Sparkflow
ENDE

Privacy Policy

Sparkflow: Advent Calendar & Countdown — app for Shopify

Last updated: 04 September 2026

Sparkflow is an app for Shopify stores. Merchants use it to build advent calendars and countdown timers that run inside their own theme, and to have discount codes created automatically for individual doors.

This policy covers two different things: what happens when you visit this page, and what the app processes inside a merchant's store. The data protection roles are not the same in both cases.

1. Who is responsible for what

For this page, the provider named below is the controller within the meaning of Art. 4(7) GDPR.

For the data the app processes inside a merchant's store, the merchant is the controller. They decide whether to use Sparkflow, what content goes into the doors and which discounts are granted. We act as a processor under Art. 28 GDPR and solely on their instructions. The agreement covering this is the Data Processing Agreement.

If you shopped in a store that uses Sparkflow, contact that store first. They are the controller. We may not release their customers' data on our own initiative.

2. Provider

David Diallo, handelnd unter „Diallo Media“

Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland

Represented by: David Diallo (Inhaber)

Commercial register: nicht im Handelsregister eingetragen (Einzelunternehmen)

VAT identification number: DE366538188

Email: daviddiallo@web.de

No data protection officer has been appointed; the statutory thresholds are not met. Privacy enquiries go to the address above.

3. When you visit this page

This page sets no cookie of its own and stores nothing in your browser. There is no analytics tool, no ad network and no tracking pixel.

It does load two files from Shopify's servers: the Inter typeface and the App Bridge library, both from `cdn.shopify.com`. They are loaded because the same base document also carries the app inside the Shopify admin. In doing so, Shopify learns your IP address, the time and the file requested. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in serving one consistent application.

The application runs on Railway (see section 9). When you request a page, the host processes technically necessary connection data such as IP address, time, requested address and browser identifier. Server location: Railway-Region us-west2 (US West Metal), Kalifornien, USA. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure operation.

The language switch in the top right works without a cookie: it only appends `?lang=de` or `?lang=en` to the address.

4. What the app stores

Complete list. Anything not listed here is not stored.

RecordContentsPurpose
StoreThe store's myshopify domain, plan, expiry date of a Season Pass, a “branding removed” flag, time zone, creation and last change timestampsMapping the configuration to the right store, checking the plan, unlocking doors correctly in local time
SessionStore domain, Shopify access token, granted scopes, expiryCalling the Shopify Admin API on the merchant's behalf. The schema also has fields for a Shopify staff member's name and email; Sparkflow uses offline access tokens, so those fields stay empty.
CalendarName, handle, number of doors, start date, and the door configuration: heading, text, discount code, link, button label, image addresses, optional custom HTML and CSSRendering the calendar in the merchant's theme
CountdownName, handle, target date, heading, subtitle, finished text, button label and targetRendering the countdown in the merchant's theme
Generated discountCalendar handle, door number, discount code, Shopify discount id, percentage, day of validityCreating discount codes automatically and avoiding duplicates
Door clickCalendar handle, door number, anonymous session id, timestampReporting which doors were opened (paid plans only, see section 5)
Integration keysOptionally a Klaviyo and a Mailchimp API key entered by the merchantPreparation for future integrations. See section 10 — no transmission takes place at present.
  • No customer names, no email addresses, no postal addresses, no phone numbers.
  • No order data, no cart contents, no purchased products.
  • No payment or card data. Plan billing runs entirely through Shopify; we see neither bank details nor card numbers.
  • No link to Shopify customer accounts. There is no field for a Shopify customer id anywhere in the database.
  • No sharing with ad networks, no sale of data, no profiling for advertising.
  • No training of AI models on this data.

5. Click tracking in the store

When a visitor opens a door, the calendar reports it to our `/api/track` endpoint. Exactly four values are transmitted: the store's myshopify domain, the calendar handle, the door number and a session id.

The session id is a random value, not a person. It is generated in the visitor's browser (timestamp plus a random part) and kept there under the key `sf_session_id` in local storage. It contains no name, no email address and no Shopify customer id. Because local storage is bound to the domain, each store produces its own id — matching across store boundaries is technically impossible, not merely forbidden.

The IP address is read but not stored. It is used solely for rate limiting (at most 60 reports per minute), which runs in memory and disappears on restart. No IP address ever reaches the database.

On the Free plan nothing is recorded at all. The endpoint accepts the report and discards it without storing. Opening the same door repeatedly in the same session is counted only once per hour.

The purpose is performance reporting for the merchant: they see how often each door was opened. The legal basis is Art. 6(1)(f) GDPR together with the merchant's instruction; storing the id in local storage is additionally governed by § 25 TDDDG. Whether consent must be obtained for this is decided and answered for by the merchant as the operator of the store.

