Legal
Privacy and data protection
Last updated 27 July 2026. Glow is operated by Intirn LLC. Contact: davis@team8.co
Who this is for
This covers anyone with a Glow account: people making videos of the products they sell, and people running a store who use Glow to sell from it. They are the same kind of account, and often the same person. Connecting a Shopify store means agreeing to the data-processing terms on this page. It also covers the shoppers who watch those videos, in the section below.
What we collect from a connected store
When a merchant connects a Shopify store, Glow receives:
- Order records: order number, order value, currency, order status, and the first page of the session that led to the order.
- Product catalogue: product titles, images, prices and links.
- Checkout events: whether a checkout was started.
We do not store customer names, email addresses, phone numbers, shipping or billing addresses, or payment details. Shopify sends some of these inside order webhooks; Glow reads what it needs and writes only the fields listed above to its database.
What we collect from viewers
When someone clicks a product in a Glow video we record the click: which video and product, the moment in the video, an anonymous session identifier, the page the embed was on, and coarse device type. This is how a creator learns which videos sell. We do not build advertising profiles and we do not sell data.
Why we process it
- Attribution: match a completed order to the video that drove it.
- Analytics: show creators and merchants what their videos did.
- Billing: calculate the commission owed on an attributed sale.
We do not use merchant or customer data to train or fine-tune machine-learning models. That is also a requirement of the Shopify Partner Program Agreement and we hold to it.
How long we keep it
| Order and commission records | 7 years, as financial records for tax, accounting and dispute resolution |
| Click and view events | 25 months from the event |
| Product catalogue | Until the store is disconnected |
| Shopify access token and webhook signing secret | Deleted immediately when a store is disconnected or the app is uninstalled |
| Shopify privacy request log | 7 years, as the record that we received a request and what we did about it |
When a merchant uninstalls Glow, we delete their access token and product catalogue. We keep order and commission records for the period above because they are the accounting record of money owed and paid; those records contain no customer names, addresses or contact details.
Uninstalling Glow from Shopify admin now triggers that cleanup automatically. We do not wait for anyone to ask. Where Shopify sends us a store erasure request we go further: the product catalogue, the access token, the webhook signing secret and the billing ledgers are deleted outright, the store's name and domains are blanked, and the remaining commission record is pseudonymised so it no longer identifies the store. What survives is an amount, a currency, a date and a status, which is the accounting entry and nothing more.
Security
- All traffic is served over HTTPS.
- Data is encrypted at rest by our database provider.
- Shopify access tokens and the per-store webhook signing secrets are additionally encrypted with AES-256-GCM. The encryption key is held outside the database, so a copy of the database on its own does not open them.
- Every connected store is bound to exactly one Glow account. One account cannot read another account's store data.
Your rights and how to exercise them
Merchants can disconnect at any time from Shopify admin under Settings, then Apps. To request a copy of the data we hold, or its deletion, email davis@team8.co and we will respond within 30 days. Shoppers should contact the merchant they bought from; we will act on any request a merchant passes to us.
Shopify's three privacy webhooks are answered automatically, without a person in the loop: a customer data request, a customer erasure request, and a store erasure request. Our order, click, catalogue and billing records hold no customer names, addresses, contact details or Shopify customer ids, so there is no customer profile in them to hand over or delete. On a customer erasure request we still remove the one shopper-derived field those records can contain, the first page of the shopping session, for the orders named in the request.
One honest exception. When Shopify sends us a privacy request we log the request itself, which is Shopify's message including the customer id and any contact details Shopify put in it, as the record that we received it and what we did. That log is kept for seven years and is not reachable from any other part of the product.
Sub-processors
Glow uses third-party providers for hosting, database, media storage and video processing. A current list of sub-processors is available on request at davis@team8.co. Shopify is the source of merchant order data. We do not sell data and we do not share it with advertisers.
Changes
If we change this policy in a way that affects how merchant or customer data is handled, connected merchants are notified by email before it takes effect.