Privacy policy
Your shop's data,
and what we do with it.
Written to be read, not just filed. If anything here isn't clear, email us and we'll explain it properly.
Last updated: 13 July 2026.
The short version
- Your data stays in Australia
- Stored in Sydney. The only thing that routinely leaves is our operational alert email.
- Your own private setup
- A dedicated container and database per shop. Never mixed in with another merchant's.
- We don't want your customers' details
- We don't request or read customer personal details, and the sales we record carry no customer record.
- We never touch payment cards
- Shopify bills you. We never see or hold payment details.
- No tracking on this website
- No cookies, no analytics, no advertising trackers.
- Leave and it's deleted
- When you offboard, your instance, database, backups and encryption key are all deleted.
This summary is here to help you find your way around — the full sections below are what actually applies.
Who we are
TrolleyRelay (ABN 22 524 307 821) is an Australian business. We can be reached at support@trolleyrelay.com.
Information about you
When you request access, sign up, or contact support, we collect your contact details (name and email address), your Shopify store domain and ShopFront subdomain, and the contents of our correspondence, directly from you. We use this to onboard you, operate the service (including sending you operational alerts), and provide support. We do not send marketing communications.
What we access
Shopify
When a merchant installs the TrolleyRelay Shopify app, we request access to:
- Products, variants, and inventory: read and write, so we can mirror the ShopFront catalogue and keep stock levels in sync.
- Metafields on variants: read and write, used to store pack-pricing metadata consumed by our Shopify Function.
- Product media (images): read and write, so product photos from ShopFront flow through to the storefront.
- Discount Functions: only when pack pricing is enabled in the TrolleyRelay admin do we create a Function-backed automatic discount that applies pack pricing at checkout. Nothing is created until then, and we read/write the discount's configuration only. Disabling pack pricing deactivates the discount.
- Cart line data during function execution: read-only, inside Shopify's Function sandbox. Cart contents are not exfiltrated.
- Orders and fulfilments: read-only. When online-order routing is enabled, we read orders and their fulfilment events so a matching sale can be recorded in ShopFront. We do not request or read customer personal details, and the sale we record carries no customer record.
- Locations: read-only, to map Shopify locations to ShopFront outlets for inventory sync.
- Theme content: read-only, to detect whether our app blocks are present in the merchant's published theme so setup status can be shown accurately.
- Sales channels and publications: read and write, to publish synced products to the Online Store channel and read published product listings.
ShopFront
We access the ShopFront API on the merchant's behalf using OAuth credentials they provide:
- Product catalogue: read-only. Products, prices, case quantities, images, categories, and tags, so the catalogue can be mirrored to Shopify.
- Inventory: read-only, per outlet, to keep Shopify stock levels in sync.
- Change notifications: we register webhooks for product and stock-level changes so syncs run automatically.
- Registers, staff users, and payment methods: read-only lists shown when configuring online-order routing; we store only the merchant's chosen selections, not the lists themselves.
- Sale creation: when online-order routing is enabled, we record completed Shopify online orders as sales in ShopFront. Sales we create carry no customer record.
What we store
- A cross-reference between ShopFront products and their Shopify counterparts, to enable deterministic updates.
- Encrypted-at-rest credentials for both platforms (one set per merchant).
- Structured audit logs of every sync action, kept on a 90-day rolling window for operational debugging.
- A billing record for each online order we successfully record into ShopFront (order identifier, timestamps, and billing state; no customer details), kept for the life of the service.
- The merchant's current subscription status and billing-cycle window, as provided by Shopify.
Each merchant's data lives in a dedicated container with an isolated database. Data is never co-mingled with other merchants.
We use aggregated, de-identified operational data (sync volumes, error rates, performance timings) to operate, secure, and improve the service. It cannot identify a merchant, their staff, or their customers.
Billing
Charges are billed by Shopify and appear on the merchant's Shopify invoice; we never see or hold payment details. To operate billing, we store the merchant's subscription status and billing-cycle window as provided by Shopify, and each billable order sync is reported to Shopify as a usage event carrying a count and a reference identifier only, never order contents or customer information. Rates are published on our pricing page.
Backups and retention
Each merchant database is continuously replicated to encrypted storage (AWS, Sydney region)
using a per-merchant encryption key. Backup history is kept on a 30-day rolling window. When
a merchant offboards, or a shop/redact webhook is received, the dedicated
instance, its database, its backups, and its encryption key are all deleted. Billing and
financial records (order identifiers and billed amounts, never customer personal information)
may be retained after the service ends, as required for financial record-keeping.
What we do not store
- Customer personal information beyond what is already inside Shopify or ShopFront.
- Payment details. TrolleyRelay never touches payment card data.
- Cart contents or session state outside a Function execution window.
Shopify mandatory data-subject webhooks
We implement the Shopify customers/data_request,
customers/redact, and shop/redact webhooks. A
shop/redact triggers deletion of the merchant's entire dedicated instance
(container, database, and backups) within the Shopify-mandated window.
Sub-processors
- Fly.io: tenant container hosting (Sydney, Australia, for AU data residency).
- Amazon Web Services: encrypted database backups (Sydney, Australia).
- Cloudflare: DNS, CDN, and hosting for this website.
- Resend: transactional email for operational alerts (US-based). Alert emails carry operator contact details and alert text only, never merchant customer data.
- Shopify: Shopify-managed platform data.
- ShopFront: ShopFront-managed POS platform data.
Overseas disclosure
Merchant data we hold is stored in Australia (Sydney). The only routine overseas transfer is operational alert email via our US-based email provider. Shopify and ShopFront hold their own platform data under their own privacy policies; Shopify hosts data globally.
Data breaches
If a data breach affects a merchant's data, we will notify the affected merchant promptly, and the Office of the Australian Information Commissioner where required by law.
This website
This website sets no cookies and runs no third-party analytics or advertising trackers. Our hosting provider, Cloudflare, processes standard request data (such as IP address and browser type) to serve and secure the site, and provides us aggregated, anonymised traffic statistics. We do not use this data to identify visitors.
Contact
Privacy requests: support@trolleyrelay.com. We reply within 5 business days.
You can request access to, or correction of, the personal information we hold about you by emailing the address above.
Complaints: if you believe we have mishandled personal information, contact us at the address above and we will respond within 5 business days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).