Privacy Policy
Last updated: 2026-08-18
This Privacy Policy explains how Gainify ("we", "us") handles data in our mobile and Shopify apps and on gainifyapps.com. We are based in Spain and follow the EU General Data Protection Regulation (GDPR) and Spanish data-protection law.
Data controller
The data controller responsible for any processing described here is:
- Name: Gainify
- Contact: Support page
Who this policy covers
We publish two different kinds of software, and they handle data differently. This policy covers both:
- Our iOS apps, downloaded from the Apple App Store by individual users — these work on-device.
- Our Shopify apps, installed by merchants on their Shopify store — these run as a hosted service connected to the merchant’s store.
- This website, gainifyapps.com.
Our iOS apps store your data on your device
Our iOS apps are built to work on-device. The content you create and the data the app reads (for example device scans, settings and preferences) stays on your phone — we don’t run a server that receives it, and we don’t have user accounts for it. We don’t sell your personal data. The one exception is purchases: if an app offers a subscription or in-app purchase, that is handled by Apple and our subscription provider RevenueCat, as described below.
Some of our apps use Bluetooth and your local network to find nearby devices, trackers and earbuds and to list the devices on your Wi-Fi. This scanning runs on your device and the results are not sent to us.
Permissions our iOS apps may request
Where an app asks for a system permission, it is used only to provide the feature you requested and is processed on your device:
- Bluetooth — to find nearby Bluetooth devices, trackers and earbuds.
- Local Network — to list the devices on your Wi-Fi network.
- Location — only where iOS requires it to scan for nearby devices; your location is not stored or shared.
Our Shopify apps
When a merchant installs one of our Shopify apps, the app runs as a hosted service that connects to their Shopify store through Shopify’s official APIs, using only the access scopes shown on the installation screen. The merchant can review and revoke that access at any time by uninstalling the app from their Shopify admin.
To run the app we store: basic store information provided by Shopify (shop domain, store name, the store’s contact email, plan, country, currency and timezone), the API access token issued at install, the settings and content the merchant configures in the app, and technical logs needed to keep the service working and secure. We request the minimum scopes each app needs, and we do not request access to your customers’ personal data, order contents or payment details unless an app’s stated features require it and the scope is disclosed at install.
Where an app displays content on a storefront, that content is rendered from the merchant’s own settings. Our storefront code does not set cookies, does not build shopper profiles and does not send shopper personal data to us.
Shopify apps: our role, subprocessors and deletion
For the merchant’s own account and store data we are the data controller. Where an app processes personal data belonging to a merchant’s customers, we act as a processor on the merchant’s documented instructions — the merchant remains the controller and is responsible for their own privacy notice and any consent required from their shoppers.
We use a small number of subprocessors to run the service: our hosting and database provider, and Shopify itself as the platform the app runs on. Subprocessors are bound by written terms and may process data outside the EU under appropriate safeguards such as standard contractual clauses.
We support Shopify’s mandatory privacy webhooks. On a customer data request we return the personal data we hold for that customer, if any; on a customer redaction request we delete it; and when a store is redacted after uninstall we delete that store’s data, in each case within the periods Shopify requires (generally 30 days for data requests, and deletion within 30 days of a redaction request). Uninstalling an app immediately revokes our access token.
Billing for paid Shopify apps runs through Shopify’s Billing API and appears on the merchant’s Shopify invoice. We never see or store payment-card details.
Purchases and subscriptions (iOS)
If an iOS app offers a subscription or in-app purchase, the payment is processed by Apple through the App Store under Apple’s terms and privacy policy. We never receive your payment-card details.
To unlock features and keep your subscription status in sync we use RevenueCat, Inc., a US provider acting as our processor. When you buy or restore a purchase, RevenueCat receives purchase and receipt information, an app-generated user identifier (not your name or email) and basic device/app data, in order to validate the purchase and manage entitlements. This may be processed in the United States under appropriate safeguards. See Apple’s and RevenueCat’s privacy policies for details.
This website
gainifyapps.com is a static site. It has no accounts and no forms that send data to a server. We use Cloudflare Web Analytics, which is privacy-first and cookieless: it does not use cookies, does not fingerprint visitors, and does not collect personal data. As our hosting provider, Cloudflare may process limited technical data (such as IP address) to deliver and secure the site; see Cloudflare's privacy documentation.
With your consent, we also use Google Analytics (Google Ireland Limited / Google LLC). It loads only after you accept our cookie banner, sets cookies, and may transfer data to the United States under appropriate safeguards. You can withdraw consent at any time via “Cookie settings” in the footer. See our Cookie Policy for the details.
Legal basis
For our iOS apps (data processed only on your device) and the cookieless website analytics, our processing relies on your use of the software (performance of the service you requested) and our legitimate interest in operating a secure, functional site.
For purchases, subscriptions and our Shopify apps, the legal basis is performance of our contract with you or with the merchant (GDPR Art. 6(1)(b)), together with our legitimate interest in keeping the service secure and preventing abuse (Art. 6(1)(f)). Where we process a merchant’s customers’ personal data, we do so as a processor under Art. 28 on the merchant’s instructions.
For the optional Google Analytics on this website, the legal basis is your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, and to data portability. Because iOS app data lives on your device, you can exercise most of these directly — by editing or deleting data in the app, or by deleting the app. For purchase data, you can also contact Apple or RevenueCat. For anything else, reach us via our Support page.
If you are a merchant using one of our Shopify apps, contact us and we will action your request; uninstalling the app also starts the deletion process described above. If you are a shopper who bought from a store that uses one of our apps, the merchant is the controller of your data — please contact the store directly, and we will assist them as their processor.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es).
Data retention
For our iOS apps we don’t keep your personal data on our own servers. Data created in an app stays until you delete it or remove the app. Purchase records held by Apple and RevenueCat are retained under their policies and as needed for accounting, tax and subscription management.
For our Shopify apps we keep store data for as long as the app is installed. After uninstall we delete the store’s data on Shopify’s shop-redaction webhook, and in any case within 30 days, except where we must keep billing and tax records for the period required by law. Technical logs are kept for a short period for security and troubleshooting and then deleted.
Children's privacy
Our apps are not directed to children under 13, and we do not knowingly collect personal data from children. Some apps carry a higher age rating on the App Store — our wine-related apps are rated 18+ — and should only be used by people old enough for that rating. If you believe a child has provided personal data, contact us and we will delete it.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about privacy? Reach us via our Support page.