Instant Reviews — Privacy Policy
Last updated July 29, 2026
Instant Reviews (“the app”, “we”) is a product-review app for Shopify stores, operated by FourCore. This policy explains what personal data the app processes when a merchant installs it, why, and the rights merchants and their customers have. We process personal data only to provide the app’s features to the merchant — never for advertising, profiling across stores, or sale.
Data we process, and why
- Customer name and email address — received from Shopify order events, used to send a post-purchase review request about that customer’s own order and to mark submitted reviews as “verified buyer”.
- Order context (order ID, product purchased) — used to reference the right product in the review request and link the customer to the product page.
- Review content (rating, text, optional photos or videos, reviewer name, optional email, country) — submitted voluntarily by the reviewer, displayed publicly on the merchant’s storefront at the merchant’s direction.
- Customer questions (question text, name, optional email) — submitted voluntarily, displayed publicly once the merchant publishes them.
- Imported reviews — when a merchant imports reviews from another platform, we store the fields that platform exported (which may include reviewer name, location, or IP recorded by that platform). We do not collect IP addresses from reviews submitted through our own widgets.
- Suppression list — email addresses that bounced, complained, or unsubscribed. Kept so we never email them again; this retention is required to honor the opt-out.
What we don’t do
- We do not sell or rent personal data, and we do not share it across merchants.
- We do not use customer personal data for our own marketing or advertising.
- We do not make automated decisions with legal or similarly significant effects.
- We do not request customer phone numbers or addresses from Shopify.
Service providers (sub-processors)
The app runs on a small set of infrastructure providers, each bound by their own data-processing terms:
- Vercel — application hosting (USA/EU edge).
- Neon — Postgres database, encrypted at rest, with encrypted backups.
- Amazon Web Services (SES, eu-north-1) — email delivery for review requests and notifications.
- Google Gemini API — only if the merchant enables AI review summaries: published review text (not customer emails) is processed to generate a summary.
- Shopify — the platform itself, source of order and customer data under the merchant’s agreement with Shopify.
Security
All data is encrypted in transit (TLS) and at rest, including backups. Production access is limited to authorized personnel with multi-factor authentication; the app’s internal support tooling is restricted by an explicit allowlist. Access to production systems is logged by our infrastructure providers.
Retention and deletion
Personal data is kept only while the merchant uses the app. We implement Shopify’s mandatory privacy webhooks: when a customer requests deletion (customers/redact) or a merchant uninstalls (shop/redact), the corresponding data is deleted. Suppressed email addresses are retained solely to keep honoring the opt-out. Customers can also unsubscribe from review-request emails at any time via the one-click link in every email.
Your rights
Customers can ask the merchant they bought from to access or delete their data — Shopify relays those requests to us automatically and we honor them. Merchants and customers can also contact us directly at sophia@fourcore.dev and we’ll respond promptly.
Changes
If this policy changes materially, we’ll update this page and the “last updated” date above.