relode
Relode legal

Privacy Policy

Last updated July 5, 2026 · Auto Shift Media LLC
← Back to relode.app

This Privacy Policy explains how Relode collects, uses, shares, protects, and retains personal information. It covers two connected things we operate: our marketing website at relode.app, including the free interactive Revenue Leak Audit estimator and the email capture form, and the Relode application, an automated win-back and lapsed-customer reactivation app that Shopify merchants install from the Shopify App Store. Please read it alongside our Terms of Service. If anything here is unclear, email us at support@relode.app and we will explain it in plain language.

1. Introduction and scope

Relode is a new, independent software product. This policy applies to personal information we handle in three settings: (a) when you visit relode.app or use the Revenue Leak Audit or submit the email capture form; (b) when you, as a Shopify merchant or a member of a merchant's staff, install and use the Relode app; and (c) when we process the personal data of your store's customers in order to run win-back email on your behalf.

Relode is an independent application and is not affiliated with, endorsed by, or sponsored by Shopify. References to Shopify describe a platform we integrate with and a service provider we rely on, not a partner that controls this policy.

This policy does not govern how a merchant runs its own store, how Shopify operates its platform, or how any third-party website you reach through a link handles your data. Those are governed by their own policies.

2. Our roles: controller and processor, explained plainly

Data-protection law distinguishes between a "controller" (the party that decides why and how personal data is used) and a "processor" (a party that handles personal data on the controller's instructions). Relode acts in both roles, depending on whose data is involved. Keeping this straight is the single most important idea in this policy, so here it is in plain terms:

Where we act as a processor, our handling of that data is also governed by a Data Processing Agreement (DPA) available to merchants (see the section on our processor role below).

3. Who we are and how to contact us

Relode is built and operated by Auto Shift Media LLC, an Ohio limited liability company in the United States. In this policy "Relode", "we", "us", and "our" refer to Auto Shift Media LLC.

Email is the fastest way to reach us with a privacy question, a data request, or a request for our current list of subprocessors or a copy of our DPA.

4. Categories of information we collect

We group the information we handle into three categories, matching the roles above.

4.1 Website visitors and Revenue Leak Audit inputs (we are controller)

4.2 Merchant account, contact, and billing information (we are controller)

4.3 The merchant's customers' personal data (we are processor)

To run win-back on the merchant's behalf, and only with the merchant's authorization through Shopify's Admin API, we process the following categories of the store's customers' personal data:

We request only the minimum Shopify access needed for this: reading orders and customers, and writing discount codes to mint single-use win-back codes. We do not request access to your products, inventory, or payment details.

5. Sources of data

6. How and why we use information (purposes)

We use each category of information only for the purposes it was collected for:

Where the GDPR (EU) or UK GDPR applies, we rely on the following legal bases for the personal data for which we are the controller:

For the merchant's customers' personal data, Relode acts as a processor and does not choose the legal basis. The merchant, as controller, is responsible for having a lawful basis (for example the customer's consent or the merchant's own legitimate interest) for the win-back processing we carry out on the merchant's instructions.

8. Shopify Protected Customer Data

Some of the data we access through Shopify's Admin API is treated by Shopify as Protected Customer Data, including customer names, email addresses, and order information. We handle it in line with Shopify's requirements and with data minimization at the center:

9. Email and marketing practices

Email is central to what Relode does, so we are specific about it. We distinguish two kinds of email:

10. Cookies and similar technologies

On relode.app we use a small number of cookies and similar technologies. Strictly necessary ones keep the site and forms working and secure. Any analytics we use is lightweight and aimed at understanding aggregate traffic, not at profiling individuals, and it is not tied to any store's customer data. Where required by law, we ask for consent before setting non-essential cookies, and you can control cookies through your browser settings. The embedded Relode app inside Shopify admin uses only the cookies and tokens needed to keep your session secure.

11. How we share data, and our subprocessors

We do not sell your data or your customers' data, and we do not share it for cross-context behavioral advertising. We share personal information only with the service providers (subprocessors) that make Relode work, each bound to handle data only on our instructions and only to the extent needed to provide their service, and we may disclose data where required by law or valid legal process, or to protect the rights, safety, and property of Relode, our merchants, or the public. A business transfer (such as a merger or acquisition) could also involve transferring data, subject to this policy.

