Privacy Policy
Upsway · Last updated June 26, 2026
Upsway is a Shopify app that adds in-cart, thank-you, and post-purchase upsells to a merchant's store and bills the merchant only for the revenue it generates. This policy explains what data Upsway accesses and stores, and how it is used. Upsway uses no customer personal data.
Data we access and store
When a merchant installs Upsway, we access their products, orders, and theme information through Shopify's APIs. We store only what is needed to recommend, attribute, measure, and bill upsells:
- Shop domain and app installation details.
- Order identifiers, line items (product and variant ids and titles), order totals, and currency.
- The A/B test “bucket” assigned to an order (treated or control) used to measure incremental lift.
- A co-purchase graph (which products are bought together) and the merchant's curation rules, used to choose recommendations.
- Billing state and a cache of generated upsell copy.
We do not collect or store customer personal information: no names, email addresses, shipping addresses, or payment details.
How we use it
- Choose and display relevant upsell offers.
- Attribute accepted upsells to bill the merchant under True-Attribution pricing (a percentage of attributed revenue, or a flat plan).
- Measure A/B incrementality (treated vs. control).
- Generate short AI-written upsell copy. Product titles are sent server-side to our AI provider for this purpose; no customer data is sent, and your data is never used to train models.
Service providers (subprocessors)
- Shopify: the platform Upsway runs on and reads store data from.
- Railway: application hosting and our PostgreSQL database.
- Anthropic: generation of AI upsell copy from product titles only.
We never sell data, and we do not share it beyond the providers above.
Data retention and deletion
We retain store data only while the app is installed. When a merchant uninstalls Upsway, or when Shopify sends a shop-redaction request, we delete that shop's data. Because Upsway stores no customer personal data, customer data-request and customer-redaction requests have no personal data to return or erase; we honor Shopify's mandatory privacy webhooks regardless.
Security
All data is transmitted over TLS and stored in an access-controlled database. Credentials and API keys are kept server-side and are never exposed to the storefront or to shoppers.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new “last updated” date.
Contact
Questions about this policy or your data? Email [email protected].