SECURITY AND PRIVACY
See what Atomato accesses
and what it keeps
Check the Shopify permissions Atomato asks for, the shopper activity it records and what it deletes, before you install or answer a reviewer. The answers below link to the help articles with the full detail.
Describes how the app works today. This page isn't legal advice.
HOW IT WORKS
Your store's data, from install to uninstall
What Atomato sets up, records and deletes at each stage, and where Shopify makes the call.
WHAT IT TOUCHES
Six areas to check before you install
Your store, your shoppers' browsers, signups, API keys and the services Atomato relies on. Each row sums up how the app works today and links to the full detail.
-
Shopify permissions
The access scopes Atomato requests at install, such as read_orders to report NotiSell orders and write_themes so Theme Launcher can publish the theme you pick. Atomato uses your store's access, not each staff member's Shopify permissions.
26 access scopesSee every scope -
Shopper privacy choices
Atomato's pixel declares analytics, marketing and sale of data to Shopify, and Shopify decides when it runs. The script that shows messages doesn't check those choices.
Shopify decides when the pixel runsHow consent works -
Browser storage
Atomato's scripts keep notes in local and session storage, such as which messages a shopper has seen, and don't write cookies themselves. A signup that offers a discount keeps the email or phone number and the code there too.
No cookies of its ownRead the cookie policy -
Email and SMS signups
A signup goes to the platform you picked in that step. Atomato sends it to Mailchimp and Omnisend as subscribed, and Klaviyo and Drip get no status. You write the disclosure line shoppers see.
Sent to the platform you pickWhat shoppers see -
Integration API keys
Keys you connect are saved in Atomato's database and shown in full on the integration page to anyone who can open Atomato. Use a key made only for Atomato.
Shown in full in the appWho can see your keys -
Outside services
Besides Shopify and the tools you connect, Atomato uses Heroku and Supabase to run the app, OpenAI for Generate text, Mailgun for its notification emails and Slack for error alerts.
Every outside service namedSee the subprocessors
FAQ
Questions reviewers and merchants ask
Short answers, each linked to the help article that covers it in full.
Where can I find Atomato's policies and permissions?
Atomato's privacy policy and terms of use are linked in the footer of this site. The Shopify permissions Atomato requests are listed by feature in which Shopify permissions Atomato requests, and why. For how to reach the team with a privacy or security question, see where to find Atomato's privacy policy and terms of use.
How does Atomato work with my consent banner?
Shopify decides when Atomato's pixel runs, based on each shopper's choices from your consent banner or Shopify's customer privacy settings. When it doesn't run, messages still show, but that visit's message activity doesn't reach Analytics. The storefront script doesn't check those choices. On each page it asks Atomato for campaigns. That request carries the page address, device type, language and country, plus a signed-in customer's first and last name so messages can include them, and Shopify adds that customer's ID. The script also keeps a few notes in browser storage. Whether your banner and privacy notice should cover that is for you and your legal adviser to decide. See how Atomato works with Shopify's customer privacy settings.
What do shoppers see when they sign up, and what reaches my email or SMS platform?
Shoppers see your Disclosure Language under the signup buttons. Atomato sends the email address or phone number to the platform you picked in that step. It sends Mailchimp and Omnisend the status subscribed, including for a contact who had unsubscribed, and sends Klaviyo and Drip no subscription status. New campaigns start with sample disclosure text, so rewrite it for your form. What your wording and platform settings need to cover is a question for your legal adviser. See what shoppers see and what Atomato sends when they sign up.
What happens when a customer asks for their data or to be erased?
When you act on the request in Shopify, Shopify passes it to Atomato. An erasure request deletes the revenue records and SKIO data held under that customer's ID. It doesn't cover records made while the shopper was signed out, the customer's ID and name in campaigns that use Specific customers, or the email or phone number and code that a discount signup keeps in the shopper's browser. Contacts in your email or SMS platform, the customer's data in SKIO and discount codes in your Shopify store stay too. A data request emails Atomato's team a summary of the revenue records and SKIO data under that customer's ID. The team then emails you every record Atomato holds under that ID for your store, including the customer's ID and name in campaigns that use Specific customers, within 30 days of the request, as Atomato's Data Processing Agreement sets out. The records come to you, not to the customer or to Shopify. How you answer a request is your decision, so check with your own legal adviser. See what happens when a customer asks Shopify for their data or to be erased.
Who can see my API keys, and which outside services does Atomato use?
Integration keys are saved in Atomato's database and shown in full on the integration page to anyone who can open Atomato, so use a key made only for Atomato and revoke it in your platform when you stop using it. Atomato also uses Heroku for its app server, Supabase for its database and analytics, OpenAI for Generate text, Mailgun for its notification emails and Slack for error alerts, all listed on the subprocessors page. Whether your store's privacy policy should mention these services is for you and your legal adviser to decide. See where Atomato uses your integration API keys and who can see them and outside services Atomato uses.
What happens to my data when I uninstall?
When you uninstall, Atomato deletes your store's staff sign-in records, clears your plan and emails the recipients you turned on under Email notifications to ask for feedback. Campaign records, analytics, settings and saved API keys are deleted from its database when Shopify later asks Atomato to erase your store's data, apart from recent shopper activity not yet added to your analytics. Customer segments, order tags, uploaded images and signup discount codes stay in your Shopify store, and message content saved as metaobjects can stay too. Contacts stay in your email or SMS platform. Revoke your API keys in each platform too. To decide what your store needs to delete or keep, check with your own legal adviser. See what happens to your data when you uninstall Atomato.
Have a security or privacy question for the team?
Ask the Atomato support team, Monday to Friday, 9 AM to 5 PM Pacific Time, and include your store's .myshopify.com address so the team can find your store. To report a security vulnerability, email support@atomato.co. Section 31 of Atomato's terms of use covers how those reports are handled.
In the app, click Contact support under Help & Support.
1