1. Scope
This Privacy Policy applies to the MaxVFY Shopify application, MaxVFY verification-request pages, related support pages, and the service infrastructure used to create, track, and manage identity-verification requests. It does not replace the privacy notices that apply inside a third-party hosted identity-verification flow.
2. Information MaxVFY collects
Shopify merchant and app information
When a merchant installs or uses MaxVFY, we may receive or maintain information needed to authenticate and operate the app, such as the Shopify shop domain, shop name or identifier, app-installation credentials or tokens, installation status, and technical records associated with the connection. Authentication secrets are treated as confidential service credentials.
Verification-request records
For each request, MaxVFY may store a MaxVFY request identifier, merchant-entered reference or purpose, optional internal note, secure-link state, timestamps, request status, archive state, provider session identifier, verification outcome/status, billing-state identifiers, and audit or event history. Merchants should not place sensitive personal information, identity-document data, medical information, financial-account details, or other unnecessary personal data in the reference or internal-note fields.
Recipient interaction and technical information
MaxVFY records limited activity needed to operate a request, such as when a secure link is created, opened, continued, started, completed, expired, cancelled, archived, or restored. Standard web-server and security logs may also contain request timestamps, network address, browser or user-agent information, and security diagnostics. We use this information to operate, secure, troubleshoot, and prevent abuse of the service.
3. Identity documents, selfies, and biometric-related data
Identity verification is completed through a hosted verification flow powered by Didit, the identity-verification technology provider. Depending on the configured checks, that flow may process identity-document images and data, selfies, face images, liveness captures, biometric-derived information, device or network information, and anti-fraud telemetry needed to perform the verification.
MaxVFY is designed so that the Shopify merchant dashboard does not display or store copies of identity documents, selfies, liveness videos, biometric templates, document numbers, or extracted identity-document data. MaxVFY receives the limited session metadata, status, timestamps, and verification outcome needed to operate the service.
Before completing a verification, recipients should review the MaxVFY Verification Privacy Notice. The hosted verification provider's required legal notices are linked there and from the verification journey where applicable.
4. How we use information
- Authenticate the merchant and maintain the Shopify app connection.
- Create and manage secure verification requests and 24-hour request links.
- Show request progress, timestamps, status, and final outcome to the requesting merchant.
- Maintain request history, search, archive/unarchive, and audit records.
- Prevent abuse, investigate security incidents, troubleshoot errors, and protect service integrity.
- Measure billable successful verifications and maintain billing/audit records when Shopify billing is enabled.
- Respond to support, legal, privacy, security, and compliance requests.
- Comply with applicable law and enforce our Terms of Service.
We do not sell personal information. We do not use verification data for third-party behavioral advertising, and MaxVFY does not use Shopify customer data for advertising or marketing profiles.
5. When information is disclosed
We disclose information only as reasonably necessary to operate the service, comply with law, protect rights and security, or complete billing. Relevant recipients may include:
- Shopify, for app installation, authentication, platform operation, required compliance events, and Shopify-managed app billing.
- Identity-verification technology provider. Didit powers the hosted verification checks and processes verification materials needed to perform those configured checks. We reference Didit only as necessary to identify the verification technology provider and provide legally required notices.
- Infrastructure and security service providers used to host, protect, monitor, or deliver MaxVFY.
- Authorities or legal recipients when disclosure is required by law, valid legal process, or reasonably necessary to protect rights, safety, security, or prevent abuse.
We do not authorize service providers to use MaxVFY data for their own marketing purposes merely because they support our service.
6. Retention
We retain MaxVFY request, audit, security, and billing records for as long as reasonably necessary to operate the service, maintain legitimate audit and billing records, prevent abuse, resolve disputes, enforce agreements, and satisfy legal obligations. Archiving a request hides it from the merchant's normal current-request view; archiving is not deletion.
When Shopify sends a valid mandatory privacy/compliance request, MaxVFY processes it in accordance with Shopify's requirements and applicable law, subject to any lawful retention requirement. Retention of materials within the hosted verification flow is governed by the verification provider's applicable notices, configuration, contractual terms, and legal obligations.
7. Privacy rights and requests
Depending on applicable law, an individual may have rights to request access, correction, deletion, restriction, objection, or other treatment of personal information. Merchants and verification recipients may submit a privacy request through MaxVFY Support. We may need information sufficient to authenticate the request and locate the relevant verification or merchant record.
Requests concerning identity documents, selfies, liveness captures, or biometric-related information handled within the hosted verification flow may require coordination with the verification technology provider. MaxVFY will route or address such requests as appropriate to the context and applicable law.
8. Security
MaxVFY uses administrative, technical, and organizational safeguards designed to protect service data, including authenticated Shopify sessions, encrypted storage of sensitive app credentials, access controls, secure transport, request-token protections, audit logging, and anti-abuse controls. No system can guarantee absolute security, and users should promptly report suspected unauthorized access through support.
9. International processing
Service infrastructure and third-party providers may process information in countries other than the country where a merchant or verification recipient is located. Where applicable, the relevant provider's privacy terms and legally required transfer safeguards govern its processing.
10. Children and age restrictions
MaxVFY's verification-request workflow is intended for adults age 18 or older. It is not designed for requesting identity verification from children. Merchants must not knowingly use MaxVFY to request verification from a person under 18.
11. Changes to this Policy
We may update this Policy when the service, law, or data practices change. The updated version will be posted here with a revised “Last updated” date. Material changes may also be communicated through the app or another reasonable method when required.
12. Contact
For privacy questions, rights requests, or concerns, use https://shop.maxvfy.com/support. We intentionally use the support portal rather than publishing personal or support email addresses on this page.