Privacy Policy

BubaFy · Last updated 2026-09-09

BubaFy is an app for Shopify stores. It delivers courses and digital products to people who buy from a merchant's store. This policy explains what data the app handles, why, and for how long.

Who's who

Two people are involved: the merchant, who installs BubaFy on their Shopify store, and the buyer, who purchases a course or digital product from that store.

For buyer data, the merchant is the controller — they decide what to sell and to whom. BubaFy acts as a processor: it handles that data only to deliver what was purchased, following the merchant's instructions.

Buyer data

When Shopify confirms a payment, BubaFy receives from Shopify and stores:

  • The buyer's email and name
  • The Shopify customer and order identifiers, the amount and the currency
  • Which content was granted to them, and when
  • Photos the buyer uploads themselves, when the product has personalized photo pages

What the data is used for

Only to deliver what was purchased: create the access, email the members-area link, and let the buyer open their content.

BubaFy does not sell, rent or share buyer data with third parties, and does not use it for advertising or to train artificial intelligence models.

How buyers sign in

Access is through an emailed link, with no password. The link is valid for 15 minutes and can only be used once. The app stores only a cryptographic hash of the link, never the link itself — a database leak hands out access to no one.

Merchant data

From the merchant, BubaFy stores the store domain, the members-area name and logo, the support email, the language and the plan status.

If the merchant sets up email sending, their provider's API key is stored encrypted and is never displayed back on screen.

What the app accesses on Shopify

BubaFy requests three permissions, and only these: read products, read orders, read customers. Reading products lets the merchant connect a course to one of their store's products; reading orders and customers is how the app knows who bought what and grants access.

The app does not modify products, does not modify orders, does not process payments and does not change the store's theme.

Where the data lives

Data and files are stored on Fly.io servers in the São Paulo, Brazil region, on an encrypted disk. All traffic between the browser and the app is encrypted with HTTPS.

Files that were sold (PDFs, videos, images) are never publicly reachable: every download goes through a signed, short-lived address generated only after the server confirms that this person bought that item.

Third parties

Shopify — the source of order and customer data, and the party handling payment.

Fly.io — app hosting and storage.

Email provider (for example, Resend) — when the merchant sets up sending. The account belongs to the merchant; BubaFy only uses the key they provided to send the access email.

How long it's kept

A buyer's data is kept for as long as the merchant keeps the app installed and that access exists.

When a buyer requests deletion, or when Shopify requests it on their behalf, the app deletes the record, the access grants, the purchases and also any files that person uploaded — not just the database rows.

When a merchant uninstalls the app, Shopify requests the store's deletion and BubaFy deletes all of that store's data and all of its files.

Buyer rights

Buyers may request access to their data, correction, or deletion. The request should go to the store where the purchase was made, as that store decides about this data. BubaFy fulfils such requests through Shopify's official channels as soon as the store forwards them.

Children

BubaFy is not intended for children under 13 and does not knowingly collect data from that age group.

Changes to this policy

If this policy changes in a meaningful way, the update date at the top of this page changes with it.

Contact

Questions about this policy or your data: makemoneywithbuba@gmail.com. If you are a buyer, please contact the store you bought from first.