Privacy Policy

Effective 28 September 2026

This policy describes how SRH Web Agency (“we”, “us”, “Smart Contact Form Builder”) handles information when merchants install and use the Shopify app Smart Contact Form Builder. It is written for Shopify’s App Store listing and for merchants who need to know what the app accesses on their shop.

Smart Contact Form Builder is a merchant tool. Shoppers on a merchant’s storefront may submit forms; they do not create a Smart Contact Form Builder account.

1. Who is responsible

SRH Web Agency operates Smart Contact Form Builder and the production app at https://smartforms.srhwebagency.com. Shopify remains responsible for the merchant’s store, Admin, and Checkout. Merchants remain responsible for their own storefront privacy notices to shoppers.

2. Shopify permissions we request

Smart Contact Form Builder uses the Shopify Admin GraphQL API only (not the REST Admin API). After install, the app requests these access scopes (read_themes,read_content,write_content):

Smart Contact Form Builder does not request customer-profile, order, or checkout scopes. We do not read customer addresses or payment methods from Shopify.

3. Merchant data we store

All application data is scoped to the installing shop. We store:

4. Shopper (customer) data

When a shopper submits a form, answers may include personal data such as name, email, phone, message content, and uploaded files. That data is stored as form submissions scoped to the merchant shop. We do not create separate shopper accounts in this app.

Merchants should mention storefront forms in their own privacy policy if required by their region. Shoppers should contact the merchant first for storefront privacy requests.

5. How we use this data

We do not sell personal data. We do not use shopper submission data for advertising networks. We do not train third-party AI models on merchant forms or shopper answers.

6. Where data is stored

Access tokens are stored in the shop’s session row and used only to call Shopify Admin GraphQL for that shop.

7. GDPR and Shopify mandatory webhooks

Smart Contact Form Builder implements Shopify’s mandatory compliance webhooks. Shopify authenticates each request before we process it.

Compliance webhook receipts are stored in an audit table keyed by shop domain (not a foreign key to the shop). Rows store shop domain, request id, topic, status, and timestamp — not raw customer webhook bodies.

8. Data retention

9. Cookies and similar technology

The embedded admin uses Shopify’s session cookies to keep the merchant logged in. This public marketing site does not set marketing cookies. Storefront forms may use normal browser networking to the App Proxy; they do not create a separate Smart Contact Form Builder shopper login cookie.

10. International transfers

The app process may be hosted on Hostinger. Databases may be hosted with a cloud Postgres provider. Shopify remains the merchant’s store and Admin host. If a merchant or shopper is in the EEA, UK, or another region, data described above may be processed where those hosts operate in order to provide the app.

11. Your choices and requests

Merchants can:

Shoppers should contact the merchant first. The merchant can use Shopify’s customer privacy tools; we will receive the corresponding webhook.

12. Children

Smart Contact Form Builder is a B2B Shopify app. We do not knowingly collect personal information from children. Submission data comes from the merchant’s storefront forms, not from child accounts we create.

13. Changes

We will update this page when our data practices or Shopify requirements change. The effective date at the top will change. The current version is always at this URL.

14. Contact

SRH Web Agency — Smart Contact Form Builder
Email: sohilhunani11@gmail.com
In-app: Smart Contact Form Builder → Contact
Also see our Terms of Service.