Legal
Privacy policy
What we collect, why we collect it, who else touches it, and how to get it back or have it deleted. Written to be read, not to be skipped.
Last updated
01Who we are
ezomfy is a Shopify development studio and Shopify Select Partner. This policy covers ezomfy.com and our customer portal at pay.ezomfy.com.
Registered address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, USA. For anything in this policy, write to info@ezomfy.com.
02What we collect
We only collect what a page actually needs. Nothing here is bought from third parties or scraped.
- Quote and contact requests: name, email, company, phone, budget range, timeline, and your message.
- Free store audits: your store URL and email, plus the technical results we generate about that store.
- Support tickets: first and last name, email, store URL, product and version, your message, and any screenshots you attach. Screenshots are forwarded to us by email and are not stored in our database.
- Consultation bookings: name, email, and the slot you pick. A Google Calendar event and Meet link are created for the call.
- Accounts: email, display name, and optionally phone and company. There is no password: we email you a one-time sign-in link.
- Purchases: name and email, plus the identifiers Stripe returns. We never see or store your card details.
- Newsletter and launch lists: email, and which page you signed up from.
- Public Q&A: the display name and question or answer you post. Your email is not shown publicly.
- Technical data: IP address on form submissions and sign-in sessions, used for rate limiting and abuse prevention.
03Why we use it
- To answer your enquiry and deliver work you have asked for. This is the performance of a contract, or steps taken before entering one.
- To take payment and issue receipts, which is a legal and contractual obligation.
- To send the transactional email a request implies: a magic sign-in link, a booking confirmation, a support acknowledgement.
- To send marketing email only where you asked for it. Every one carries an unsubscribe link.
- To keep the site working and defend it from abuse, which is our legitimate interest.
04Who else processes it
We keep the list short and use each one for a single job. Every processor below receives only the data that job needs.
- Stripe: payments, subscriptions and invoices. Card details go straight to Stripe and never touch our servers.
- Resend: transactional and newsletter email delivery.
- Google Calendar and Meet: creating consultation events and video links.
- Google Gemini: powers the site chat assistant. Messages you type into the chat are sent to Google to generate a reply.
- Google Analytics 4 and Google Tag Manager: aggregate traffic measurement.
- Microsoft Clarity: heatmaps and session recordings of how pages are used. Clarity masks text input by default, so what you type into a form is not captured.
- Cloudflare: serves and protects this website.
- Railway: hosts our application and database.
We do not sell your personal data, and we do not share it for advertising.
06How long we keep it
- Enquiries, audits and support tickets: while we are working with you, and afterwards as a record of the work.
- Purchase and invoice records: kept as long as tax and accounting law requires.
- Newsletter subscriptions: until you unsubscribe.
- Sign-in sessions: expire on their own and are cleared automatically.
- Rate-limit records: a short rolling window, then deleted.
Ask us to delete something earlier and we will, unless we are legally required to keep it.
07Your rights
Wherever you live, we will honour these. If you are in the UK, EU, or a US state with a privacy law, they are also your statutory rights.
- Get a copy of the data we hold about you.
- Have anything inaccurate corrected.
- Have your data deleted.
- Object to, or ask us to restrict, how we use it.
- Receive it in a portable, machine-readable format.
- Withdraw consent to marketing at any time, using the unsubscribe link in any email or by asking us.
Email info@ezomfy.com and we will reply within 30 days. We will not charge you or make the site worse for asking.
08International transfers
We operate from the United States and Bangladesh, and the processors above operate globally. Your data may therefore be processed outside your country. Where that happens from the UK or EEA, transfers rely on the receiving provider's Standard Contractual Clauses or an adequacy decision.
09Security
Traffic is encrypted in transit with TLS. Sign-in uses one-time email links rather than passwords, so there is no password of yours for us to lose. Session cookies are HttpOnly, so JavaScript cannot read them. Payment details never reach our servers.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant regulator as the law requires.
10Children
This is a service for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, email us and we will delete it.
11Changes to this policy
When this policy changes we update the date at the top. For a change that materially affects your rights, we will say so on the site or by email rather than expecting you to notice.
The short version: we collect what you send us so we can do the work, we use a handful of named processors to run the business, we never sell your data, and you can have it deleted by sending one email to info@ezomfy.com.
Questions about this page? Get in touch.
