ValidRev

Legal

ValidRev - Privacy Policy

Last updated: September 2, 2026

1. Scope and Roles

This Privacy Policy explains how Zain Qazi LLC, the owner and operator of ValidRev ("we", "us", or "our"), collects, uses, discloses, retains, and protects information when you use validrev.com, connect a Shopify store, or contact us.

For account administration, service security, and our own business operations, Zain Qazi LLC acts as the party responsible for that processing. When we process Shopify order data solely to provide services to a merchant, the merchant determines the purpose of that processing and Zain Qazi LLC acts as its service provider or processor where applicable.

2. Information We Process

Account and Authentication Data

We process your email address, account identifier, session information, and any profile information you choose to provide. If you use Google sign-in, Google provides the basic profile information needed to authenticate you. If a password credential is created, only its secure hash is stored.

Shopify Store and Connection Data

After a merchant authorizes ValidRev, we process the store identifier and domain, store name, description, logo, country, currency, reporting timezone, Shopify plan, granted scopes, installation status, synchronization status, and encrypted access and refresh tokens.

The Storefront access used for a store logo is read-only. Shopify credentials are server-only and are never included in public pages or browser JavaScript.

Orders and Protected Customer Data

ValidRev reads the minimum order fields needed to calculate store-level analytics: order identifiers and dates, test status, sales and return amounts, discounts, shipping, taxes, duties, fees, quantities, currency, and customer identifiers used to count distinct customers.

We do not request or use customer names, email addresses, phone numbers, or postal addresses for analytics. Individual order records and customer identifiers are processed transiently while a Shopify result is aggregated and are discarded after that operation. We persist monthly aggregate values, not customer identifiers or individual orders.

Service and Technical Data

Our hosting, authentication, and security systems may process IP address, browser and device information, request metadata, authentication events, error information, and essential cookie data. Shopify webhook-delivery metadata is stored without raw order payloads so deliveries can be verified, deduplicated, retried, and audited.

Communications

We process the contents of messages you send to us and delivery information for transactional emails such as one-time login codes and service notices.

3. Why We Process Information

We process information only for the following purposes:

  • Authenticate users and protect accounts
  • Connect and maintain merchant-authorized Shopify integrations
  • Import, reconcile, and display accurate store-level aggregate analytics
  • Create the automatic public aggregate profile described below
  • Provide synchronization, reconnect, privacy, and disconnect controls
  • Diagnose errors, prevent abuse, and maintain service reliability
  • Respond to support, privacy, and legal requests
  • Comply with Shopify requirements and applicable law

No Advertising or Sale of Personal Data

We do not sell personal data, use Shopify customer data for advertising, or share it for cross-context behavioral advertising. We do not use protected customer data to make decisions that produce legal or similarly significant effects about an individual.

4. Public Store Profiles

Connecting an eligible Shopify store automatically creates a public profile and directory entry. The profile can display Shopify-owned store identity and store-level aggregate analytics, including monthly sales, order count, average order value, growth, reversal or refund rate, currency, and verification freshness.

A merchant can enable anonymous mode to hide the store name, logo, description, and identifying URL. Aggregate analytics remain public while the store is connected because public verification is a core ValidRev service. Disconnecting or uninstalling removes the store from public queries.

ValidRev never publishes Shopify access credentials, customer identifiers, customer contact information, or individual order records.

5. Service Providers and Disclosures

We disclose information only as needed to operate the service, follow merchant instructions, protect rights and security, complete a business reorganization subject to appropriate safeguards, or comply with law. Our current core providers include:

  • Shopify, for merchant authorization, APIs, and webhook delivery
  • Vercel, for application hosting and request processing
  • Supabase, for managed PostgreSQL database infrastructure
  • Resend, for transactional email delivery
  • Google, only when a user chooses Google authentication

International Processing

These providers may process information in countries other than your own. Where required, we and our providers rely on appropriate contractual or legal safeguards for international transfers.

6. Retention and Deletion

We retain information only for as long as needed for the purposes described in this policy, to follow merchant instructions, or to meet security and legal obligations.

  • Individual Shopify order fields and customer identifiers are discarded after transient aggregation and are not stored as customer-level records
  • Monthly aggregate metrics and store identity are retained while needed to provide the connected service
  • Disconnecting or uninstalling immediately disables public display and destroys stored Shopify access and refresh credentials
  • A valid Shopify shop-redaction request removes the remaining Shopify-derived store identity, import state, and aggregate analytics covered by the request
  • Completed webhook-delivery receipts and security records are retained only as reasonably necessary for reliability, abuse prevention, and legal compliance
  • Account-deletion requests are completed within 30 days unless a limited record must be retained by law, to resolve disputes, or to prevent fraud

Shopify Privacy Requests

ValidRev verifies and honors Shopify's mandatory customer data-request, customer-redaction, and shop-redaction webhooks. Because ValidRev does not persist customer identifiers or individual order records, it ordinarily has no customer-level record to return or erase. Store-level redaction is applied to Shopify-derived store data.

7. Security

We use administrative, technical, and organizational safeguards appropriate to the information we process. These include HTTPS in transit, application-layer authenticated encryption for stored Shopify credentials, server-only credential access, authorization checks, limited data collection, and webhook signature verification.

No method of storage or transmission is completely secure. If a security incident affects personal data, we will investigate and provide notifications when required by applicable law.

8. Cookies and Authentication

ValidRev uses essential cookies for authentication, session continuity, OAuth state validation, fraud prevention, and request security. Optional third-party authentication may use provider cookies when you choose that sign-in method. ValidRev does not use third-party advertising cookies.

Blocking essential cookies can prevent login, Shopify connection, and other authenticated features from working.

9. Privacy Rights

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal data, and to appeal or complain to a privacy regulator. We apply Shopify's standardized privacy-request process regardless of where a Shopify customer is located.

Merchants should submit Shopify customer requests through Shopify so the mandatory compliance webhook reaches installed apps. ValidRev account holders can contact us directly. We may need to verify your identity and authority before completing a request.

10. Children's Privacy

ValidRev is intended for merchants and adults who are authorized to manage stores. It is not directed to children under 18, and we do not knowingly collect personal data directly from children through ValidRev accounts.

11. Changes to This Policy

We may update this policy to reflect changes to the service, providers, or legal requirements. We will update the date on this page and provide additional notice when a material change requires it.

12. Contact

The business responsible for this policy is Zain Qazi LLC. For privacy questions, data requests, or complaints, email hello@validrev.com or write to Zain Qazi LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. Do not send passwords, Shopify access tokens, API keys, or one-time login codes.