BubaFy · Last updated 2026-09-09
BubaFy is an app for Shopify stores. It delivers courses and digital products to people who buy from a merchant's store. This policy explains what data the app handles, why, and for how long.
Two people are involved: the merchant, who installs BubaFy on their Shopify store, and the buyer, who purchases a course or digital product from that store.
For buyer data, the merchant is the controller — they decide what to sell and to whom. BubaFy acts as a processor: it handles that data only to deliver what was purchased, following the merchant's instructions.
When Shopify confirms a payment, BubaFy receives from Shopify and stores:
Only to deliver what was purchased: create the access, email the members-area link, and let the buyer open their content.
BubaFy does not sell, rent or share buyer data with third parties, and does not use it for advertising or to train artificial intelligence models.
Access is through an emailed link, with no password. The link is valid for 15 minutes and can only be used once. The app stores only a cryptographic hash of the link, never the link itself — a database leak hands out access to no one.
From the merchant, BubaFy stores the store domain, the members-area name and logo, the support email, the language and the plan status.
If the merchant sets up email sending, their provider's API key is stored encrypted and is never displayed back on screen.
BubaFy requests three permissions, and only these: read products, read orders, read customers. Reading products lets the merchant connect a course to one of their store's products; reading orders and customers is how the app knows who bought what and grants access.
The app does not modify products, does not modify orders, does not process payments and does not change the store's theme.
Data and files are stored on Fly.io servers in the São Paulo, Brazil region, on an encrypted disk. All traffic between the browser and the app is encrypted with HTTPS.
Files that were sold (PDFs, videos, images) are never publicly reachable: every download goes through a signed, short-lived address generated only after the server confirms that this person bought that item.
Shopify — the source of order and customer data, and the party handling payment.
Fly.io — app hosting and storage.
Email provider (for example, Resend) — when the merchant sets up sending. The account belongs to the merchant; BubaFy only uses the key they provided to send the access email.
A buyer's data is kept for as long as the merchant keeps the app installed and that access exists.
When a buyer requests deletion, or when Shopify requests it on their behalf, the app deletes the record, the access grants, the purchases and also any files that person uploaded — not just the database rows.
When a merchant uninstalls the app, Shopify requests the store's deletion and BubaFy deletes all of that store's data and all of its files.
Buyers may request access to their data, correction, or deletion. The request should go to the store where the purchase was made, as that store decides about this data. BubaFy fulfils such requests through Shopify's official channels as soon as the store forwards them.
BubaFy is not intended for children under 13 and does not knowingly collect data from that age group.
If this policy changes in a meaningful way, the update date at the top of this page changes with it.
Questions about this policy or your data: makemoneywithbuba@gmail.com. If you are a buyer, please contact the store you bought from first.