Maestra: CDP Companion App for Shopify — Privacy Policy and Terms
Version 2.0 — July 20, 2026
1. Who we are and what this document covers
This policy applies to the processing of data through the Maestra: CDP Companion App for Shopify (the "App"). References to "Maestra," "we," and "us" mean the Maestra contracting entity identified in your Order Form: Maestra.io LLC (United States) or Maestra B.V. (European Union).
The App is available only to merchants who have entered into a signed agreement with Maestra — a Software as a Service Agreement together with an Order Form (together, the "Agreement"): US SSA · EU SSA. This policy supplements the Agreement, the Maestra Privacy Policy and, for processing in the EU/EEA, the Maestra Personal Data Policy (EU). It contains only App-specific terms; all other matters are governed by those documents.
If anything in this policy is inconsistent with your signed Agreement, the Agreement prevails.
2. Terms of use
Your use of the App and of the Maestra platform is governed by your Agreement, including the Acceptable Use Policy incorporated into it. Installing the App does not create a separate contract or a separate data processing agreement. The processing of personal data through the App is governed by Section 7 of the US SSA or, for merchants contracting with Maestra B.V., by the Data Processing Agreement (Annex 1) to the EU SSA.
3. Roles
For the personal data of your customers processed through the App, you are the controller (or "business" under US state privacy laws) and Maestra is your processor (or "service provider"), as set out in Section 7.4 of the US SSA and in the DPA to the EU SSA. Maestra processes this data only to provide the Services under your Agreement and on your documented instructions. Establishing the lawful basis for the processing of your customers’ personal data is your responsibility as controller.
4. Data the App processes
When you install and authorize the App, the following data is synced from your Shopify store to your Maestra workspace, limited to the minimum access scopes required for the App’s functionality:
- Customer information: full name, email address, phone number, billing and shipping address, customer tags, customer notes, Shopify customer ID, account creation date, and related customer metadata.
- Marketing consent status: email marketing opt-in status, SMS opt-in status, timestamp of consent, and consent source.
- Order details: order ID, order date, order status, line items (product names, variants, SKUs), quantities, total amount, discount codes used, fulfillment and payment status, and associated product/order metadata.
- Store metadata: Shopify shop domain, store name, store locale, store currency, time zone, and plan type.
- Customer activity events: product viewed, product added to or removed from cart, cart viewed, checkout started, shipping or contact information submitted, customer identified, checkout completed, collection viewed.
The App does not collect payment card data, customer passwords, or special categories of personal data.
5. Purposes
Data synced through the App is used solely to provide the Services to you under your Agreement: unifying customer profiles in your Maestra workspace, segmenting your audience, triggering the marketing workflows you configure, and providing reporting and analytics for your campaigns. Maestra does not sell your customers’ personal data and does not use it for Maestra’s own advertising.
6. Consent and the Shopify Customer Privacy API
Customer privacy preferences set in Shopify are respected. If your store uses Shopify’s Customer Privacy API, data tracking and marketing actions for a customer are deferred until valid consent exists. As between you and Maestra, obtaining and maintaining consent from your customers — and implementing and enforcing consent logic in your storefront — is your responsibility, as set out in Sections 3.2–3.4 and Exhibit D of your Agreement and in accordance with Shopify’s requirements.
7. De-identified data and AI
Maestra creates irreversibly de-identified, aggregated data ("Resultant Data" and "Anonymized Data," as defined in your Agreement) from use of the Services, and uses it to operate and improve the Services — including training the machine-learning models that power product features such as recommendations and predictions for all Maestra customers.
What we commit to, because each commitment is verifiable:
- Identifiable customer personal data is never used to train Maestra’s AI or machine-learning models and is never sold (Agreement, Section 3.7);
- Models built by Maestra are used solely within the Services and are never licensed, sold, or made available as standalone products;
- De-identified data is never used to identify, or to attempt to re-identify, any individual (Agreement, Section 10.1);
- Outputs shared outside the Services (such as benchmarks and industry insights) are aggregate-only and do not identify any merchant or any customer.
Your Agreement (Sections 3.5, 3.7, and 10.1) records your consent to Maestra’s creation and use of Resultant Data and Anonymized Data, including for AI and machine-learning model training. That signed consent also constitutes your prior written consent for the purposes of the Shopify Partner Program Agreement and the Shopify API License and Terms of Use.
Because Resultant Data and Anonymized Data have no per-customer lineage after derivation, they cannot be attributed to, extracted for, or deleted on behalf of any individual store or person. The deletion rights described in Section 11 therefore apply to identifiable data.
8. Sub-processors
The hosting and infrastructure providers engaged in delivering the Services are listed in the Maestra Personal Data Policy (EU) and are available at any time on request at dpo@maestra.io.
9. Data location and international transfers
The locations and hosting arrangements for production data are described in Section 8 of Exhibit C — Information Security Policy to the SSA. Where personal data is transferred across borders, Maestra relies on recognized transfer mechanisms — including adequacy frameworks and Standard Contractual Clauses — as set out in the applicable DPA and the Personal Data Policy (EU).
10. Security
Maestra’s technical and organizational measures — including encryption of data in transit (TLS 1.2 or higher) and at rest, role-based access controls, centralized logging, and incident response — are set out in Exhibit C — Information Security Policy to the SSA. Maestra’s information security program is audited annually against the SOC 2 Type II standard.
11. Retention and deletion
- During your Agreement: data synced through the App is retained in your workspace to provide the Services. You can configure retention periods for personal data in your account settings (Exhibit C, Section 7.2).
- Shopify privacy webhooks: the App subscribes to Shopify’s mandatory compliance webhooks. Data access requests (customers/data_request) are fulfilled to you as the controller. Redaction requests (customers/redact) and store deletion requests (shop/redact) are typically processed in near real time, and in any event within 30 days of receipt, except where retention is required by applicable law.
- App uninstall: when you uninstall the App, personal data received through the App is deleted from production systems following Shopify’s shop/redact webhook (sent by Shopify 48 hours after uninstall), on the timeline above. Uninstalling the App does not terminate your Agreement, and data received through integrations or sources other than the App is unaffected.
- Agreement termination: deletion of identifiable Customer Data upon termination is governed by your Agreement (US SSA, Section 15.3(b); EU SSA, Section 14.3(b)).
- Backups: backup copies of deleted data are purged on a rolling basis and are retained for no longer than six (6) months (Exhibit C, Section 7.3).
- De-identified data: Resultant Data and Anonymized Data are retained as described in Section 7.
12. Your customers’ privacy requests
Your customers should direct requests to access, correct, or delete their personal data to you, as the controller, or exercise them through Shopify’s privacy tools. Maestra actions the corresponding requests relayed by you or by Shopify as described in Section 11. Privacy questions about the App may be sent to Maestra’s data protection team at dpo@maestra.io (Maestra, 1167 Massachusetts Ave, Arlington, MA 02476).
13. Profiling and automated processing
The Services include profiling and predictive features (for example, segmentation, recommendations, and personalization) that operate under your configuration and control. You are responsible for providing any notices and opt-outs to your customers that applicable law requires in connection with your use of such features, as allocated in your Agreement.
14. Changes
We may update this policy from time to time; the current version date appears at the top of this page. For existing customers, material changes take effect through notification in accordance with the Agreement.