Privacy Policy — Flow Fill
Last updated: 11 July 2026
Flow Fill ("the App", "we", "us") helps Shopify merchants audit their Klaviyo lifecycle email flows, build the missing ones, and measure real email revenue. This policy explains exactly what data the App accesses, why, and how it is protected. We hold no customer personal data: the App requests no read_customersand no read_orders scope, and never stores a customer's name, email, phone, address, IP or order contents. The complete list of what it does read is below.
What we access
- Your Klaviyo flow metadata (flow names and status) via a private API key you provide, to detect which lifecycle flows you have versus which are missing, and to create draft flows and campaigns you review.
- Your store's brand context (shop name, product titles, content) via
read_productsandread_content, used only to ground generated email copy in your brand voice. - Your published theme's settings (
read_themes) — we read the main theme'sconfig/settings_data.jsonfor its brand colours, so generated emails match your storefront. - Your markets and languages (
read_markets/read_locales) — market names, countries, currency and locales, so flows and campaigns can be built per market in the right language. - Discounts you ask the App to create (
read_discounts/write_discounts), as unique single-use codes. - Checkout events via our first-party Web Pixel (
read_customer_events/read_pixels/write_pixels). Shopify deliverscheckout_completedinto a sandboxed worker; we read four fields from it and transmit only those — order value, currency, the UTM parameters of our own flow/campaign tags, and the checkout token used solely to de-duplicate a repeated beacon — to measure real, first-party email revenue. Name, email, phone, address and line items are left unread and never leave the shopper's browser.
What we never access
- Orders, customers, or any customer personal data (name, email, phone, address) — on Shopify or in Klaviyo. We never request
read_ordersorread_customers, and our pixel filters out personal data.
How we use it
- To produce the flow-gap audit, generate on-brand draft emails and campaigns (pushed to Klaviyo as drafts you review — never sent automatically), and report your first-party email revenue.
- We do not sell your data, and we do not use it to train third-party models. LLM generation runs under a zero-retention agreement.
Security & retention
- Your Klaviyo key and any Shopify access token are encrypted at rest (AES-256-GCM) and are never returned to the browser or written to logs.
- On uninstall and on a Shopify
shop/redactrequest, all of your stored data is deleted. - The GDPR
customers/data_requestandcustomers/redactwebhooks are answered truthfully: we hold no customer personal data.
Contact
Questions about this policy or your data: gheorghe.beschea@overheat.agency.