DropifyBot
Privacy Policy
This Privacy Policy explains how DropifyBot handles information when streamers connect Twitch and Shopify, viewers claim discount codes, and subscribers manage paid plans.
Last updated: July 22, 2026
Who we are
DropifyBot provides Twitch-to-Shopify discount automation, including chat commands, viewer claim flows, Shopify discount creation, subscription management, and aggregate discount analytics.
In this policy, “DropifyBot,” “we,” “our,” and “us” refer to the operator of the DropifyBot service. Questions and privacy requests may be sent to support@dropifybot.com.
Information we collect
Streamer account information
When a streamer signs in with Twitch, we may receive and store the Twitch account identifier, login name, display name, authorization tokens, granted permissions, and information needed to operate the bot in that streamer’s channel.
Shopify connection information
When a merchant connects Shopify, we store the shop domain, encrypted Shopify authorization token, granted scopes, store timezone, connection status, and identifiers needed to create and monitor discount codes.
Viewer claim information
When a viewer requests or claims a discount, we may process a Twitch account identifier, Twitch login, claim status, timestamps, the associated streamer, and information needed to enforce cooldowns, claim limits, and fraud-prevention rules.
Discount and analytics information
We store discount configuration and operational records such as discount type, discount amount, creation time, expiration time, status, Shopify usage count, attributed sales totals, currency, and analytics synchronization status.
Billing information
Paid subscriptions are processed through Stripe. We may store Stripe customer, checkout, price, and subscription identifiers, subscription status, plan, billing period dates, and related billing metadata. Payment-card details are entered into Stripe-hosted payment interfaces and are not stored directly by DropifyBot.
Technical information
We may process IP addresses, browser and device information, request timestamps, security events, error information, and limited server logs to authenticate users, maintain the service, prevent abuse, and diagnose failures.
Information we do not request from Shopify
DropifyBot is designed to operate without requesting Shopify customer or order scopes. We do not intentionally collect or store Shopify customer names, customer email addresses, shipping addresses, complete order records, or raw order webhook payloads.
Dashboard sales reporting is based on Shopify’s aggregate discount analytics rather than customer-level purchase histories.
How we use information
We use information to:
- Authenticate streamers and viewers.
- Connect Twitch channels and Shopify stores.
- Create and manage Shopify discount codes.
- Deliver private viewer claims and global stream drops.
- Apply cooldowns, plan limits, and abuse-prevention rules.
- Provide dashboard metrics and discount analytics.
- Process subscriptions and maintain billing status.
- Secure, debug, maintain, and improve the service.
- Respond to support and privacy requests.
- Meet legal obligations and enforce our Terms of Service.
Legal bases for processing
Where data-protection law requires a legal basis, we process information as necessary to provide the service requested by you, based on our legitimate interests in operating and securing DropifyBot, with consent where requested, and where necessary to comply with legal obligations.
You may withdraw consent where consent is the applicable basis. Withdrawal does not affect processing that occurred before the withdrawal.
Data retention
We retain information only for as long as reasonably necessary to provide and secure the service, enforce limits, maintain business and accounting records, resolve disputes, and comply with legal obligations.
Retention periods can differ depending on the type of record. Active account and integration records are generally retained while the account remains connected. Security logs, claim records, analytics records, and backups may remain for a limited period after account deletion.
Payment and transaction records may be retained by Stripe and by us where required for tax, accounting, fraud prevention, chargeback, or legal purposes.
Security
We use technical and organizational safeguards designed to protect information. These include encrypted provider tokens, authenticated service-to-service requests, restricted database access, secure OAuth state verification, HTTPS, session protections, limited logging, and access controls.
No online service can guarantee absolute security. Users should protect their Twitch, Shopify, Stripe, and DropifyBot accounts and notify us promptly of suspected unauthorized access.
International processing
DropifyBot and its service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws.
Where required, we use legally recognized safeguards for international transfers and rely on our providers’ applicable transfer mechanisms.
Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also have the right to complain to a data-protection authority.
To exercise a privacy right, email support@dropifybot.com. We may ask for information needed to verify your identity and relationship with the relevant Twitch account or Shopify store.
Authorized agents may submit requests where permitted by law, but we may require proof of authorization and direct identity verification.
Children
DropifyBot is not directed to children who are not legally able to consent to use of the service. We do not knowingly collect personal information from children in violation of applicable law. Contact us if you believe a child has submitted information improperly.
Third-party services
Twitch, Shopify, Stripe, and other third-party services have their own privacy policies and terms. DropifyBot does not control how those independent services process information. Users should review those providers’ policies before connecting an account.
Changes to this policy
We may update this Privacy Policy to reflect service, legal, or operational changes. The “Last updated” date shows when this policy was most recently revised. Material changes may also be communicated through the website, dashboard, or email where appropriate.
Contact us
Privacy questions, complaints, and requests can be sent to:
DropifyBot Support
Email: support@dropifybot.com