Privacy Policy
Última atualização: May 26, 2026
This Privacy Policy describes how Arthimo (operated by , registration , registered at ) collects, uses, stores and protects personal data while providing its services to Shopify merchants and end consumers.
This policy complies with the General Data Protection Regulation (GDPR) in the European Union and the LGPD (Brazilian General Data Protection Law nº 13.709/2018).
1. Data controller and processor roles
Arthimo acts in two capacities, depending on data origin:
- Data controller for merchant account data (users of the Arthimo admin panel).
- Data processor for end-consumer data flowing through the mobile app generated by Arthimo. In these cases the Shopify merchant is the controller and Arthimo processes data under their instructions.
2. Data we collect
2.1. Merchant data (direct user)
- Name, email and phone of the merchant contact
- Legal entity / registration number / billing address
- Connected Shopify store domain
- Shopify API access tokens (encrypted at rest)
- Payment data (via Shopify Billing API — we don't store card numbers)
2.2. End-consumer data (via merchant)
- Push notification token of the mobile device
- Anonymous device and session ID (does not identify a person)
- Platform (iOS/Android), app version, language
- Shopify customer ID (when logged into the store)
- Customer email (when associated with a push token, for campaign segmentation)
We don't collect:detailed order contents, consumer payment data, residential addresses. These remain stored in the merchant's Shopify, not in Arthimo.
3. How we use data
- Operate the merchant admin panel
- Generate and deliver the merchant's mobile app
- Send push notifications per merchant-configured campaigns
- Attribute app-originated sales for subscription billing
- Send operational communications (invoices, support, contract changes)
- Meet legal and regulatory obligations
4. Data sharing
Arthimo does not sell personal data. We share only with:
- Shopify Inc. — operates the platform where the merchant store runs; receives webhooks and app data.
- Infrastructure providers: Railway (hosting), Resend (transactional emails), Firebase Cloud Messaging (push delivery), Sentry (error monitoring).
- Legal authorities: when required by law or court order.
5. Storage and security
- Data stored in Postgres servers in Brazil (Railway).
- API tokens and sensitive data encrypted at rest (AES-256).
- Transmission always over HTTPS/TLS 1.2+.
- Internal access restricted to authorized personnel with MFA.
- Sensitive access audit logs retained for 12 months.
6. Your rights (GDPR / LGPD)
You have the right, at any time, to:
- Confirm whether we process your data
- Access a copy of your data
- Correct incomplete, inaccurate or outdated data
- Anonymize, block or erase unnecessary or non-compliant data
- Port your data to another provider
- Withdraw consent
To exercise any right, email [email protected]. We respond within 30 days (GDPR) or 10 business days (LGPD).
Important:if you're an end consumer who used a merchant's mobile app, first contact the merchant — they are the controller of your data. Arthimo only processes on their behalf and will fulfill the request within the deadline after receiving the merchant's request.
7. Data retention
- Active merchant data: while contract lasts + 5 years after termination (tax obligation).
- API tokens: revoked immediately upon Shopify app uninstall.
- End-consumer data: up to 48h after merchant uninstalls the app (full purge via Shopify
shop/redactwebhook). - Audit logs: 12 months.
8. Cookies and similar technologies
We use httpOnly cookies only to maintain an authenticated merchant session in the admin panel. We do not use tracking, advertising or third-party analytics cookies without consent.
9. Children
Arthimo does not direct its services to minors under 18. If we identify inadvertently collected minor data, it will be deleted.
10. Changes to this policy
We may update this policy periodically. Material changes will be communicated by email to merchants with at least 30 days advance notice.
11. Contact
Data Protection Officer (DPO): [email protected]
General support: [email protected]
Portuguese version available at /privacidade.