Privacy Policy
Effective 28 September 2026
This policy describes how SRH Web Agency (“we”, “us”, “Smart Contact Form Builder”) handles information when merchants install and use the Shopify app Smart Contact Form Builder. It is written for Shopify’s App Store listing and for merchants who need to know what the app accesses on their shop.
Smart Contact Form Builder is a merchant tool. Shoppers on a merchant’s storefront may submit forms; they do not create a Smart Contact Form Builder account.
1. Who is responsible
SRH Web Agency operates Smart Contact Form Builder and the production app at https://smartforms.srhwebagency.com. Shopify remains responsible for the merchant’s store, Admin, and Checkout. Merchants remain responsible for their own storefront privacy notices to shoppers.
2. Shopify permissions we request
Smart Contact Form Builder uses the Shopify Admin GraphQL API only (not the REST Admin API). After install, the app requests these access scopes (read_themes,read_content,write_content):
read_themes— list themes so Publish can deep-link into the theme editor.read_content— list Online Store pages for publish targets.write_content— create or update Online Store pages when a merchant (or demo tooling) publishes a form onto a page.
Smart Contact Form Builder does not request customer-profile, order, or checkout scopes. We do not read customer addresses or payment methods from Shopify.
3. Merchant data we store
All application data is scoped to the installing shop. We store:
- Shop identity and sessions. Shop domain, install time, plan label (Free on development stores; Premium or Advance via Shopify Billing on live stores), and OAuth session records (offline access token and, for online sessions, staff fields as provided by Shopify’s session storage). Charges are created only through Shopify Billing; see our Terms for plan prices.
- Forms. Form definitions (fields, appearance, mail settings, after-submit behavior) created in the app.
- Submissions. Answers submitted from the storefront (including optional uploaded files stored as media assets).
- App settings. SMTP / mail provider preferences and optional custom CSS scoped to the shop.
- Support drafts. If a merchant uses Contact in the admin, a draft of their message may be saved with shop settings until they send or we purge the shop.
4. Shopper (customer) data
When a shopper submits a form, answers may include personal data such as name, email, phone, message content, and uploaded files. That data is stored as form submissions scoped to the merchant shop. We do not create separate shopper accounts in this app.
Merchants should mention storefront forms in their own privacy policy if required by their region. Shoppers should contact the merchant first for storefront privacy requests.
5. How we use this data
- Provide the form builder and storefront embeds.
- Show merchants their submissions and export tools.
- Send admin notifications and auto-responders when configured.
- Respond to uninstall and mandatory compliance webhooks.
- Deliver merchant support messages when Contact is used.
We do not sell personal data. We do not use shopper submission data for advertising networks. We do not train third-party AI models on merchant forms or shopper answers.
6. Where data is stored
- Local development: SQLite on the developer machine.
- Production: the app process is intended to run on Hostinger (Node.js). Production databases may use PostgreSQL (for example Supabase) when configured — not Hostinger MySQL.
- Shopify: OAuth and the merchant’s store remain on Shopify.
- Email: if SMTP is configured, messages are sent through that provider. Contact messages may be delivered to our support inbox.
Access tokens are stored in the shop’s session row and used only to call Shopify Admin GraphQL for that shop.
7. GDPR and Shopify mandatory webhooks
Smart Contact Form Builder implements Shopify’s mandatory compliance webhooks. Shopify authenticates each request before we process it.
customers/data_request— we log a non-PII audit row and report what shopper submission data we hold for that shop when applicable.customers/redact— we delete matching form submissions (and related uploaded media) for that customer identifier, then record a non-PII audit row.shop/redact— after uninstall, we purge shop-scoped sessions, forms, submissions, media, and settings. If purge fails we return an error so Shopify can retry.app/uninstalled— we run the same cleanup path when the merchant uninstalls, without waiting forshop/redact.
Compliance webhook receipts are stored in an audit table keyed by shop domain (not a foreign key to the shop). Rows store shop domain, request id, topic, status, and timestamp — not raw customer webhook bodies.
8. Data retention
- While installed: forms, submissions, and settings are kept so the product works.
- After uninstall / shop redact: shop-scoped sessions and tenant data are deleted as described above.
- Compliance audit logs may be retained without PII for App Store evidence.
- Support email copies may remain in our support inbox.
9. Cookies and similar technology
The embedded admin uses Shopify’s session cookies to keep the merchant logged in. This public marketing site does not set marketing cookies. Storefront forms may use normal browser networking to the App Proxy; they do not create a separate Smart Contact Form Builder shopper login cookie.
10. International transfers
The app process may be hosted on Hostinger. Databases may be hosted with a cloud Postgres provider. Shopify remains the merchant’s store and Admin host. If a merchant or shopper is in the EEA, UK, or another region, data described above may be processed where those hosts operate in order to provide the app.
11. Your choices and requests
Merchants can:
- Uninstall the app, which starts deletion of shop-scoped data.
- Use Shopify Admin → Apps to review permissions, or Shopify’s customer privacy tools (those trigger the webhooks above).
- Contact us in-app (Smart Contact Form Builder → Contact) or email sohilhunani11@gmail.com.
Shoppers should contact the merchant first. The merchant can use Shopify’s customer privacy tools; we will receive the corresponding webhook.
12. Children
Smart Contact Form Builder is a B2B Shopify app. We do not knowingly collect personal information from children. Submission data comes from the merchant’s storefront forms, not from child accounts we create.
13. Changes
We will update this page when our data practices or Shopify requirements change. The effective date at the top will change. The current version is always at this URL.
14. Contact
SRH Web Agency — Smart Contact Form Builder
Email: sohilhunani11@gmail.com
In-app: Smart Contact Form Builder → Contact
Also see our Terms of Service.