Made By Fans
Legal & Compliance

Privacy Policy

Last updated: September 2026

Made By Fans (“we”, “our”, or “us”), operated by Lubab LTD (registered in the United Kingdom), is a Shopify application built to help merchants collect, manage, and share authentic video testimonials from their verified customers. We take privacy seriously and adhere strictly to global data protection laws, including the European General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act (“CCPA”), and Shopify’s Partner API compliance requirements.

Shopify Merchant Guarantee: Made By Fans never sells customer data, never tracks users across external websites, and only processes data necessary to execute post-purchase video invitations and display approved testimonials.

1. Data We Collect

When merchants install and use Made By Fans, or when consumers interact with our invitation and submission pages, we process the following categories of information:

  • Merchant Account Data: Your Shopify store domain (e.g., store.myshopify.com), unique Shopify Shop ID, active subscription plan, and administrative access tokens required to operate the application within Shopify Admin.
  • Customer Order & Contact Data: When an order is completed, we receive the customer’s email address and Shopify Order ID to dispatch automated post-purchase invitations according to your campaign settings.
  • Customer Testimonial Submissions: Display name (optional), customer email, recorded video files, and structured timestamps recording explicit publishing and advertising consent.
  • Technical Logs & Metrics: IP addresses (used exclusively for rate-limiting and preventing abuse), browser user-agent, and video playback/upload error diagnostics.

2. How We Use Your Data

We process collected data exclusively for the following legitimate business purposes:

  • To dispatch transactional story requests and reward discount codes to verified buyers.
  • To encode, store, and stream submitted video testimonials to merchants for review.
  • To maintain audit-ready records of customer marketing and advertising consent.
  • To prevent fraud, multiple automated submissions, and malicious API usage.
  • To calculate subscription quotas and billing under Shopify Managed Pricing.

3. Authorized Sub-Processors

We partner with high-security, industry-standard infrastructure providers to deliver our service:

ProviderRoleLocation
Shopify Inc.Application host, merchant authentication, and billingCanada / Global
Mux, Inc.Direct video uploads, encoding, streaming, and CDN hostingUnited States
MailerSendTransactional email dispatch for invitations and test emailsUnited States / EU

4. Data Retention & Auto-Purge

Submitted video files are stored according to the merchant’s active subscription retention window (30 days on Basic, 90 days on Grow and Advanced). Once the retention deadline passes, video media files are permanently removed from our streaming servers while audit receipts (consent, timestamp, and order linkage) remain preserved for merchant protection.

5. GDPR & CCPA Compliance (Your Rights)

Under GDPR and CCPA, customers and merchants possess the following rights:

  • Right to Access: Request a complete export of all testimonial data associated with your email or order.
  • Right to Erasure / Takedown: Request immediate deletion of video files, name, and contact details.
  • Right to Revoke Consent: Customers may withdraw consent for publishing or advertising at any time. When revoked, the testimonial is immediately locked and suppressed.

Made By Fans fully implements Shopify’s mandatory GDPR webhooks:

  • customers/data_request: Generates customer data records upon merchant or buyer inquiry.
  • customers/redact: Automatically anonymizes customer details, scrubs pending invites, and removes video media within 48 hours.
  • shop/redact: Permanently deletes all store data, campaigns, videos, and session tokens within 48 hours of an uninstallation or store deletion.

6. Security Measures

All network communication is strictly encrypted in transit using TLS 1.3. Database storage utilizes PostgreSQL with row-level workspace scoping and atomic rate-limiting safeguards. Tokens generated for customer invite links are cryptographically random 128-bit identifiers that cannot be guessed.

7. Contact Us

If you have questions regarding this Privacy Policy or wish to exercise your data protection rights, please contact our Data Protection team at:

Company: Lubab LTD (United Kingdom)
Email: privacy@lubab.dev
Support: support@lubab.dev