Privacy Policy for Verba - Post-Purchase Surveys

Effective date: September 14, 2026 Last updated: September 14, 2026

Who we are

Verba - Post-Purchase Surveys ("Verba" or "the app") is a Shopify app made by homedoctor LLC ("we", "us", "our"). Merchants install Verba to show surveys to their customers after checkout and to review the answers.

This policy explains what data Verba collects from merchants and from merchants' customers, how we use it, who we share it with, how long we keep it, and how to make a request about it.

Our role

For data about a merchant's customers, the merchant decides why and how that data is used, and we process it on the merchant's behalf. Under the EU and UK General Data Protection Regulation (GDPR), the merchant is the controller and we are a processor. Under the California Consumer Privacy Act (CCPA), the merchant is the business and we are a service provider. For data about merchants themselves, such as their store and settings, we are the controller.

Information we collect

From merchants

When a merchant installs and uses Verba, we store:

From merchants' customers, through the checkout survey

Verba shows a survey block on the merchant's Thank you page and Order status page. When a survey is shown and answered, we store:

Verba does not ask customers for their name, address, or phone number. Email questions are not offered on checkout pages.

How we use information

We use the data above only to run Verba for the merchant:

We do not sell personal data. We do not use survey data to advertise to customers.

Third parties that receive data

Shopify

Verba runs on Shopify. Shopify provides the checkout pages where the survey appears, the APIs the app uses, and the webhooks that tell us about uninstalls and data requests. Shopify's own privacy policy covers how Shopify handles data.

Anthropic (Claude API)

Chat, Content Studio, Demand Lab, and Recovery use Anthropic's Claude API. Data goes to Anthropic only when a merchant uses one of these features.

Anthropic states that it does not use inputs or outputs from its commercial API to train its models. Anthropic's commercial terms govern how long it keeps that data.

Klaviyo (only if the merchant connects it)

A merchant can connect their own Klaviyo account by entering a Klaviyo private API key. If Klaviyo sync is turned on:

Data sent to Klaviyo is held in the merchant's Klaviyo account under the merchant's own agreement with Klaviyo. The merchant is responsible for having the customer's consent to any marketing they send from Klaviyo.

Services the merchant connects

Webhook endpoints, API keys, and connected apps (such as Claude) receive survey data only because the merchant set them up. Data sent to them is handled under the merchant's own arrangements with those services.

Hosting

Verba's servers and database run on Fly.io in the US East region (Ashburn, Virginia, United States). The database is stored on an encrypted Fly.io storage volume.

Retention and deletion

How long we keep data

Deletion by the merchant

In the app, merchants can:

Blog posts and draft products that Verba created in the merchant's Shopify store stay in that store until the merchant deletes them there.

When a merchant uninstalls

When the app is uninstalled, we delete the store's Shopify access sessions, revoke its API keys and connected apps, and stop sending its webhooks. Shopify sends a shop deletion request (shop/redact) 48 hours after uninstall. When we receive it, we delete all of the store's data in Verba: surveys, questions, responses, answers, content briefs, generated articles, product ideas, win-back drafts, settings (including the Klaviyo key), API keys, webhook endpoints, connected apps, privacy request records, chat usage counts, and sessions.

Customer deletion requests (customers/redact)

When a customer asks a merchant to erase their data, Shopify sends us a customer deletion request (customers/redact). We find the customer's responses in that store by email address, customer ID, or the orders listed in the request. For those responses we:

Choice and score answers stay so the merchant's totals remain accurate, but they are no longer linked to an order or email address. The order total, currency, and first order flag also stay on the response.

This process does not change data already sent to Klaviyo, webhook endpoints, connected apps, content already created in the merchant's Shopify store, or data already sent to Anthropic. Merchants handle copies in those systems.

Shopify requires apps to complete these requests within 30 days of receiving them.

Customer data requests (customers/data_request)

When a customer asks a merchant for a copy of their data, Shopify sends us a customer data request (customers/data_request). The request appears on the Privacy requests page in the merchant's Verba admin, where the merchant can download the survey data Verba holds for that customer and mark the request as sent.

Merchants can also download a survey's responses as a CSV file from the survey's Responses page at any time.

Security

Your rights and how to make a request

Merchants

Customers of a merchant's store

Answering a survey is optional. Verba still creates an unanswered response record when a survey is shown, as described above.

The merchant you bought from controls the survey data about you. To access, correct, or delete it, contact that merchant. When the merchant makes a request through Shopify, we handle it as described in "Retention and deletion." You can also email phil@homedoctor.pro and we will pass your request to the merchant.

Rights under GDPR and UK GDPR

If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to its processing, and to complain to your local data protection authority. Because merchants are the controllers of their customers' survey data, we will help the merchant respond to these requests. Verba's data is stored in the United States, so data about customers outside the United States is transferred there.

Rights under the CCPA

If you are a California resident, you have the right to know what personal information is collected about you, to request that it be deleted or corrected, and not to be discriminated against for using these rights. We do not sell personal information, and we do not share it for cross-context behavioral advertising. As a service provider, we use merchants' customer data only to provide Verba to that merchant.

Changes to this policy

We may update this policy when Verba or our practices change. We will post the new version here and change the "Last updated" date. For significant changes, we will notify merchants by email at their store's contact address and with a notice in the Verba admin.

Governing law

This policy is governed by the laws of the State of Delaware.

Contact

homedoctor LLC 145 E 16th Street, Apt 20D New York, NY 10003 phil@homedoctor.pro