Forwarding Address
Privacy Policy
Last updated: July 28, 2026
Who we are
Forwarding Address (forwardingaddress.app) is a Shopify app that helps merchants win back lapsed customers by sending win-back emails and printed mail pieces on the merchant’s behalf. For the customer data described below, the merchant is the data controller and Forwarding Address acts as a processor on their instructions.
Data we process
When a merchant installs the app, we receive data from Shopify strictly to provide the service:
- Customer data — customer name, email address, default mailing address, order count, lifetime spend, the date and items of their most recent order, and their email marketing consent state. Win-back email is only ever sent to customers whose consent state is subscribed.
- Store data — store name, domain, contact email, currency, and the settings the merchant configures in the app (including the postcard return address).
- Send activity — the content of win-back messages we generate, delivery identifiers from our providers, and whether a link or QR code was used, so returned customers can be attributed and usage billed accurately.
We do not collect payment card details, and customers check out only through Shopify — never through us.
How we use it
Only to operate the service for the merchant: deciding which customers count as lapsed under the merchant’s rules, writing and sending win-back emails and mail pieces, attributing returned customers, and billing usage through Shopify. We do not sell personal data, use it for advertising, or use one merchant’s data for another merchant’s benefit.
Service providers
We use a small set of subprocessors, each receiving only what its role requires:
- Vercel — application hosting.
- Supabase — database hosting.
- Resend — win-back email delivery.
- Lob — printing and mailing physical win-back pieces (receives recipient name and mailing address).
- OpenAI — on plans with personalized copy, receives the customer’s first name, the product titles from their last order, how long they’ve been away, and the store name to write the message. It never receives email addresses or mailing addresses.
Retention and deletion
- When a merchant uninstalls the app, our access credentials are revoked immediately and the store’s data is deleted when Shopify issues its uninstall redaction request.
- When a customer asks their merchant for erasure, Shopify’s
customers/redactrequest causes us to erase that customer’s personal data (name, email, addresses, purchase details, message content), cancel any queued sends to them, and exclude them from all future campaigns — while preserving the merchant’s anonymous revenue records. - When a customer asks their merchant for their data, we deliver what we hold to the merchant, who responds to their customer.
Security
All traffic is encrypted in transit. Data is stored in an access-controlled database reachable only by the application backend, and Shopify access tokens are short-lived and rotated automatically. Merchant dashboards are authenticated with Shopify-signed session tokens, so only a store’s own staff can see its data.
Contact
Questions or requests about this policy: benjaminfingram@gmail.com. If you are a customer of a store using this app, contact the store you purchased from first — under data-protection law they are the controller of your data, and we act on their instructions.