Unformed Privacy Policy
Version 1.3 — Effective date: 31 July 2026
> This version has been aligned with what is actually implemented in the > platform. Where a retention period or safeguard is not yet automated, it says so.
1. Who is Unformed?
Unformed is a software platform that lets organisations build interactive feedback flows, collect feedback, and generate insights from conversations and answers.
Unformed is provided by:
| Legal name | D.E. DIGITAL (sole proprietorship) |
| Trading name | Unformed / Unformed AI |
| Registered address | Pacayastraat 2 B17, 1105 BT Amsterdam, Netherlands |
| Dutch Chamber of Commerce number | 73677671 |
| Email for privacy enquiries | privacy@unformed.ai |
Referred to in this policy as "Unformed", "we" or "us".
2. Who does this policy apply to?
- organisations and staff who use an Unformed account;
- customers of Shopify stores belonging to organisations that use Unformed;
- people who complete a feedback flow, interview, survey or conversation;
- people who contact us for support or other questions;
- visitors to the Unformed website and application.
3. Unformed's role
3.1 As controller
For data we process for our own business operations: merchant account and contact details, subscription and billing data, support communication, security and access logs, platform usage data, and data needed to prevent abuse and security incidents.
3.2 As processor
When a merchant uses Unformed to process customer data from Shopify, send invitations or collect feedback. The merchant then determines the purpose, the audience, the questions, the legal basis and the retention period.
Questions from Shopify customers or respondents about their privacy rights should in principle be directed to the merchant concerned. Unformed supports the merchant in handling them.
4. What personal data do we process?
4.1 Merchants and users
Name, business email address, organisation and store name, job title or role, account ID and user ID, login and authentication data, subscription and billing status, support communication, settings and usage data.
4.2 Shopify customer data
For the post-purchase feedback feature we process only:
- email address;
- first name;
- language or locale setting;
- marketing and communication preference, including unsubscribe status.
What we do not request or store: last name, phone number, home address, billing address, payment details, card details, or the full customer profile.
This is not an intention but a technical boundary: the system rejects payloads containing monetary amounts with an error. The fields total_price, subtotal, amount, price and currency_amount are actively refused.
4.3 Order data
- Shopify order ID and order number;
- order date and time of fulfilment;
- fulfilment, payment and cancellation status as a status value;
- product and variant IDs, product titles and quantities;
- the customer's language at the time of the order;
- technical metadata that determines when an invitation is sent.
Amounts are not processed. Whether an order was fully refunded is derived from the status value Shopify provides, never from a calculation on totals.
4.4 Catalogue data
Product title, handle, product type, vendor, product image, product status and the store's product IDs.
This is not personal data. It is listed here because we do store it: it determines which feedback conversation belongs to which product, and it gives the AI agent context about what the conversation is about. Prices and inventory levels are not retrieved.
4.5 Discount codes
Where the merchant has configured discount codes as a reward, we create a discount in their store with a stock of unique codes beneath it. Each code can be used once and applies to one customer.
The code stock itself contains no personal data: only the code, the store, the expiry date, and whether it has been issued.
The link between a code and a person only comes into being at the moment of issue, and is recorded with the reward assignment: the respondent's email address and the code they received. See the retention periods below.
4.6 Feedback and conversation data
Answers, open text responses, ratings and scores, audio or transcription data where that feature is enabled, AI-generated follow-up questions and summaries, insights and recommendations, the date and status of the conversation, and the associated technical identifiers.
Respondents are asked not to share special categories of personal data, unless the merchant has lawfully and demonstrably arranged for this.
4.7 Technical and security data
IP address, browser type and device category, session and authentication data, times of use, error messages, audit logs, configuration changes, records of access to protected customer data, and information about suspicious activity.
5. What do we use personal data for?
Providing and securing the platform; connecting a Shopify store; identifying relevant orders; sending feedback invitations on behalf of a merchant; preventing contact with customers who have unsubscribed; running feedback flows; generating follow-up questions, summaries and insights; presenting results to the merchant; support; resolving technical problems; fraud prevention; legal obligations; and maintaining an access and incident record.
Unformed does not sell Shopify customer data or feedback data, and does not use it for our own advertising purposes.
6. Legal bases
As controller: performance of a contract, a legal obligation, a legitimate interest (security, fraud prevention, support, technical improvement), or consent where legally required.
As processor, the merchant is responsible for establishing and documenting the legal basis.
7. Use of artificial intelligence
Unformed may use OpenAI and Anthropic to generate follow-up questions, summarise conversations, identify topics, formulate insights and categorise feedback.
Only information necessary for the feature in question is sent to an AI provider. Shopify customer profiles and full order data are not forwarded by default; where context about an order is needed, it is limited to product titles and quantities.
Unformed uses business API services rather than consumer accounts, and disables settings for optional model training.
8. Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, storage, edge functions | eu-west-1 (Ireland) |
| Railway | Hosting of the Shopify app | EU West |
| OpenAI | Processing of selected conversation content | United States |
| Anthropic | Processing of selected conversation content | United States |
| Resend | Sending and delivery of email | eu-west-1 (Ireland) |
| Langfuse | Monitoring and quality control of AI interactions | eu-west-1 (Ireland) |
Not every provider is used in every flow. OpenAI and Anthropic may be used as alternative model providers.
