Skip to content
Kelby

Privacy Policy

Last reviewed August 2, 2026

Kelby is a loyalty and rewards app for Shopify. It stores the least data a loyalty program needs, which is a customer ID, a points balance, and the ledger behind it. This policy explains what that means for merchants who install Kelby and for their customers.

Kelby is operated by Samy Arezki, an individual (sole proprietor) based in Quebec, Canada, trading as “Kelby”, and governed by the laws of Quebec and Canada. If the operator later incorporates, the registered entity name and address will be updated here.

The short version

  • Kelby stores a Shopify customer ID, a points balance, a points transaction ledger, a VIP tier, and a referral code. This is the data a loyalty program is made of.
  • Kelby never stores payment data. It does not keep customer names or email addresses, and reads those live from Shopify when it needs them for display.
  • The merchant controls their customers’ data. Kelby processes it on the merchant’s instructions.
  • Uninstalling Kelby removes the shop’s data. Individual customers can be erased on request.

Data Kelby stores

To run a points program, Kelby keeps the following for each customer who takes part:

  • the Shopify customer identifier, used to attribute points;
  • the current points balance, which is a running total of the ledger;
  • a points transaction ledger, the record of every accrual, redemption, adjustment, and migration entry;
  • the customer’s VIP tier status and referral code;
  • the program settings you configure, such as earning rules, rewards, and tiers.

Kelby processes Protected Customer Data under Shopify’s requirements (Levels 1 and 2). It requests only the access it needs: reading customers, orders, and products, and writing discounts for redemption.

Data Kelby does not store

  • Payment or card data. Kelby never accesses it and never stores it.
  • Customer names and email addresses. Kelby reads these live from the Shopify API for display, such as showing a member list, and does not keep them in its database. The one exception is a migration file in progress, which can hold emails while they are being matched and is deleted when the import finishes.

How data is used

Data is used to run the loyalty program you configure. That means awarding and redeeming points, applying VIP tiers, attributing referrals, sending the emails you turn on, and showing you analytics about your own program. Kelby does not sell data and does not use it for advertising.

Subprocessors

Kelby relies on a small set of providers, each handling data only to run the service:

  • Shopify. The platform Kelby runs on and the source of customer, order, and product data. It also processes billing.
  • Fly.io. Application hosting and the database, in a US region.
  • Resend. Delivery of the transactional and lifecycle emails you turn on.
  • Sentry. Error monitoring, which keeps the app reliable.

Data retention and deletion

Kelby keeps program data while the app is installed. It implements Shopify’s privacy webhooks:

  • customers/redact. Deletes a specific customer’s member record and ledger.
  • shop/redact. Removes all of a shop’s data after the app is uninstalled.
  • customers/data_request. Compiles a customer’s stored data for a data-access request.

Your rights

Depending on where you and your customers live, such as under the GDPR or the CCPA, data subjects may have rights to access, correct, or delete their data. As a merchant, you can trigger a customer erasure or data request through Shopify, and Kelby honours it automatically through the webhooks above. Customers should send requests to the store they shopped with, which can action them.

This website

This marketing site (kelbyloyalty.com) is a static site. It sets no advertising cookies and does not sell visitor data. If privacy-friendly analytics are added later, this section will name the provider.

Contact

For questions about privacy or a data request, email hello@kelbyloyalty.com.