Skip to content
Privacy

How Flockly handles your data

Last updated 26 July 2026 · Covers the Flockly Shopify app and getflockly.com.

Flockly is a social media planning app for Shopify stores. This policy explains what the app collects, why, who else sees it, and how to get it deleted. It covers the Flockly app installed on a Shopify store and this website.

Flockly is operated by [[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]] (“Flockly”, “we”). For anything in this policy, write to privacy@getflockly.com.

The short version

  • We store your store domain, your Shopify access tokens, and the posts you create.
  • We read your products, orders and files to build posts and attribute revenue.
  • We do not store your customers’ personal data. Order data is queried live and used only in aggregate.
  • We never sell data, and we do not use it to train machine-learning models.
  • Uninstall the app and your data is deleted — see Deletion.

What Flockly collects

From your Shopify store

When you install Flockly you grant three read-only scopes. We request nothing beyond them:

  • read_products — product titles, descriptions, images, prices, inventory status and URLs, so a post can be built from a product and linked back to it.
  • read_orders — order totals and the referring source or UTM parameters attached to an order, so revenue can be attributed to the post or Shop Grid tile that earned it.
  • read_files — images and video already in your Shopify media library, so you can post them without re-uploading.

We also store your store’s myshopify.com domain, store name, and the Shopify access tokens that let the app act on your behalf. Tokens are stored encrypted at rest and are never exposed to the browser.

Your customers’ data

Flockly does not create, store or maintain records about your customers. Order information is read at the moment a report is generated and used only to produce aggregate totals — revenue attributed to a channel, a post, or a grid tile. No customer name, email address, shipping address or payment detail is written to our database at any point.

This is why Shopify’s customers/data_request and customers/redact compliance webhooks are acknowledged but perform no deletion: there is nothing held about an individual customer to return or erase.

From your social accounts

When you connect Instagram, TikTok, Facebook, LinkedIn, Pinterest or X, we store the access tokens that authorise posting, along with the account handle, profile picture and the metrics each network reports back — reach, engagement, follower counts, and the comments or direct messages on your own posts. We never access a connected account beyond what you authorise, and disconnecting a channel deletes its tokens immediately.

From this website

If you join the waiting list we store the email address you submit, and use it once, to tell you the app is live. There is no advertising or analytics tracking on this site, and no cookies are set for marketing purposes.

Why we process it

  • To provide the app — scheduling, publishing, the Shop Grid page, analytics and the comment and DM inbox. Legal basis: performance of a contract.
  • To keep the service working and secure — error diagnosis, abuse prevention, and rate-limit compliance with each network. Legal basis: legitimate interests.
  • To bill you — handled by Shopify, see below. Legal basis: performance of a contract.

We do not profile you, and we do not use your content or metrics to train machine learning models — ours or anyone else’s.

Who else sees it

Flockly relies on a small number of processors, each bound by contract:

  • Cloudflare — hosting, and media storage (R2). Your uploaded media and the app itself are served from Cloudflare’s network.
  • Neon — the managed PostgreSQL database holding your store record, posts and tokens.
  • Upload‑Post — the publishing service that delivers your posts to the social networks and returns their metrics.
  • The social networks themselves — Meta (Instagram, Facebook), TikTok, LinkedIn, Pinterest and X receive the content you choose to publish, under their own terms and privacy policies.
  • Shopify — your store data originates with Shopify, and billing runs through Shopify App Pricing.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the CCPA/CPRA.

Payments

Subscriptions are billed by Shopify on your regular Shopify invoice. Flockly never receives, processes or stores your card details.

Where data is held, and for how long

Data is processed in [[ PRIMARY DATA REGION ]]. Where personal data is transferred out of the UK or EEA, our processors rely on Standard Contractual Clauses or an adequacy decision.

  • Shopify access tokens — kept while the app is installed; deleted on uninstall.
  • Social access tokens — kept until you disconnect the channel or uninstall.
  • Posts, drafts and Shop Grid content — kept while the app is installed, then deleted 30 days after uninstall unless you ask us to delete them sooner.
  • Analytics snapshots — retained for the history window your plan includes (30 days, 6 months or 12 months), then deleted.
  • Waiting-list emails — deleted once the launch email is sent, or on request.

Deleting your data

Uninstalling Flockly from your Shopify admin triggers Shopify’s app/uninstalled webhook. We mark the store uninstalled, revoke and delete its access tokens immediately, and purge the remaining store data within 30 days. Shopify’s shop/redact webhook, which arrives 48 hours after uninstall, erases the store record outright.

You can also ask us to delete everything at any time, installed or not, by writing to privacy@getflockly.com. We will confirm within 30 days.

Your rights

Depending on where you live you may have the right to access, correct, export, restrict or delete the personal data we hold about you, to object to processing, and to withdraw consent. Exercise any of them at privacy@getflockly.com — we do not charge for this and we do not require an account to make a request.

If you are in the UK or EEA and you think we have handled your data badly, you may complain to your supervisory authority. In the UK that is the Information Commissioner’s Office.

Security

Data is encrypted in transit (TLS) and at rest. Access tokens are stored server-side and never sent to the browser. Access to production systems is limited to the people who need it. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.

Children

Flockly is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children.

Changes

If we change this policy we will update the date above, and for material changes we will tell you in the app or by email before the change takes effect.

Contact

privacy@getflockly.com
[[ LEGAL ENTITY NAME ]], [[ REGISTERED ADDRESS ]]