Appearance
Privacy Policy
Effective date: August 11, 2026
Fisoma ("Fisoma", "we", "us", or "our") provides applications and related services for Shopify merchants. This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit our website or documentation, contact us, or install and use our Shopify applications, including UpForm and SEOEngine (collectively, the "Services").
1. Who We Are and Our Role
Fisoma is responsible for the personal data that we collect and use for our own purposes, including data relating to our website, documentation, merchant relationships, application administration, and customer support. For these activities, Fisoma acts as a data controller.
When a Shopify merchant uses our applications to process personal data on behalf of that merchant, the merchant generally acts as the data controller and Fisoma acts as a data processor. In that context, we process personal data according to the merchant's instructions, our agreement with the merchant, and applicable law.
If you are a customer or visitor of a Shopify store that uses a Fisoma application, the merchant is normally your primary contact for questions or requests concerning your personal data.
2. Personal Data We Collect
The personal data we collect depends on how you interact with the Services and which application features a merchant enables.
Website and documentation data
When you visit our website or documentation, we may process:
- IP address and approximate location derived from the IP address
- Browser type, device type, operating system, and language
- Pages visited, referring page, access time, and request information
- Security, diagnostic, and error logs
- Cookie and similar technology data, where applicable
Contact and support data
When you contact us through a form, email, or another support channel, we may process:
- Name and email address
- Shopify store domain or URL
- Application name and account information
- Support request content and correspondence
- Files, screenshots, or other information that you choose to provide
Merchant and Shopify store data
When a merchant installs or uses a Fisoma application, we may process information necessary to authenticate the store, provide the application, manage the merchant relationship, and support enabled features. This may include:
- Store identifier, store domain, and basic store information
- Store owner or merchant contact information
- Application installation, upgrade, and uninstall status
- Subscription or plan information made available through Shopify
- Application settings, preferences, and configuration
- Usage, security, audit, and diagnostic information
- Shopify resources required by the features the merchant chooses to use
We request and use Shopify permissions according to the functions provided by each application. A permission may technically cover more information than a particular feature needs. We do not intentionally access or retain personal data merely because it falls within a granted permission.
UpForm data
UpForm may process information required to create, publish, operate, and manage forms. Depending on how the merchant configures a form, this may include:
- Form structure, fields, design, settings, and publication configuration
- Form submissions and submission metadata
- Names, email addresses, phone numbers, messages, store information, or other details entered by form submitters
- Files or attachments submitted through a form when that feature is enabled
- Email, workflow, automation, CAPTCHA, and third-party integration settings
UpForm may use AI to translate forms and to generate forms, form structure, questions, labels, descriptions, or related content. When a merchant invokes those AI features, Fisoma may process prompts or instructions, source form content, language preferences, and generated or translated output. Fisoma may send only the data necessary to an AI provider to fulfill the selected feature.
The merchant determines which fields to include in a form, why the information is collected, and how the merchant uses submitted information.
SEOEngine data
SEOEngine may process store content and configuration required to analyze, manage, or improve search engine optimization. Depending on the features used, this may include:
- Store domain and SEO configuration
- Product, collection, page, blog, and related storefront content
- Titles, descriptions, URLs, structured data, redirects, sitemap, robots, and other SEO-related information
- Audit results, optimization settings, reports, and application activity
SEOEngine processes this information to provide the SEO functions selected by the merchant.
When a merchant invokes SEOEngine AI features, Fisoma may process selected storefront content, prompts/instructions or feature settings, and generated output. Fisoma may send only the data necessary to an AI provider for the selected feature.
Data from other sources
We may receive personal data:
- Directly from you
- From the Shopify merchant that uses our Services
- From Shopify through application interfaces, permissions, and privacy requests
- From service providers and integrations selected by us or the merchant
- Automatically through devices, logs, cookies, and similar technologies
We do not sell personal data.
3. How and Why We Use Personal Data
We process personal data only when we have an appropriate purpose and legal basis. Depending on the circumstances, we use personal data to:
- Provide, operate, maintain, and support the Services
- Authenticate stores and make enabled application features work
- Perform our agreements with merchants
- Respond to questions, support requests, and service communications
- Process application subscriptions and related records through Shopify
- Protect the Services, prevent fraud or abuse, and investigate security incidents
- Diagnose errors, monitor reliability, and improve performance
- Understand how the Services are used and improve existing or future features
- Comply with legal obligations and enforce our agreements
- Send product or marketing communications where permitted by law
Under the General Data Protection Regulation ("GDPR"), our legal bases may include:
- Performance of a contract: when processing is necessary to provide the Services requested by a merchant
- Legitimate interests: when necessary to operate, secure, support, and improve the Services, provided those interests are not overridden by individual rights
- Consent: when we ask for consent, including for certain non-essential cookies or communications
- Legal obligation: when processing is necessary to comply with applicable law
When Fisoma processes personal data as a processor for a merchant, the merchant is responsible for determining the legal basis for collecting and using that data and for providing required notices to affected individuals.
We may create aggregated or de-identified information that does not reasonably identify an individual. We may use that information for analytics, security, research, and service improvement.
4. Cookies and Similar Technologies
Our website, documentation, and applications may use cookies, local storage, pixels, and similar technologies.
These technologies may be used for:
- Strictly necessary operation and security
- Remembering settings and preferences
- Support and application functionality
- Performance measurement and analytics
Where required by applicable law, we obtain consent before using non-essential cookies or similar technologies. You may be able to manage cookies through the consent controls made available on the relevant Service or through your browser settings. Blocking some technologies may affect Service functionality.
