Privacy Policy for Verba - Post-Purchase Surveys
Effective date: September 14, 2026 Last updated: September 14, 2026
Who we are
Verba - Post-Purchase Surveys ("Verba" or "the app") is a Shopify app made by homedoctor LLC ("we", "us", "our"). Merchants install Verba to show surveys to their customers after checkout and to review the answers.
- Business: homedoctor LLC
- Mailing address: 145 E 16th Street, Apt 20D, New York, NY 10003
- Privacy and support contact: phil@homedoctor.pro
This policy explains what data Verba collects from merchants and from merchants' customers, how we use it, who we share it with, how long we keep it, and how to make a request about it.
Our role
For data about a merchant's customers, the merchant decides why and how that data is used, and we process it on the merchant's behalf. Under the EU and UK General Data Protection Regulation (GDPR), the merchant is the controller and we are a processor. Under the California Consumer Privacy Act (CCPA), the merchant is the business and we are a service provider. For data about merchants themselves, such as their store and settings, we are the controller.
Information we collect
From merchants
When a merchant installs and uses Verba, we store:
- Store identity and access. The store's myshopify.com domain, plus the offline access token and granted permissions that Shopify issues at install. We use these to call Shopify's APIs for the store. Verba does not store the name or email address of staff members who sign in.
- Surveys. Survey names, questions, answer choices, conditional logic, audience rules (order value range, new or returning customers, and sample rate), and the thank-you message.
- Settings. An optional Klaviyo private API key, whether Klaviyo sync is turned on, and the time the survey block last appeared on the Thank you page and the Order status page. We show those times on the Setup screen so merchants can tell the survey is live.
- Developer connections. API keys the merchant creates (we store a hashed copy, never the full key), webhook endpoint URLs with their signing secrets, and apps the merchant connects to Verba, such as Claude. For a connected app we store its name, the permissions granted, the Shopify staff user ID of the person who approved it, and hashed access tokens.
- Content created with AI features. When a merchant uses Content Studio, Demand Lab, or Recovery, we store the merchant's prompt and the output. Output includes blog post ideas and drafts, product ideas with sample customer quotes as evidence, and win-back email drafts. A win-back draft includes the customer's score, their written answer, the survey name, and their email address if one is on the response.
- Chat. We store a monthly count of chat messages for each store, but not the conversation itself. Surveys the merchant creates or edits through chat are saved like any other survey.
From merchants' customers, through the checkout survey
Verba shows a survey block on the merchant's Thank you page and Order status page. When a survey is shown and answered, we store:
- Answers. What the customer types or selects, including any text entered for an "Other" choice.
- Order details. The Shopify order identifier. On the Thank you page this is the order identifier from Shopify's order confirmation. On the Order status page it is the order ID and the order name (for example, #1001). We also store the order total and currency.
- Email address. The email address the customer used for the order, which Shopify provides to the survey block. We save it only when the customer submits a survey. If the customer doesn't answer, no email address is stored.
- First order flag. Whether this was the customer's first order with the store (Thank you page only).
- Response status and timestamps. Each time a survey is shown, we create a response record marked as not yet answered, even if the customer never answers. The record is marked completed when the customer submits. We store when the record was created and when it was completed.
Verba does not ask customers for their name, address, or phone number. Email questions are not offered on checkout pages.
How we use information
We use the data above only to run Verba for the merchant:
- Pick which survey to show for an order, based on the merchant's audience rules.
- Save the customer's answers against the order.
- Show the merchant results for each question, NPS scores, and the order revenue linked to each answer.
- Let the merchant download a survey's responses as a CSV file from the admin.
- Send completed survey answers, with the customer's email address, to the merchant's own Klaviyo account, if the merchant connects it (see below).
- Send completed responses to webhook URLs the merchant sets up, and return survey data to API keys and connected apps the merchant has authorized.
- Run the AI features when the merchant asks for them (see below).
- When the merchant chooses, create a hidden blog post or a draft product in the merchant's Shopify store. AI-written blog posts are created hidden so the merchant can review them before customers see them. Product ideas are created as draft products.
- Handle data access and deletion requests from Shopify.
We do not sell personal data. We do not use survey data to advertise to customers.
Third parties that receive data
Shopify
Verba runs on Shopify. Shopify provides the checkout pages where the survey appears, the APIs the app uses, and the webhooks that tell us about uninstalls and data requests. Shopify's own privacy policy covers how Shopify handles data.
Anthropic (Claude API)
Chat, Content Studio, Demand Lab, and Recovery use Anthropic's Claude API. Data goes to Anthropic only when a merchant uses one of these features.
- Chat. We send the merchant's messages and the survey data the assistant looks up to answer them. This can include survey settings, results, and response answers. It does not include customer email addresses.
- Content Studio and Demand Lab. We send the store name (taken from the myshopify.com domain) and the merchant's prompt. If the merchant picks a survey, we also send a text summary of its responses. The summary includes the number of responses, the share and count for each answer choice, NPS scores and numeric averages, up to 12 text answers per text question, and up to 8 "Other" answers per choice question. Each text excerpt is cut to 200 characters.
- Recovery. For each response with a low score (NPS from 0 to 6, or a star rating of 2 or lower), we send the store name, the score, the survey name, and the customer's first text answer on that response. We do not send the customer's email address to Anthropic.
Anthropic states that it does not use inputs or outputs from its commercial API to train its models. Anthropic's commercial terms govern how long it keeps that data.
Klaviyo (only if the merchant connects it)
A merchant can connect their own Klaviyo account by entering a Klaviyo private API key. If Klaviyo sync is turned on:
- When a customer completes a survey, we send Klaviyo an "Answered Survey" event for the customer's email address. The event includes the survey name, each answer labeled by its question, any "Other" text, the order total, and a response ID. The same answers are saved as properties on the customer's Klaviyo profile.
