Fixify Privacy Policy
Effective and last updated: August 26, 2026
Scope
This policy applies to Fixify, the Shopify shipping-address editing application operated by MK WebTech. It explains the categories of information Fixify processes, why that information is needed, and the choices available to merchants and customers. Fixify integrates with Shopify and uses Shopify APIs to provide its functionality. MK WebTech operates Fixify independently and is not Shopify.
Information processed
Merchant and shop information
Fixify may process:
- Shopify shop identity and app installation or session information.
- Merchant configuration, editing permissions, and editing-window settings.
- Subscription or plan status and completed order-edit activity.
Customer and order information
To provide eligible shipping-address corrections, Fixify may process:
- Shopify customer or Customer Account identifiers.
- Order identifiers, order state, fulfillment state, and other eligibility information.
- Line items, products, variants, quantities, totals, and currencies.
- Customer name and shipping address when needed for an eligible shipping-address edit.
Fixify does not currently request customer email addresses or phone numbers for its core Customer Account shipping-address workflow. Shopify or a separate support interaction may process contact information under its own applicable terms and privacy practices.
Pseudonymous references and access records
Fixify uses pseudonymous, HMAC-based identifiers for certain stored customer and context references. Fixify also maintains metadata-only protected-data access audit records for security and compliance. These audit records identify the context and purpose of access without storing the raw protected payload.
Why information is processed
Fixify processes information to:
- Authenticate Shopify Customer Account requests.
- Verify customer and order ownership.
- Determine order and requested-edit eligibility.
- Apply merchant editing permissions and editing-window rules.
- Preview and execute eligible order edits.
- Maintain completed edit and activity records.
- Enforce billing and plan limits.
- Support security, auditing, and abuse prevention.
- Process privacy requests, redaction, and deletion requirements.
- Provide troubleshooting and support where necessary.
Protected customer data is not used for advertising.
Payments
Fixify does not collect or store customer payment-card credentials. The current launch product supports eligible edits that do not require an additional customer payment or refund. Fixify plan billing is administered through Shopify.
Shopify and service providers
Fixify uses Shopify APIs and platform services to authenticate requests, access eligible order information, and complete supported edits. Shopify processes information under its own terms and privacy practices.
MK WebTech also uses trusted providers for application hosting, managed database hosting, security, and operational infrastructure. These providers process information only as needed to provide their services to MK WebTech and are subject to applicable contractual and confidentiality obligations. Provider certifications are not certifications of Fixify or MK WebTech.
Security
Fixify uses HTTPS/TLS for data in transit and provider-managed encryption at rest. Application secrets are managed outside customer-facing code. Shopify Customer Account session tokens authenticate customer requests, and server-side authorization validates customer identity, order ownership, eligibility, and merchant rules before an edit is completed.
Production access is restricted to authorized operational access. Fixify uses pseudonymous identifiers for certain stored references and maintains metadata-only protected-data access logs. No internet service can guarantee perfect security, but MK WebTech applies safeguards appropriate to the information and application.
Retention
Personal data is retained only for as long as needed for application functionality, security and audit records, operational requirements, and applicable obligations. Retention differs by record type. Short-lived request data may expire after processing, while edit activity, plan usage, security evidence, and compliance records may be retained for their relevant operational purpose.
Data is deleted or anonymized when required by a valid privacy request, subject to legitimate legal, security, and operational retention requirements. Shop-associated information is processed according to Shopify shop-redaction requirements and the application's applicable data-handling rules.
Shopify privacy requests
Fixify supports Shopify's mandatory privacy processes, including customers/data_request, customers/redact, and shop/redact. At a high level, these processes allow applicable customer-associated information to be identified for access or export and allow customer or shop information to be redacted or deleted according to Fixify's data-handling and retention rules.
Protected-data audit records
Fixify maintains metadata-only security audit records for protected customer-data access. These records use pseudonymous identifiers and do not contain customer names, shipping addresses, email addresses, phone numbers, session tokens, or raw protected payloads.
Data sale and advertising
Fixify does not sell merchant or customer personal data. Fixify does not use protected customer data for advertising.
Merchant and customer rights
Privacy requests may be initiated through the Shopify merchant and through applicable Shopify privacy mechanisms. Merchants and customers may also contact MK WebTech about access, correction, deletion, or other privacy questions. The ability to fulfill a request depends on the requester's relationship to the store, applicable Shopify processes, and relevant legal or operational requirements.
Contact
For Fixify privacy or support questions, use the MK WebTech contact page or email [email protected]. Please identify Fixify and your Shopify store, but do not send passwords, API keys, access tokens, payment information, or unnecessary customer/order data.
Policy updates
MK WebTech may update this policy when Fixify's functionality, data practices, service providers, or applicable requirements change. The effective and last-updated date at the top of this page will be revised when an update is published.