Third-party services used by a merchant, including integrations embedded or configured by that merchant, may use their own technologies under their respective privacy policies.
5. How We Share Personal Data
We may disclose personal data only as necessary for the purposes described in this Privacy Policy, including to:
- Shopify, for application installation, authentication, billing, privacy requests, and platform functionality
- Cloud infrastructure, database, storage, and content delivery providers
- Customer support, email, and communication providers
- Security, monitoring, diagnostics, and CAPTCHA providers
- Analytics providers where enabled and legally permitted
- Integration providers selected or enabled by a merchant
- AI providers, when a merchant uses AI-assisted features and only to the extent necessary to fulfill the selected feature
- Professional advisers, auditors, insurers, and legal authorities where necessary
Service providers that process personal data for us are authorized to use it only as needed to provide their services or comply with law and are expected to apply appropriate safeguards.
We may disclose personal data when required by law, legal process, or a valid government request, or when reasonably necessary to protect the rights, safety, security, and integrity of Fisoma, our users, or others.
If Fisoma is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its business, relevant information may be transferred subject to appropriate confidentiality and legal requirements.
We do not sell personal data or share it for cross-context behavioral advertising.
6. International Data Transfers
Our Services currently store and process data in the United States. As a result, personal data from the European Economic Area ("EEA"), the United Kingdom, Switzerland, or other jurisdictions may be transferred to and processed in the United States.
Where applicable law requires a transfer mechanism, we use an available lawful mechanism and appropriate safeguards. Depending on the provider and transfer, these may include an adequacy decision, the European Commission's Standard Contractual Clauses, the United Kingdom's applicable transfer terms, or another mechanism recognized by applicable law.
You may contact us to request more information about safeguards applicable to your personal data.
7. Data Retention and Deletion
We retain personal data only for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, protect the Services, resolve disputes, and enforce agreements.
Application data is generally retained while the relevant merchant has the application installed and uses the applicable features. Fisoma automatically deletes data associated with an application when the merchant uninstalls it or when we receive and process a valid redaction request from Shopify, subject to limited exceptions required by law or necessary for security, fraud prevention, dispute resolution, or legal claims.
Residual copies may remain temporarily in backups until those backups are deleted or overwritten through the normal backup lifecycle. During that period, backup data is protected and is not used for ordinary business purposes.
Support correspondence, security records, billing records, and legal records may be retained for different periods based on their purpose and applicable requirements. When personal data is no longer required, we delete, de-identify, or securely dispose of it.
Aggregated or de-identified information may be retained where it no longer identifies an individual.
8. Shopify Privacy Requests
Shopify provides mechanisms through which merchants and their customers can request access to or deletion of personal data. Fisoma processes valid privacy requests received through the Shopify platform, including:
- Customer data access requests
- Customer data redaction requests
- Shop data redaction requests
If you are a customer of a Shopify merchant, submit your request to the merchant first. The merchant can coordinate the request through Shopify, and we will provide reasonable assistance as required for data that we process on the merchant's behalf.
9. Your Data Protection Rights
Depending on your location and applicable law, you may have the right to:
- Request access to personal data about you
- Request correction of inaccurate or incomplete data
- Request deletion of personal data
- Request restriction of processing
- Receive certain personal data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
- Object to direct marketing
- Lodge a complaint with a competent data protection authority, particularly in the country where you live, work, or believe a data protection violation occurred
Withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
If Fisoma controls the relevant personal data, you may exercise your rights by contacting us. If the data is controlled by a Shopify merchant, please contact that merchant first. We may request information necessary to verify your identity and protect personal data from unauthorized disclosure.
Where the GDPR applies, we normally respond to a valid request within one month. We may extend that period where permitted by law due to the complexity or number of requests and will inform you if an extension is necessary.
These rights may be limited where an exemption under applicable law applies.
10. Automated Decision-Making
Fisoma does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Some application features may use automated analysis or artificial intelligence to translate content, generate forms or related form content, or provide suggestions, generated content, reports, or optimization assistance. These features support the merchant's decisions and do not independently make legally significant decisions about individuals.
11. Data Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, use, alteration, disclosure, or destruction. These measures are selected based on the nature of the data, the processing involved, and the risks presented.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to maintain and improve safeguards appropriate to the Services.
Merchants are responsible for protecting their Shopify accounts, managing authorized users, configuring application access appropriately, and using personal data collected through the Services in accordance with applicable law.
12. Children's Privacy
The Services are intended for Shopify merchants and business users and are not directed to children. We do not knowingly collect personal data directly from children through our website or documentation.
A merchant may configure an application in a way that collects information from store visitors. The merchant is responsible for determining whether its use of the Services is appropriate for its audience and for obtaining any consent required by law.
13. Third-Party Services and Merchant Integrations
The Services may link to or integrate with Shopify and other third-party services. A merchant may also choose to connect providers for email, automation, analytics, artificial intelligence, security, or other functions.
Third parties operate under their own terms and privacy policies. Merchants should review those policies before enabling an integration. Fisoma is not responsible for a third party's independent processing activities.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, our processing practices, or applicable requirements. We will publish the revised version with a new effective date.
Where appropriate, we will provide additional notice of material changes through the Services or available contact channels. If a change requires consent under applicable law, we will request consent separately.
15. Contact Us
For questions about this Privacy Policy, our data practices, or a request concerning personal data, contact Fisoma at [email protected] or use our contact form.

