Privacy Policy

Last Updated: August 6, 2025

Grid ImageGrid Image

This Privacy Policy explains how HS Software Solutions LLC (“we,” “our,” or “us”) collects, uses, and protects personal data when you use the Reflow Auctions app and related services. We comply with applicable privacy laws, including the General Data Protection Regulation (GDPR) for users in the European Union/EEA and the California Privacy Rights Act (CPRA) for California residents.

Information We Collect

We may collect the following types of personal data:

Name and Contact Details (such as name, email address, location).

Payment Information (such as billing details, payment card information).

Account Information (login details, preferences).

Technical Information (IP address, browser type, device information).

Usage Data (bidding activity, auction history, notifications).

We do not collect sensitive personal data such as health or biometric information.

How We Collect Data

We collect personal data:

Directly from you when you fill out forms, contact us, or interact with our app.

Automatically, through cookies and similar technologies, for analytics and service improvements.

From merchants and merchants’ customers collected through the Shopify API, when necessary to provide auction services.

How We Use Data

We use your personal data to:

Provide and manage auction services, including bidding functionality, order creation, and notifications.

Process payments and manage billing.

Send service-related communications.

Improve and optimize our services.

Conduct our own marketing on platforms like Facebook or Google (unless the data was collected through the Shopify API).

Comply with legal obligations.

Data Sharing

We may share your personal data with:

Service providers such as payment processors, cloud hosting services, notification services, and marketing platforms.

Law enforcement or courts when required by law.

Shopify, in accordance with Shopify’s terms and API requirements.

International Data Transfers

Our data centers are primarily located in the United States, but data may be stored in other countries for redundancy and speed optimization.

When transferring data outside the EU/EEA, we use legal safeguards such as Standard Contractual Clauses where applicable.

Data Security

All data is encrypted in transit.

Protected customer data collected via Shopify APIs is encrypted at rest.

We maintain internal security policies to limit access to personal data.

Data Retention

Data collected through Shopify API: Retained only as long as necessary to provide auction services and for billing and financial purposes.

Other collected data: Retained until we receive a deletion request or as required by law.

Notifications of Changes or Breaches

We will notify merchants of Privacy Policy updates via their Shopify store email.

In the event of a security breach, we will notify Shopify merchants within 72 hours of discovery.

Your Rights Under GDPR (EU/EEA Users)

If you are located in the EU/EEA, you have the following rights under GDPR:

Right to Access: Request a copy of your personal data.

Right to Rectification: Request correction of inaccurate data.

Right to Erasure: Request deletion of your personal data.

Right to Restrict Processing: Request limits on how we use your data.

Right to Data Portability: Receive your data in a portable format.

Right to Object: Object to certain uses of your data, such as marketing.

How to exercise your rights:

Customers of Shopify Merchants can request their data from the Shopify Merchant they placed a bid with. Shopify Merchants can submit requests to us via the Shopify Admin data request process.

We will not discriminate against you for exercising your privacy rights.

Your Rights Under CPRA (California Users)

If you are a California resident, you have the following rights under CPRA:

Right to Know: Learn what personal data we collect, use, and share.

Right to Delete: Request deletion of personal data we hold about you.

Right to Correct: Request corrections to inaccurate personal data.

Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of your personal data.

Right to Limit Use of Sensitive Data: Restrict use of sensitive personal data (not applicable here as we do not collect sensitive data).

How to exercise your rights:

Customers of Shopify Merchants can request their data from the Shopify Merchant they placed a bid with. Shopify Merchants can submit requests to us via the Shopify Admin data request process.

We will not discriminate against you for exercising your privacy rights.

Contact Us

If you have questions or requests regarding this Privacy Policy or our data practices, please contact us here: https://www.reflowauctions.com/contact