Otheriver Margin Privacy Policy

Effective date: August 18, 2026

This Privacy Policy explains how Otheriver Margin (the “App”) collects, uses, stores, and discloses information when a Shopify merchant installs or uses the App. The App is provided by Otheriver, operated by Alex Marcone, Via Riccitelli 3, 64100 Teramo, Italy (“Otheriver”, “we”, “us”, or “our”).

1. Scope and roles

This Policy applies to the Otheriver Margin Shopify application, its embedded administration interface, and its optional Meta integration. For merchant account, support, security, and billing administration data, Otheriver acts as a data controller. When we process Shopify store data solely to provide the App on a merchant’s instructions, we act as a processor or service provider for that merchant, as applicable.

2. Information we process

Shopify store and merchant information

  • Shop identifier and myshopify.com domain, store name, country, currency, and time zone.
  • Order identifiers, dates, financial totals, currency, line-item quantities, product and variant identifiers, SKUs, and product cost information required to calculate revenue, costs, margins, and plan usage.
  • Product and inventory cost information made available through the Shopify APIs approved by the merchant.
  • Shopify session and authorization information required to authenticate the installation and make authorized API calls.

The App does not request or intentionally store customer names, customer email addresses, shipping addresses, payment card details, or full payment credentials. Shopify may transmit limited identifiers in mandatory privacy requests; these are used only to locate and complete the request.

Information entered by the merchant

  • Product costs, payment-fee assumptions, recurring or one-time expenses, settings, language preference, and Tax Reserve rules and percentages.
  • Subscription choice and usage information. Subscription payment processing is handled by Shopify; we do not receive payment card details.
  • Messages and contact information that a merchant voluntarily sends to support.

Optional Meta information

If a merchant connects Meta, the App processes the selected Meta ad-account identifier, campaign, ad-set and ad identifiers and names, status information, daily advertising spend, and related performance insights needed for the profit dashboard. The App requests the minimum permission used by this feature, currently ads_read. Meta OAuth access tokens are encrypted at rest. The App does not publish advertisements or modify campaigns.

Technical information

We may process security, diagnostic, request, and error logs, timestamps, IP address information made available by our infrastructure providers, and session cookies needed to operate the embedded App. Otheriver Margin does not install tracking cookies or scripts on the merchant’s storefront and does not sell personal information or use merchant data for third-party advertising.

3. How we use information

  • Provide and secure the App, authenticate merchants, and maintain sessions.
  • Import authorized Shopify data and calculate revenue, product costs, expenses, Meta spend, Tax Reserve estimates, margins, ROI, and related metrics.
  • Provide subscriptions, enforce plan limits, maintain service reliability, troubleshoot errors, and respond to support requests.
  • Meet legal obligations, process privacy requests, prevent fraud or misuse, and protect merchants, Otheriver, Shopify, and Meta.

We do not use Shopify or Meta data to build advertising profiles, sell data, or advertise to a merchant’s customers.

4. Legal bases

Where the GDPR or similar law applies, processing is based on performance of our contract with the merchant, our legitimate interests in providing and securing the App, compliance with legal obligations, and consent where consent is required. A merchant may disconnect Meta at any time from the App.

5. Service providers and disclosures

We disclose information only as needed to operate the App, comply with law, or protect rights. Current core providers include Shopify for installation, APIs, authentication and billing; Railway and its infrastructure subprocessors for application hosting and PostgreSQL database services; and Meta when the merchant chooses to connect Meta products. These providers process information under their own terms and privacy commitments. We may also disclose information to competent authorities when legally required or in connection with a business reorganization, subject to appropriate safeguards.

6. International transfers

Otheriver is based in Italy. Some service providers may process information outside Italy or the European Economic Area. Where required, transfers are supported by recognized safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.

7. Retention and deletion

  • Active-installation data is retained while needed to provide the App and for legitimate security, accounting, or legal purposes.
  • Shopify access sessions and App-held Meta OAuth tokens are deleted when the App is uninstalled. A Meta token is also deleted when the merchant disconnects Meta.
  • Selections for a disconnected Meta account are deleted. Historical aggregated advertising-spend records may remain so the merchant’s prior profit reports remain consistent until the App is uninstalled or deletion is requested.
  • Operational shop data is deleted within 30 days after uninstall or a valid deletion request, unless retention is legally required.
  • Residual encrypted backups are removed or overwritten within 90 days.
  • Records required for tax, accounting, dispute, fraud-prevention, or legal compliance may be retained for the period required by law.

8. Shopify privacy requests

Otheriver Margin supports Shopify’s mandatory privacy webhooks for customer data requests, customer redaction, and shop redaction. Requests are authenticated and handled within the time required by Shopify and applicable law. Because the App does not intentionally store customer contact details, a customer request normally returns no customer profile data from the App.

9. Your choices and rights

Depending on applicable law, merchants and individuals may have rights to access, correct, delete, restrict, object to processing, or receive a portable copy of personal information, and to complain to a supervisory authority. To exercise a right, contact apps@otheriver.com. We may need to verify the request and may direct a customer request through the relevant Shopify merchant.

10. Meta data deletion

A merchant can remove Meta access from the Otheriver Margin Meta page by selecting Disconnect. This deletes the App-held Meta OAuth token and current Meta selections. A merchant may also request deletion by emailing apps@otheriver.com. Valid requests are completed within 30 days, subject to legal retention requirements.

11. Security

We use reasonable technical and organizational safeguards, including encrypted transport, access controls, tenant separation by Shopify shop, encrypted Meta tokens, restricted production credentials, and monitored hosting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Children

The App is a business service for Shopify merchants and is not directed to children.

13. Changes to this Policy

We may update this Policy to reflect changes to the App, providers, or legal requirements. The effective date above will be updated when material changes are published.

14. Contact

Otheriver / Alex Marcone
Via Riccitelli 3
64100 Teramo, Italy
apps@otheriver.com

This document describes the App’s current data practices and is not legal advice.