- When a merchant chooses to push a win-back draft to Klaviyo, we send the score, the customer's text answer, the survey name, and the draft's subject and body, attached to the customer's email address.
Data sent to Klaviyo is held in the merchant's Klaviyo account under the merchant's own agreement with Klaviyo. The merchant is responsible for having the customer's consent to any marketing they send from Klaviyo.
Services the merchant connects
Webhook endpoints, API keys, and connected apps (such as Claude) receive survey data only because the merchant set them up. Data sent to them is handled under the merchant's own arrangements with those services.
Hosting
Verba's servers and database run on Fly.io in the US East region (Ashburn, Virginia, United States). The database is stored on an encrypted Fly.io storage volume.
Retention and deletion
How long we keep data
- Unanswered responses. Response records for surveys that were shown but never answered are deleted after 90 days. The cleanup runs at most once an hour while the app is serving surveys.
- Completed responses. Kept until the merchant deletes the survey, Shopify sends a customer deletion request that matches the response, or the merchant uninstalls the app.
- AI content and drafts. Kept until the merchant deletes or dismisses them, or uninstalls the app.
- Backups. Fly.io takes daily snapshots of the storage volume and keeps each one for 5 days, so deleted data can remain in a snapshot for up to 5 days.
Deletion by the merchant
In the app, merchants can:
- Delete a survey, which also deletes its questions, responses, and answers.
- Delete generated blog drafts.
- Dismiss product ideas and win-back drafts, which deletes them.
- Disconnect Klaviyo, which removes the stored API key.
- Revoke API keys, delete webhook endpoints, and disconnect connected apps.
Blog posts and draft products that Verba created in the merchant's Shopify store stay in that store until the merchant deletes them there.
When a merchant uninstalls
When the app is uninstalled, we delete the store's Shopify access sessions, revoke its API keys and connected apps, and stop sending its webhooks. Shopify sends a shop deletion request (shop/redact) 48 hours after uninstall. When we receive it, we delete all of the store's data in Verba: surveys, questions, responses, answers, content briefs, generated articles, product ideas, win-back drafts, settings (including the Klaviyo key), API keys, webhook endpoints, connected apps, privacy request records, chat usage counts, and sessions.
Customer deletion requests (customers/redact)
When a customer asks a merchant to erase their data, Shopify sends us a customer deletion request (customers/redact). We find the customer's responses in that store by email address, customer ID, or the orders listed in the request. For those responses we:
- Clear the email address, customer ID, order ID, order name, country code, product titles, and customer tags.
- Clear free-text answers and any "Other" text.
- Delete win-back drafts and data request records about the customer.
- Replace exact copies of the customer's written answers, and the 200-character excerpts used in AI summaries, with "[removed]" in stored product ideas, content briefs, and generated articles. An AI model's paraphrase can't be traced back to one customer, so paraphrased wording is not removed.
Choice and score answers stay so the merchant's totals remain accurate, but they are no longer linked to an order or email address. The order total, currency, and first order flag also stay on the response.
This process does not change data already sent to Klaviyo, webhook endpoints, connected apps, content already created in the merchant's Shopify store, or data already sent to Anthropic. Merchants handle copies in those systems.
Shopify requires apps to complete these requests within 30 days of receiving them.
Customer data requests (customers/data_request)
When a customer asks a merchant for a copy of their data, Shopify sends us a customer data request (customers/data_request). The request appears on the Privacy requests page in the merchant's Verba admin, where the merchant can download the survey data Verba holds for that customer and mark the request as sent.
Merchants can also download a survey's responses as a CSV file from the survey's Responses page at any time.
Security
- Verba is only served over HTTPS, so data is encrypted in transit.
- The database is stored on an encrypted storage volume.
- We encrypt Klaviyo private API keys and webhook signing secrets with AES-256-GCM before saving them. After they are saved, they are not shown again in the app.
- API keys and connected app tokens are stored only as one-way hashes.
- The survey block can only read or write survey data for the store whose checkout it runs on, verified with a token signed by Shopify.
Your rights and how to make a request
Merchants
- You can view all survey data in the Verba admin and download it as CSV.
- You can delete surveys and AI content in the app, as described above.
- Uninstalling the app starts deletion of all your store's data.
- For any other request about your data, including access, correction, or deletion, email phil@homedoctor.pro.
Customers of a merchant's store
Answering a survey is optional. Verba still creates an unanswered response record when a survey is shown, as described above.
The merchant you bought from controls the survey data about you. To access, correct, or delete it, contact that merchant. When the merchant makes a request through Shopify, we handle it as described in "Retention and deletion." You can also email phil@homedoctor.pro and we will pass your request to the merchant.
Rights under GDPR and UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to complain to your local data protection authority. Because merchants are the controllers of their customers' survey data, we will help the merchant respond to these requests. Verba's data is stored in the United States, so data about customers outside the United States is transferred there.
Rights under the CCPA
If you are a California resident, you have the right to know what personal information is collected about you, to request that it be deleted or corrected, and not to be discriminated against for using these rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising. As a service provider, we use merchants' customer data only to provide Verba to that merchant.
Changes to this policy
We may update this policy when Verba or our practices change. We will post the new version here and change the "Last updated" date. For significant changes, we will notify merchants by email at their store's contact address and with a notice in the Verba admin.
Governing law
This policy is governed by the laws of the State of Delaware.
Contact
homedoctor LLC 145 E 16th Street, Apt 20D New York, NY 10003 phil@homedoctor.pro