Privacy
Sway sends push, email, and WhatsApp notifications for Shopify stores. This page explains exactly what it collects, why, and how long it keeps it. Last updated 24 September 2026.
The short version
Sway stores a shopper’s first name (never a full name) — and, only for shoppers who opt in, their email address or phone number. Sway never collects a shopper’s postal address; the only postal address Sway holds is the store’s own, printed on marketing emails because the law requires it. Sway holds level 2 protected customer data access from Shopify, the level that covers exactly those fields. Sway does not sell or share personal data with anyone.
If you are a shopper
A store you visited uses Sway to send notifications — by browser push, email, or WhatsApp, depending what you opted into. Sway holds:
- Your push subscription — an address your browser generates so notifications can reach it, plus the encryption keys that go with it. It identifies a browser, not a person.
- A random browser id, so a notification can be linked to the visit it produced. It is not derived from anything about you.
- Your first name, if the store has it from Shopify — used only to greet you by name (“Hey Sarah,”) in a message you already opted into.
- Your email address, only if you subscribed to email from this store.
- Your phone number, only if you opted into WhatsApp messages from this store.
- Which store pages and products you viewed, and what you added to a cart or ordered — only where the store has your consent to analytics.
- Order totals and dates, used to work out things like “ordered before” or “has not ordered in a while”.
To stop it: block or reset notification permission for the store in your browser settings. That ends delivery immediately. To have the data removed, ask the store to request deletion on your behalf — Shopify passes that request to Sway and it is honoured automatically.
If you are a merchant
Sway reads, from your store:
- Product descriptions and store pages, to learn how your store writes so campaigns sound like you.
- Your customers — first name, email address, and phone number, for whichever of push, email, and WhatsApp each one has opted into. This is what lets Sway message them at all; see “If you are a shopper” above for what that means for them.
- Orders and checkouts — customer id, totals, currency, line items, status and timestamps.
- Customer events from Shopify’s Web Pixel, for browse-abandonment triggering.
It is used only to segment your subscribers, trigger your flows, and attribute revenue to notifications. It is not used to train models, is not combined across stores, and is not shared with other merchants.
Automated content generation
Sway uses Anthropic’s Claude API to write campaign copy. No customer data is sent to it. What is sent is your brand voice profile, samples of your own product and page copy, and the campaign brief you wrote. Nothing that identifies a shopper leaves Sway.
Live chat
Sway’s website and admin pages carry a live-chat widget provided by Tawk.to, so you can ask a question without leaving what you are doing. It is there for merchants; it is never shown to your shoppers. Tawk.to receives what you type in the chat, the page you were on, your browser and approximate location, and it sets its own cookies to keep a conversation together across pages. Shopify session credentials are removed from the page address before the widget loads, so it never sees them. Sway does not send it anything about your customers.
How long it is kept
- Behavioural events: 180 days.
- Notification and revenue records: 400 days, so year-on-year comparisons work.
- Subscribers who unsubscribe or expire: identifiers are erased after 180 days. Aggregate totals survive so your revenue history stays correct.
- Email addresses and phone numbers: if you unsubscribe, ask the store to delete your data, or the store uninstalls Sway, the address or number itself is erased. Your marketing preference (subscribed or not) is kept separately and is not reset by a deletion request — deleting your data erases what Sway holds right now, it does not withdraw your consent. That means if the store later has a new reason to share your information with Sway again — a new order, for instance, or reconnecting Sway — and you were previously subscribed, messages may resume without asking you to opt in again. If you want to stop being messaged as well, unsubscribe (see “To stop it” above) — that preference does survive.
- Everything: deleted within 48 hours of uninstalling Sway.
A scheduled job enforces this nightly. It is not a stated intention — it runs.
Consent
Where your store uses Shopify’s consent management, Sway obeys it. Without analytics consent it records no browsing and creates no browser id; without marketing consent it does not show the notification opt-in prompt. Consent granted later takes effect without a page reload.
Security
Data is encrypted in transit. Every storefront request is verified against Shopify’s signature before it is trusted. Access to production data is limited to Sway’s operator.
Your rights, and requests
Shopify’s customers/data_request, customers/redact and shop/redact webhooks are implemented, so access and deletion requests made through Shopify are handled automatically. For anything else, contact privacy@getsway.io.
Changes
Material changes will be announced in the app before they take effect.