1. Who we are and what this covers
CustomerHub Pty Ltd (“CustomerHub”, “C:Hub”, “we”, “us”) provides the C:Hub Shopify app, website and related support. Our address is 801 Glenferrie Rd, Hawthorn VIC 3122, Australia. Contact support@customerhubapp.com about privacy.
This policy distinguishes merchants using our service, customers using a merchant’s account experience, and visitors to our website. The merchant decides why it collects its customers’ information and which C:Hub features and integrations to enable. We generally process that shopper information on the merchant’s behalf. We are responsible for our own business contact, support and website information. Where applicable, our Data Processing Addendum describes our processor responsibilities.
2. Information we handle
| Category | Examples and purpose |
|---|---|
| Merchant and app information | Shop domain, owner/contact details, location and language settings, Shopify plan, customer count, installation state, app configuration, support history and billing/trial information. Used to provide and support the app. |
| Shopper and order information | Customer identifiers, names, email, phone, addresses, orders, fulfilment/tracking, preferences and supported custom fields. Used for the account features the merchant enables. |
| Product activity | Recently viewed or previously added products, product/variant details and timestamps. Used for configured product-history and repeat-shopping features. |
| Files and custom content | Profile images, supported uploaded files, custom field values and merchant-provided account content. Used for configured forms and account displays. |
| Technical and support information | Authentication/session data and access tokens, feature-use events, diagnostic information, contact messages and relevant merchant account context. Used to operate, troubleshoot and support the service. |
The information handled varies with the merchant’s setup and Shopify permissions. Shopify manages customer authentication. Classic-account registration or password-change forms may process a password to perform the requested Shopify action. This policy does not describe C:Hub as never handling credentials.
Website contact enquiries
If you use our website contact form, we receive your name, reply email, enquiry topic and message, plus any store domain, account area, connected-app name, affected page or screenshots you choose to provide. Store enquiries require a store domain; general and B2B questions do not. We remove query strings and fragments from the separate affected-page field to avoid passing sign-in tokens in that field. Please do not include passwords, access codes, payment information or unnecessary customer information in your message or images.
The website server sends the enquiry and optional images through Twilio SendGrid to our support inbox so our team can respond. Your email is used as the reply address. We do not use form submissions to sign you up for marketing. The website origin does not write enquiry bodies or images to a contact database; email and support systems retain the resulting correspondence under their applicable arrangements.
Hosting services receive normal technical request information. The form uses a short-lived security token, an essential browser session cookie, hashed request identifiers and temporary rate-limit records to prevent spam and repeat submissions. Production rate limits and delivery outcomes are kept in private Google Cloud Storage; these records contain hashes and request references, not enquiry bodies or images. Active records expire within two hours and expired entries are removed during subsequent submissions. Storage lifecycle deletion also removes an idle record file after one day, subject to the storage service?s asynchronous deletion schedule. These are separate from the support correspondence. Contact us if you need help accessing or deleting an enquiry.
3. Where information comes from and why we use it
We receive information from merchants and shoppers, from Shopify when authorized by the merchant, from enabled integrations, and from use of the website or app.
We use it to deliver the configured account experience, process requested account actions, maintain app settings, show feature-use reports, administer subscriptions, answer support requests, investigate faults or misuse, and meet legal obligations. If a requested field is not supplied, the related action or feature may not work; merchants should distinguish required from optional fields.
Where a law requires a legal basis, our own processing may rely on performing our agreement, legitimate interests in operating and securing the service, consent where required, or legal obligations. The merchant is responsible for the lawful basis and notices for its customer processing. This policy is not a request for blanket consent to every use of personal information.
5. Custom fields and files
Merchants choose the information requested in their forms and must give appropriate notices. Do not use C:Hub to collect health information, government identity documents, full payment-card details or other sensitive information without an appropriate written arrangement and safeguards.
Supported uploads can be passed to Shopify-hosted file storage and referenced from customer data. A file link is not a promise of private document storage. Merchants should confirm the intended visibility and handling before requesting documents from customers.
6. Retention and deletion
We retain personal information for the purposes for which it is needed, including providing the service, responding to requests, maintaining appropriate business and security records, and meeting legal obligations. Retention differs between app configuration, support records, operational logs and other data.
Uninstalling C:Hub stops app access and billing as described in the applicable Shopify subscription, but does not itself delete the merchant’s Shopify customer or order records. Data requests and deletion requests are handled through the applicable merchant, Shopify and service-provider processes. Contact us about the records involved and the applicable retention or deletion arrangements.
Where deletion is required, it must include relevant service records and copies, subject to lawful retention requirements and the applicable backup deletion process. Retention and backup expiry depend on the records involved and the applicable service arrangements.
7. International processing
CustomerHub operates from Australia and uses infrastructure and service providers that may process information in other countries, including the United States. The relevant locations depend on the service and provider arrangement.
Where applicable law requires safeguards for overseas processing, the appropriate legal mechanism must apply. Acceptance of this policy alone is not a substitute for an international-transfer safeguard. Contact us for the arrangements relevant to your store.
8. Your choices and privacy requests
If you are a shopper, contact the store first about your account, order or customer information. Merchants can use Shopify’s privacy-request processes and contact us for assistance with C:Hub-held information.
You can contact support@customerhubapp.com to request access or correction, ask about deletion, or raise a privacy concern. We may need to verify your identity or authority before disclosing or changing information. Where applicable law provides them, rights may also include portability, restriction, objection and withdrawal of consent. Withdrawing consent does not affect processing that was lawful before withdrawal.
We will assess requests and complaints and respond within the applicable legal timeframe. If you remain concerned, you may contact the Office of the Australian Information Commissioner or the relevant privacy regulator in your jurisdiction. These rights may be subject to lawful exceptions.
10. Updates and contact
Material changes to this policy will be communicated through the website and, where appropriate, merchant contact channels before taking effect. The date shown on this page identifies the current version.
Privacy contact: CustomerHub Pty Ltd, 801 Glenferrie Rd, Hawthorn VIC 3122, Australia. Email support@customerhubapp.com.
Questions about this document?
support@customerhubapp.com