Legal
Privacy Policy
Last updated: August 2026
1. Who We Are
For Daily Use is a Shopify embedded application operated by For Daily Use. This policy explains what data we collect, how we use it, and how we protect it when you use For Daily Use or when your customers enter a draw on a store running our app.
2. Data We Collect
From merchants (store owners):
- Shopify store domain and access token (required to operate as an embedded app)
- Store contact email address (used to send you service and account email — see Section 3)
- Klaviyo API key, if provided (stored per shop to enable optional Klaviyo integration)
- Billing plan and Shopify subscription ID
From draw entrants (your customers):
- First name and last name
- Email address
- Phone number
- IP address at time of entry
- Entry timestamp
- Size/variant preference selected on the entry form
- Marketing opt-in status (checkbox)
- Bot risk score, risk label, and risk reason data (automated signals — see Section 5)
3. How We Use Data
Merchant data is used to authenticate your Shopify store, manage your subscription, and operate the app features you've configured.
We also use your store's contact email address to send you email about the app itself — service notices, account and billing changes, and occasional product updates. These are sent from our own domain, separately from anything your customers receive. Every non-essential message includes a one-click unsubscribe, and opting out never affects service notices you need to receive. We do not send marketing email to your draw entrants at any time; the only email they receive comes from Shopify, from your store.
Entrant data is collected on behalf of the merchant running the draw. It is used to:
- Record and deduplicate entries
- Run the winner draw engine
- Create draft order invoices for winners via Shopify's API
- Apply Shopify customer tags to entrant profiles
- Sync opted-in entrants to Klaviyo (if the merchant has enabled this integration)
- Score entries for bot risk and exclude high-risk entries from the draw
We do not sell entrant data. We do not use entrant data for any purpose other than operating the draw the entrant submitted to.
4. Klaviyo Data Sharing
If the merchant has connected a Klaviyo account, we will sync opted-in entrants (those who checked the marketing consent box on the entry form) to Klaviyo as profiles and events. Only entrants with explicit marketing consent are synced. Entrants who did not opt in are stored in our database only and are never sent to Klaviyo. Bot-flagged entries above the merchant's risk threshold are also excluded from Klaviyo sync.
5. Bot Risk Scoring
Every draw entry is automatically evaluated by a risk scoring system to detect automated and fraudulent entries. The categories of data used in that evaluation are: how the submission was completed and behaved, the network address it came from, the reputation of the email domain, and the internal consistency of the details provided. We do not publish the individual detection methods or their weightings, because doing so would allow them to be circumvented.
The following is stored on each entry record and is visible to the merchant in their admin:
- botRiskScore — a numeric risk score
- botRiskLabel — a categorical label: Low, Medium, High, or Critical
- botRiskReasons — the reasons that contributed to the score
This scoring affects one thing only: whether an entry is eligible to win that particular draw. It produces no consequence for the entrant outside that draw, is not shared with third parties, and is not used to build any profile of the individual. A merchant can review any flagged entry and reinstate it.
6. IP Address Storage
IP addresses are collected at entry submission and stored with the entry record. They are used only to detect automated and duplicate entries. They are not shared with third parties and are not used for tracking or advertising.
IP addresses are automatically anonymized (removed from entry records) 90 days after a draw ends. This process runs as a nightly automated job and applies to all draws whose end date was 90 or more days prior.
7. Cookies
We use minimal cookies for analytics purposes only (e.g., page view tracking). We do not use cookies for advertising or cross-site tracking. The entry form pages do not set persistent cookies on the entrant's browser beyond what is required for the Shopify theme session.
8. Data Retention
Entrant data (name, email, phone, entry records, and bot risk data) is retained for the duration of the merchant's use of the app, plus a 48-hour grace period after uninstall. Permanent deletion occurs when Shopify's shop/redact request is received (see Section 9).
IP addresses are subject to an earlier retention limit: they are automatically anonymized 90 days after the draw they were collected for ends, regardless of whether the merchant's account remains active. See Section 6 for details.
9. Data Deletion on Uninstall
When a merchant uninstalls For Daily Use, their store's access token is immediately invalidated so no further API calls can be made on their behalf. Draw records, entry records, winner records, and Notify Me subscriber records are retained for 48 hours.
If the merchant reinstalls the app within 48 hours, all data is restored and the store picks up exactly where it left off. If the merchant does not reinstall, Shopify sends a shop/redact request after 48 hours, at which point all remaining data is permanently and automatically deleted: all draw records, all entry records (including name, email, phone, IP address, and bot risk data), all winner records, and all Notify Me subscriber records.
10. GDPR Compliance
For Daily Use is designed to be used in a manner consistent with GDPR requirements. Merchants are the data controllers for entrant data collected through their draws. For Daily Use acts as a data processor on behalf of the merchant. Merchants are responsible for ensuring their use of the app complies with applicable data protection laws in their jurisdiction, including providing appropriate disclosures to their customers.
Entrants located in the EEA or UK have the right to access, correct, or request deletion of their personal data. Requests should be directed to the merchant whose draw the entrant participated in. Merchants may contact us at privacy@fordailyuse.com to fulfill data subject requests.
11. Data Security
Access tokens and API keys are stored with encryption at rest. All data in transit is encrypted via TLS. Access to production data is restricted to authorized personnel only.
For details on how we respond to security incidents, including our merchant notification commitments and credential revocation procedures, see our Security Incident Response Policy.
12. Contact
For data-related inquiries, contact us at: privacy@fordailyuse.com