Champ › Privacy policy
Privacy policy
Effective 20 September 2026
This policy explains what Champ collects when a merchant installs it on a Shopify store, what it does with that data, and how to get it removed. It describes actual practice, not aspiration.
Who we are#
Champ is a Shopify application operated by Furvur. Contact: support@getchamp.net.
There are two groups of people in this policy: merchants, who install Champ on their Shopify store, and forum members, who are the merchant's own customers posting in that merchant's forum. For forum content, the merchant is the data controller and Champ is the processor acting on their instructions.
What we collect from merchants#
- Your Shopify store domain, shop name, email address, plan and country, supplied by Shopify at install.
- An offline access token that lets Champ read your customer records, stored encrypted.
- Settings you enter in the dashboard: colours, custom CSS, translated strings, menus, webhook URLs, and — if you provide them — SMTP credentials and Cloudinary, reCAPTCHA or Akismet keys. Credentials are stored encrypted.
- Billing status, held by Shopify. Champ never sees or stores a payment card.
What we collect from forum members#
- The Shopify customer ID, name and email address of members who sign in, so posts can be attributed and notifications sent.
- Content members submit: topics, posts, private messages, poll votes, reactions, tags, nicknames, profile descriptions, signatures and uploaded avatars.
- The IP address and user agent attached to a post, retained for spam prevention and abuse investigation.
- Read state, subscriptions and points, so "unread" and the leaderboard work.
Member images and file attachments, where a merchant has enabled them, are uploaded to that merchant's own Cloudinary account, not to us.
Access scope#
Champ requests exactly one Shopify scope: read_customers. It is used to identify a signed-in customer and read the tags that govern forum access. Champ does not read orders, products, inventory or payment data, and cannot write to your store.
Cookies#
Champ sets a session cookie so a signed-in member stays signed in across forum pages, and — where enabled — cookies required by reCAPTCHA. There is no advertising network, no third-party analytics tracker and no cross-site profiling on forum pages served by Champ.
This marketing site — getchamp.net, the pages you are reading now — uses Plausible Analytics, which we host ourselves. It sets no cookies, stores no personal data, assigns no persistent identifier, and does not follow you to any other site. It is not loaded on merchants' forum pages.
Who we share it with#
Nobody, except the service providers needed to run the app:
- Shopify — authentication, billing and customer records.
- Our hosting and database providers — where the application and its database run.
- Cloudflare R2 — encrypted database backups.
- Akismet, StopForumSpam and Project Honey Pot — a post's IP address and, for Akismet, its text, when checking whether it is spam. Akismet is used only if the merchant supplies their own key.
- The merchant's own SMTP provider or ours — to deliver notification email.
We do not sell personal data, and we do not use forum content to train machine learning models.
Retention#
Forum content is retained for as long as the merchant's store has Champ installed, because uninstalling is frequently temporary and merchants expect their community to survive it. IP addresses attached to posts are retained while the post exists. Backups are kept for 14 days and then deleted.
Your rights#
Members should contact the merchant whose forum they posted in — they control that data. Shopify's customer data request and redaction flows are implemented and honoured; see the GDPR page. Merchants can email us to export or delete a store's data at any time.
Changes#
If this policy changes materially, the effective date above changes with it and merchants are notified by email.