account is granted via OAuth protocols that connect your Google account with our Service. We store URLs to your Google Sheets in order to link and send data from your workflow automations in our App to your Google Sheet(s). The Service only collects and stores the URLs to your Sheets that you specifically provide to us in the Service. When your workflows are triggered, we transmit your specified data to your specified Google Sheet(s). We do not store the data in your Sheet(s) or use it in any other way. Your Google Sheet(s) may contain or be linked to your Personal Data. You can access and amend your Sheets in accordance with Google’s policies, terms and conditions. Google’s ability to use and share information stored in Google Sheets about your visits to this site is restricted by the Google Terms of Service, the Google Privacy Policy and Data Processing Amendment.

Third Party Provider: IFTTT

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Transmits Personal Data and End User data to automated workflows as directed by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Twilio

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects End User SMS data to provide customized communications as directed by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: SendGrid

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects End User email addresses to provide customized communications as directed by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Zapier

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Personal Data and End User data to perform tasks as directed by Customer.For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Klaviyo

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects End User data to manage multi-channel marketing automations. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Trello

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Customer Data to integrate Trello workflows and lists. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Slack

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Customer Data and End User data to provide Slack communication channels. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: MailChimp

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects End User data to update Customer mailing lists. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Zendesk

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Personal Data and End User data provide support services as directed by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third Party Provider: Airtable

Location of Processing: USA

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Personal Data and End User data provide data storage and collection as directed by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Core Third Party Sub-Processors

The following core third party sub-processors collect, use or store Personal Data and/or End User data on our behalf and transmit it to us:

Third Party Provider: Google Analytics

Location of Processing: United States

Basis for Processing: US-EU Privacy Shield and EU Standard Contractual Clauses with Data Processing Amendment.

Google Analytics collects information about the use of the Services. Google Analytics collects information such as how often users visit this site, what pages they visit when they do so, and what other sites they used prior to coming to this site. We use the information we get from Google Analytics only to improve this site, but in anonymous form. Google Analytics collects only the IP address assigned to you on the date you visit this site and assigns a user ID code, rather than your name or other identifying information. We do not combine the information collected through the use of Google Analytics with personally identifiable information. Google uses this information to analyze your use of the website, to generate reports about website activities for website operators and to provide further services related to website and internet use. Google may also share such information with third parties to the extent it is legally required to do so and/or to the extent third parties process data on behalf of Google. Although Google Analytics plants a permanent cookie on your web browser to identify you as a unique user the next time you visit this site, the cookie cannot be used by anyone but Google. Google’s ability to use and share information collected by Google Analytics about your visits to this site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy and Data Processing Amendment. You can prevent Google Analytics from recognizing you on return visits to this site by disabling cookies on your browser. You may block Google Analytics on some browsers with the help of a browser add-on if you do not want us to use this website analysis. This add-on can be downloaded at: http://tools.google.com/dlpage/gaoptout?hl=en. For more information on Google Analytics and Google’s privacy practices, please review their privacy policy at https://www.google.com/policies/privacy/

Third-Party Provider: HelpScout (HelpScout.com)

Location of the Processing: United States (US).

Basis for Processing: HelpScout is EU-US Privacy Shield Certified

Purpose and Personal Data collected: collects email address and correspondence history through service help center and support ticketing system, including, but not limited to install/uninstall and Customer upgrades/downgrades.

Privacy Policy: https://www.helpscout.com/company/legal/privacy/

Third-Party Provider: Drip (Drip.com)

Location of the Processing: United States

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects email addresses for email marketing. The service collects the merchant’s name; email address, site domain; Application status (current or past client) for Bonify campaign engagement. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third-Party Provider: Pantheon

Location of the Processing: United States

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Web hosted cloud computing for Custom Fields app only. Collects Personal Data and End User data as selected by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third-Party Provider: Mixpanel

Location of the Processing: United States

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Tracks Customer behavior and activity in the Service to provide analytics on our Services. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

Third-Party Provider: Amazon Web Services

Location of the Processing: United States

Basis for Processing: EU Standard Contractual Clauses and Data Protection Addendum

Purpose and Personal Data collected: Collects Personal Data and End User data for purposes of web storage and Service delivery. For more information on their privacy and data protection practices, please refer to their Privacy Policy.

AI Services

Bonify uses artificial intelligence (AI) sub-processors to enhance conversations and technical support through the usage of AI models. Use of an AI chatbox is an optional feature and not required for use of the Service.

Third-Party Provider: OpenAI

Location of the Processing: United States

Purpose and Personal Data collected: Artificial intelligence models. No Personal Data or End User data is required or requested by Bonify through the chatbot. OpenAI may have access to Personal Data or End User data to the extent provided by Customer. For more information on their privacy and data protection practices, please refer to their Privacy Policy.