Legal
RealFeed Privacy Policy
Last updated: September 2, 2026
This Privacy Policy applies specifically to the RealFeed Shopify app published by VirtueNest (“we”, “us”, “our”). It describes the information RealFeed processes from a merchant’s Shopify store, why it processes that information, and what RealFeed does not collect. It is separate from, and does not replace, the general VirtueNest Privacy Policy, which covers our website and our other products.
1. About RealFeed
RealFeed is a Shopify app that helps merchants display recent store activity and social-proof messages on their storefront — for example, a notification that a product was recently purchased. To do this, RealFeed reads a limited set of order and product information from the merchant’s Shopify store through Shopify’s APIs and webhooks, and uses it to generate short activity messages for storefront visitors.
RealFeed requests the Shopify access scopes read_orders and read_products. It does not request write access to store data.
2. Information RealFeed Processes
RealFeed follows data-minimization principles: it processes only the information needed to provide its social-proof functionality. For each applicable order or line item, RealFeed may process:
| Information processed | Purpose for processing |
|---|---|
| Shopify order identifier | Internal reference for an activity record, so the same order is not turned into duplicate storefront messages. |
| Order creation time | Determines whether activity is recent enough to display, and drives record expiry. |
| Product ID, handle and title | Identifies the product an activity message refers to and links it to the correct storefront page. |
| Item quantity | Describes the activity accurately in the storefront message. |
| City | Provides coarse location context in an activity message, where a message is permitted. |
| Province / state code | Coarse location context, used as an alternative to city. |
| Country code | Coarse location context, and the broadest fallback when a narrower location is not appropriate. |
The city, province/state and country values originate from the shipping-address data associated with an order. RealFeed reads only those coarse location fields and does not retain the rest of the address.
RealFeed also processes ordinary operational information needed to run a Shopify app, such as the store’s myshopify domain and app configuration settings chosen by the merchant, together with server logs generated when the app is used.
3. Information RealFeed Does Not Intentionally Collect
RealFeed does not intentionally request, process or store the following:
- Customer first or last name
- Customer email address
- Customer phone number
- Shopify customer ID
- Street address / address line 1
- Address line 2
- Postal / ZIP code
- Latitude
- Longitude
Because RealFeed stores a Shopify order identifier alongside each activity record, we do not describe that stored data as fully anonymous. The order identifier is used internally only, and direct customer-identifying information is not displayed to storefront shoppers.
4. How We Use the Information
RealFeed uses the information described above only to:
- create storefront activity and social-proof messages for the merchant’s store;
- determine an appropriate coarse location (city, province/state or country) for those messages;
- prevent the same order from producing duplicate activity messages;
- operate, maintain and support the RealFeed app;
- maintain security, investigate and troubleshoot problems, and meet legal and Shopify platform compliance requirements.
RealFeed does not use Shopify customer or order information for unrelated advertising, cross-store tracking, or customer profiling.
5. Storefront Display
On a merchant’s storefront, RealFeed may display short messages about recent product activity, and may include a coarse location such as a city, province/state or country where appropriate.
RealFeed does not display customer names, email addresses, phone numbers, street addresses, Shopify customer IDs, order identifiers, postal/ZIP codes, or geographic coordinates to storefront shoppers.
Where RealFeed’s privacy and activity thresholds do not permit an appropriate message, coarse-location detail may be broadened or the activity may be suppressed entirely rather than displayed.
6. Data Retention
RealFeed activity records carry an expiry time and are removed once it passes. The default retention period is 90 days. A merchant-configured retention period cannot exceed the maximum retention period supported by the application.
Records are removed on expiry, or earlier in response to a Shopify redaction request as described below. We do not claim immediate deletion of every record at the moment activity occurs.
7. Shopify Privacy and Deletion Requests
RealFeed implements Shopify’s mandatory privacy and compliance webhooks:
- customers/redact — RealFeed removes stored activity records associated with the order identifiers that Shopify submits for redaction.
- shop/redact — RealFeed removes data associated with the shop, other than records that must legitimately be retained as compliance evidence where applicable.
- customers/data_request — RealFeed supports Shopify’s customer data-request process and responds to requests forwarded through it.
Merchants and customers may also contact us directly using the details in Section 13.
8. Customer Privacy and Consent
Where Shopify’s Customer Privacy API indicates that consent is required for the applicable storefront functionality, RealFeed respects the privacy decision recorded for that visitor and the privacy configuration chosen by the merchant. Merchants remain responsible for configuring their store’s privacy and consent settings in line with the laws that apply to their customers.
9. Data Sharing and Sale
RealFeed does not sell customer personal information. We do not share Shopify order or product information with third parties for their own marketing or advertising purposes.
We use a small number of service providers (sub-processors) that process information only as necessary to operate RealFeed on our behalf, and only under our instructions:
- Shopify — the platform the app runs on and the source of the order and product information described in Section 2.
- MongoDB Atlas — managed database hosting for RealFeed activity records and app configuration.
- Our cloud hosting and infrastructure provider — hosting for the RealFeed application servers.
10. Data Security
We use technical and organizational safeguards designed to protect the information RealFeed processes, including encrypted HTTPS connections for data in transit, access controls that limit who can reach production systems, and verification of incoming Shopify webhook requests.
No method of transmission or storage is completely secure, and we do not claim that every relevant storage system is encrypted at rest. We hold no security or privacy certification, and we make no claim of SOC 2, ISO 27001, HIPAA or GDPR certification.
11. Merchant Responsibilities
Shopify merchants are responsible for operating their own stores, including deciding to install and configure RealFeed, and for providing any privacy notices and obtaining any consents required under the laws applicable to their customers. Merchants act as the controller of their customers’ personal information; VirtueNest processes that information on the merchant’s behalf in order to provide RealFeed.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time — for example, if RealFeed’s functionality changes or to reflect legal or platform requirements. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be reflected here before they take effect.
13. Contact Us
For questions about this Privacy Policy, or to make a privacy request relating to RealFeed, contact us at support@virtuenest.com.
RealFeed is published by VirtueNest — https://virtuenest.com.