ElemenifyElemenify by Tiwaa

Data Processing

Last updated: May 18, 2026

This page describes how Tiwaa processes data on behalf of merchants who use Elemenify, a visual page builder, in accordance with the GDPR and CCPA. It supplements our Privacy Policy.

1. Roles

2. Data We Process

The table below lists every category of data we hold or process:

CategoryDataPurposeRetention
Shop identityShop domain (e.g. mystore.myshopify.com)Identify and namespace per-merchant dataUntil uninstall + 30 days
AuthenticationShopify offline access token (encrypted at rest); short-lived session tokensWebhooks, publishing, Admin API calls, App Proxy deliveryUntil uninstall + 48 hours
Your designsPages, headers, footers and sections you build (layout, content, settings)Store, edit, preview and publish your pagesUntil deleted; Trash purged after 30 days; all on uninstall + 30 days
Catalog data (transient)Products, collections, navigation menus, blog articles read via Admin APIRender dynamic widgets; only what a page needs is baked into its published outputRead at publish/preview; not stored as a separate copy
Form submissionsFields your visitors submit via Form widgets — may include name, email, phone, message, uploaded filesShow submissions to you; optional Shopify-customer creation / integrations you enableUntil deleted by you; Trash purged after 30 days; all on uninstall + 30 days
App settings & billingEditor/form preferences, active plan, installation timestampApp configuration, trial tracking and plan gatingUntil uninstall + 30 days

Personal data from your store's visitors is processed only where you add a Form widget and a visitor submits it, or where a dynamic widget renders content you chose to publish. We never use this data for our own purposes and never sell it.

3. Sub-processors

We engage the following sub-processors, each bound by data-processing terms consistent with GDPR:

Sub-processorPurposeLocationPrivacy policy
Shopify Inc.Merchant authentication, billing, webhooks, Pages API & App Proxy deliveryCanada / USAView policy
Cloudflare, Inc.App hosting (Workers, Pages), database (D1) & object/file storageUSA (global edge)View policy

Merchant-directed transfers: if you enable an integration (Mailchimp, Klaviyo, a webhook URL, or Shopify customer creation), form submissions are additionally sent to that destination at your instruction. Those recipients are not our sub-processors — they act under your own agreements with them.

We will notify you of any new Tiwaa sub-processor by updating this page and revising the "Last updated" date at least 10 days before it begins processing.

4. International Transfers

Data may be processed in the United States (Cloudflare, Shopify) and Canada (Shopify). Cloudflare participates in the EU–US Data Privacy Framework; Shopify's international transfers are covered by Standard Contractual Clauses.

5. GDPR / Shopify Compliance Webhooks

6. Security Measures

7. Your Responsibilities

As the controller for visitor data, you must display an appropriate privacy notice, obtain any required consent, and have a lawful basis before collecting personal data through forms you build. We provide tooling (honeypot, optional GDPR consent field, deletion controls) to help you comply.

8. Contact

Data-processing enquiries: tiwaaofficial@gmail.com

DocumentationPrivacy PolicyTerms of ServiceBack to App