Privacy Policy — Review Lift
Last updated: 12 July 2026
Review Lift ("the App", "we", "us") helps merchants decide where to ask for product reviews and where to reply to low-rated ones, using their own review data and sales. This policy explains exactly what data the App accesses, why, and how it is protected. Review Lift is Protected Customer Data Level 1: it reads order data solely to total per-product units sold and stores no customer personal data.
What we access
- Your store's catalog and connected review data — product titles/handles and your review app's per-product review count and average rating (Judge.me, Loox, Yotpo, Okendo, Stamped metafields) via
read_products. - Your orders, via
read_orders, read only to total units sold per product over a trailing 90-day window. We sum quantity by product and discard everything else in the same step — this powers the sales-weighted review-gap worklist.
What we never access or store
- Customer names, emails, phone numbers, addresses, IP addresses, order IDs, or individual line-item rows. No customer personal data is retained at any point. We request no write scopes and no customer scopes.
What we store
- Per-product aggregates (title, review count, average rating, units sold — integers) and coverage snapshots over time (coverage %, rating distribution, the ranked worklist, sales-weighted coverage).
- Optional reply drafts (Pro only): AI-generated draft reply text for low-rated products, grounded only on the product title + rating. These are suggestions you edit and post yourself — we never auto-publish.
- Operational records: your shop domain, install/uninstall status, billing plan, and webhook logs (no PII).
How we use AI
- The one-click reply-draft feature (Pro only) sends a short prompt to Anthropic (Claude) to generate a draft. That prompt contains only the product title, its average rating, and review count — never customer data. Generation runs under a zero-retention agreement; we do not sell your data or use it to train third-party models.
Security & retention
- Data is transmitted over TLS. Any Shopify access token is encrypted at rest (AES-256-GCM) and is never returned to the browser or written to logs.
- On uninstall and on a Shopify
shop/redactrequest, all of your stored data is deleted. - The GDPR
customers/data_requestandcustomers/redactwebhooks are answered truthfully: we hold no customer personal data.
Contact
Questions about this policy or your data: privacy@syncerp.work.