SubprocessorPurposeWhere
ShopifyThe platform Relode runs on and reads store, order, and customer data from, and which processes subscription and one-time billing through its managed Billing APIUnited States and global (Shopify infrastructure)
ResendDelivery of transactional and win-back email, and reporting of delivery events (opens, clicks, bounces, unsubscribes, complaints)United States
VercelHosting of the relode.app marketing websiteUnited States and global (edge network)
Cloud application host and managed PostgreSQL database providerRuns the Relode application and stores its data, encrypted at rest, logically separated per storeUnited States
SentryError and performance monitoring to keep the service reliableUnited States

For our current list of subprocessors, email support@relode.app. We will make reasonable efforts to notify merchants of material changes to this list where our processor commitments require it.

12. International data transfers

Relode is operated from the United States, and the personal information we process may be stored and processed in the United States and in the locations of the subprocessors listed above. If you or your customers are located in the European Economic Area, the United Kingdom, or another region, your data may be transferred to and processed in a country whose data-protection laws differ from your own. Where such transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK Addendum, and take reasonable steps to protect the data in transit and at rest.

13. Data retention and deletion

We keep personal information only as long as needed for the purposes described here, then delete or de-identify it.

14. Security measures

We take reasonable, industry-standard measures to protect personal information and to limit what we collect in the first place. These include encryption of data in transit using TLS, storage of your Shopify access token encrypted at rest, HMAC verification of every incoming Shopify webhook, least-privilege access to production systems limited to personnel who need it, logical separation of each store's data, and a design that keeps full payment card numbers out of our systems entirely (billing stays with Shopify). Relode is a new, independent product: we describe our security honestly and we do not claim SOC 2, ISO 27001, HIPAA, or PCI certification. No method of storage or transmission is perfectly secure, but we work to protect your data and will act promptly if a problem arises.

15. Your privacy rights

Depending on where you live, you may have rights over your personal information. We honor verifiable requests as required by applicable law and do not discriminate against you for exercising them.

15.1 GDPR and UK GDPR (EEA and UK)

You may have the right to access your personal data, to correct it, to delete it, to receive it in a portable format, to restrict or object to certain processing, and to withdraw consent where we rely on it. You also have the right to lodge a complaint with a supervisory authority (see the contact section below).

15.2 CCPA and CPRA (California)

California residents may have the right to know what personal information we collect and how we use and share it, to access and delete it, to correct inaccuracies, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CPRA, and we do not use or disclose sensitive personal information for purposes that would require an opt-out. We do not discriminate against you for exercising your rights.

15.3 How to exercise your rights

16. Our role as a processor, and the DPA available to merchants

When we process the merchant's customers' personal data, we act as the merchant's processor and handle that data only to provide the win-back service on the merchant's documented instructions. We make available a Data Processing Agreement (DPA) that sets out these commitments, including confidentiality, security, use of subprocessors, assistance with data-subject requests, international-transfer safeguards, and deletion or return of data at the end of the service. Merchants can request the DPA by emailing support@relode.app.

17. Children's data

Relode is a business tool for Shopify merchants and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. The customer data we process is provided by merchants from their own store records. If you believe a child has provided us personal data directly, contact us and we will delete it.

18. Automated processing

Relode uses automated logic to learn repurchase rhythm, detect lapsing customers, and rank them by predicted reactivation value so the most valuable customers are contacted. This ranking decides the order and timing of marketing emails only. It does not produce a decision that has a legal effect or a similarly significant effect on any individual: it does not determine credit, employment, pricing to the shopper, access to essential services, or any comparable outcome. A merchant remains in control of its store and its customer relationships.

Our website and communications may link to third-party sites and services, including Shopify. We are not responsible for the privacy practices of those third parties. When you follow a link, review the privacy policy of the site you visit.

20. Changes to this policy

We may update this policy as Relode evolves or as legal requirements change. When we make a material change, we will update the "Last updated" date at the top and, where appropriate, notify merchants in the app or by email. Continued use of the website or the app after an update means you accept the revised policy.

21. How to contact us, and supervisory authorities

Relode is operated by Auto Shift Media LLC, an Ohio limited liability company in the United States. For any privacy question, data request, a copy of our DPA, or our current list of subprocessors, contact us:

If you are in the EEA or the UK and believe we have not resolved your concern, you have the right to lodge a complaint with your local data-protection supervisory authority. We ask that you contact us first so we can try to put things right. This policy is governed by the laws of the State of Ohio, USA, without prejudice to any mandatory data-protection rights you have under the laws of your own country.

22. Revenue Leak Audit data note

The Revenue Leak Audit on relode.app is a directional estimate generated from the inputs you provide plus published Shopify retention benchmarks. It is not financial advice, and it is not a report generated from a connected store: unless and until you install the app, we do not read your real Shopify data to produce it. Any email address you submit on relode.app is used to contact you about Relode. You can ask us to delete your audit inputs and contact details at any time by emailing support@relode.app.