The current list is available on request via privacy@unformed.ai and is published at https://unformed.ai/dpa/#current-sub-processors. Unformed concludes a data processing agreement with all relevant providers.
9. Transfers outside the EEA
OpenAI and Anthropic process in the United States. For those transfers Unformed relies on the European Commission's Standard Contractual Clauses, supplemented by the safeguards described in section 11.
All other sub-processors process within the EEA. Database, hosting, storage, email delivery and monitoring run in eu-west-1 (Ireland), for both the production and the development environment.
The only transfer outside the EEA is therefore the one to the AI providers, and it concerns conversation content only — not the contact details used to send an invitation.
10. Retention periods
The periods below are applied automatically by a daily clean-up job, unless stated otherwise.
Order data — 180 days
Order events are automatically deleted 180 days after they are recorded.
Email address and name on an invitation — 90 days
Ninety days after the invitation was sent, or after the scheduled send time if it was never sent, the email address and name are replaced with an untraceable value and the invitation link is invalidated.
The conversation and the feedback given remain; only the traceability to the person disappears.
Access log — 24 months
Records of access to protected customer data are kept for 24 months and then deleted automatically. The log contains no email addresses, names or conversation content — only which store, which key, which operation, how many records and when.
Register of data subject requests — 24 months
Handled requests are deleted 24 months after they are resolved. The register contains no email address of the requester, only the store domain, the Shopify customer ID and references to the records involved.
A request that has not yet been handled is retained regardless of age.
Discount codes
The code stock remains for as long as the discount is running; expired codes are not cleaned up automatically. Because that stock contains no personal data, this is a matter of tidiness rather than retention.
The link between an issued code and the recipient's email address is held with the reward assignment. This link is not currently deleted automatically. It is erased upon a customer deletion request, upon deletion of the store, and upon termination of the account. Automation is planned.
We state this explicitly because it is the only place where a discount code can be linked to a person.
Feedback and conversation content
Retained according to the merchant's settings. This period is not currently enforced automatically; deletion takes place at the merchant's request or upon termination of the account. Automation is planned.
Delivery data at the email provider
Technical delivery statuses are retained according to Resend's retention period. Unformed does not keep a separate copy of delivery logs.
Unsubscribe records
A minimal record of unsubscribes is kept longer, to prevent someone who has unsubscribed from being contacted again. Without that record, an unsubscribe would lose its effect at the next order.
Account and billing data
Account data for the duration of the customer relationship and up to 24 months thereafter. Invoices for the statutory tax retention period.
On termination
When the Shopify app is uninstalled, Unformed receives a deletion instruction from Shopify and everything belonging to that store is deleted: invitations, order events, product data, the connection and the associated access key.
Upon termination of the merchant account itself, Unformed deletes the data within 90 days. This is currently a manual procedure.
11. Security
Implemented concretely:
- TLS encryption for all traffic;
- encryption of stored data by the database provider;
- additional encryption of per-store API keys with AES-256-GCM, with the key held
outside the database;
- separate database environments for development and production;
- a dedicated database role for the Shopify app with no rights whatsoever on
platform data, enforced by the database itself;
- row-level security on all tables containing customer data;
- signature verification on all incoming Shopify webhooks;
- connection codes that are single-use and expire after sixty seconds;
- a shared secret between app and platform, so that an intercepted connection
code is worthless on its own;
- a record of every access to protected customer data;
- automated deletion procedures;
- multi-factor authentication and a password manager for administrative access;
- backups and recovery procedures via the database provider.
No system is without risk. Unformed reviews and improves these measures periodically.
12. Privacy rights
Data subjects may have the right to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and to lodge a complaint with a supervisory authority.
Where Unformed processes data on behalf of a merchant, a request should in principle be submitted to that merchant. Unformed supports the merchant in handling it.
Requests may also be sent to privacy@unformed.ai. Please state the name of the webshop concerned.
Requests received through Shopify are registered automatically with a thirty-day handling deadline, and Unformed is notified. The registration records which records relate to the request — not the requester's email address, since that is precisely the data the request is about.
13. Automated processing
Unformed uses AI to analyse feedback and generate follow-up questions or recommendations. Unformed does not take independent decisions about individuals with legal consequences. Merchants remain responsible for how the generated insights are used.
14. Children
Unformed is not directed at children. Merchants who use the platform for minors are themselves responsible for a valid legal basis and any required consent.
15. Changes
Unformed may amend this policy when the service, legislation or the providers used change. The most recent version is published with an updated effective date. Merchants are informed of material changes through the platform or by email.
16. Contact and complaints
Email: privacy@unformed.ai Postal address: Pacayastraat 2 B17, 1105 BT Amsterdam, Netherlands
Data subjects may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent supervisory authority.
*This policy is also available in Dutch at https://unformed.ai/nl/privacy/. In the event of any discrepancy between the two versions, the English version prevails.*