6. Cookies and browser storage

Complete list across all parts of the app:

NameKind, wherePurposeLifetime
sf_session_idLocal storage, in the merchant's storeRandom session id for click reporting. Created only when a door is actually opened, and only on paid plansuntil the visitor clears it
sf-langCookie, admin interfaceInterface language chosen by the merchant. Contains only “de” or “en”1 year
Shopify session cookiesCookie, admin interfaceSet by Shopify's authentication library during installation and sign-in. They are strictly necessary; without them the app cannot be installedsession

7. What the app writes into Shopify

A calendar's configuration has to reach the merchant's theme. It is therefore stored with Shopify as a shop metafield in the `sparkflow` namespace: one field per calendar and per countdown, plus the current plan and the address of the tracking endpoint.

These fields contain nothing but the texts, links and image addresses entered by the merchant. No personal data of store visitors is held in them.

Discount codes are created on the merchant's request through the Shopify Admin API (`discountCodeBasicCreate`), with the chosen percentage and a validity of exactly one day. We store the code, the Shopify discount id, the percentage and the day of validity — not who redeemed it.

8. Requested scopes

Sparkflow requests the following Shopify scopes on installation. The `read_orders` scope was removed on 4 September 2026 — the app no longer reads orders and does not need them.

ScopeUsed for
read_filesPicking existing images from the store's media library for the doors. The images stay with Shopify; only their address is stored.
write_discountsCreating the per-door discount codes automatically.
write_contentStoring calendar and countdown configuration as a shop metafield in the `sparkflow` namespace.
read_themes, write_themesOperating the theme app extension inside the merchant's theme. The app performs no write access to theme files of its own at present.
write_productsCurrently unused — there is no access to product data anywhere in the code. This scope will be reviewed at the next revision of the requested permissions.

9. Recipients and sub-processors

Data goes only to the service providers without which the app cannot run. The required processing agreements are in place with all of them; the full list with roles and third-country safeguards is in the Data Processing Agreement.

The application and its database run in the United States, in Railway region us-west2 (California). That is a transfer to a third country without an adequacy decision. The safeguard under Art. 46(2)(c) GDPR is the European Commission's Standard Contractual Clauses, which Railway's data processing agreement incorporates. A copy is available at railway.com/legal/dpa.

  • Shopify (Shopify Inc., Canada) — operator of the store platform. Store domain and access token come from there; metafields and discount codes go there. Canada is covered by an adequacy decision of the European Commission.
  • Railway (Railway Corp., USA) — operation of the application. Server location: Railway-Region us-west2 (US West Metal), Kalifornien, USA.
  • Database — PostgreSQL. Provider and server location: Railway Corporation, verwaltetes PostgreSQL im selben Projekt, Region us-west2, Kalifornien, USA.
  • There are no other recipients. No analytics service, no error reporting service, no newsletter sender, no ad network.

10. Klaviyo and Mailchimp

In the settings, merchants on a Pro plan can store a Klaviyo and a Mailchimp API key. These keys are stored but currently not used.

No data is transmitted to Klaviyo or Mailchimp. The app never calls these services, captures no email addresses in the calendar and synchronises no recipient lists. This policy will be updated before that changes.

A merchant can clear the key in the settings at any time. Switching to a plan without integrations clears both fields automatically.

11. Retention

Deletion is not a promise on paper but a procedure: on the `app/uninstalled` signal, sessions and the store record are removed; the database deletes calendars, countdowns, clicks and discount records along with them through foreign-key cascades. The `shop/redact` signal runs the same pass a second time in case the first never arrived.

DataPeriod
Store, calendar and countdown configurationas long as the app is installed
Door clicksas long as the app is installed
Generated discount codes (our record)as long as the app is installed. The discount itself lives at Shopify and is managed there by the merchant
Access tokens and sessionsuntil uninstall or until the token expires
All data of a storedeleted on uninstall (`app/uninstalled`) and a second time on Shopify's store deletion signal (`shop/redact`)
Session id in the visitor's browseruntil the visitor clears their browser's local storage
IP addressesnot at all — they are used transiently for rate limiting only

12. Requests from a store's customers

Shopify prescribes three mandatory privacy signals. All three are implemented:

  • `customers/data_request` — a customer's access request. Sparkflow stores no personal customer data; there is nothing to hand out. The request is logged and acknowledged.
  • `customers/redact` — a customer's erasure request. There are no person-linked records to erase. The anonymous session ids cannot be attributed to a customer.
  • `shop/redact` — deletion of all of a store's data, 48 hours after uninstall. Every record of that store is permanently removed.

13. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Consent you have given can be withdrawn at any time with effect for the future.

You may also lodge a complaint with a supervisory authority. The authority responsible for us is: Die Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen. You are free to contact any supervisory authority.

If you are a customer of a store that uses Sparkflow, contact that store first. They are the controller and will initiate deletion through Shopify; we then carry it out.

14. Changes to this policy

If what the app processes changes, this policy is updated beforehand and the date above is changed. Material changes are additionally announced to merchants inside the app.

Contact

Send privacy questions, access and erasure requests to:

David Diallo, handelnd unter „Diallo Media“
Schwachhauser Heerstraße 18, 28209 Bremen, Deutschland
daviddiallo@web.de
HomeTerms of ServiceData Processing AgreementLegal notice