Klofy
Last updated 25 August 2026

Privacy policy

Written to be checked against the software, not to be skimmed. Every item below matches a table that actually exists.

Who we are

Klofy is a suite of Shopify apps built by Kloeth Digital B.V., a company registered in the Netherlands. For questions about this policy or about your data, write to support@klofy.app.

This policy covers both this website and the Klofy apps you can install in a Shopify store.

Registered name
Kloeth Digital B.V.
Chamber of Commerce
42106998, the Netherlands
VAT number
NL869764585B01
Email
support@klofy.app

This website

klofy.app sets no cookies, runs no analytics, and loads no fonts, scripts or images from anyone else. There is nothing here to consent to.

Our web server processes your IP address in order to send you the page, and records it in an access log that is kept for at most fourteen days for security and troubleshooting. After that it is deleted.

Who is responsible for what

Two different relationships apply, and it matters which one you are in.

  • Data from a Shopify store. When a merchant installs a Klofy app, we process that store's data on the merchant's instructions. The merchant decides what happens with it. In the language of the GDPR, the merchant is the controller and we are the processor.
  • Data about the person who installs. Shopify tells us the name and email address of the Shopify user who installed the app. We are the controller for that, and we use it only to operate the app and to answer support requests.

What each app stores

Each app stores only what its own job requires. The lists below are complete.

Klofy - 404 & Redirects

WhatDetail
Dead URL hits on your storefrontThe requested path including its query string, the origin and path of the referring page, UTM parameters, an advertising click identifier if the visitor arrived with one (gclid, gbraid, wbraid, msclkid or ttclid), whether the visitor looked like a browser or a bot, and the time.
Audit resultsThe findings of each run: which redirects are broken, which URLs are dead, and how much of the check went unanswered.
Navigation snapshotsThe links in your storefront menus and the status each one returned, so a menu pointing at a dead page can be reported.
A log of every change Klofy madeThe redirect, its old destination and its new one. This is what makes a fix reversible, and it is the only record of it, because Shopify redirects carry no marker saying which app created them.
Product and collection handlesThe handle, title, vendor, product type and variant SKUs that Klofy last saw. Shopify reports the new state of a product but not the previous one, so recognising a rename is only possible by remembering what came before.
Archive evidence about dead pathsWhat the Internet Archive knew about a page that no longer exists, so Klofy can suggest a destination instead of guessing one.
Your store sessionThe access token Shopify issues at install, plus the name and email address of the Shopify user who installed the app, as supplied by Shopify.

Permissions this app requests from Shopify: read_online_store_navigation, write_online_store_navigation, read_products. There is no customer or order permission among them, so the app cannot read customer records or orders.

What we never store

These are design decisions, not settings. They are not switched on somewhere else.

  • No IP addresses of storefront visitors.
  • No cookies, no local storage and no device fingerprints. Klofy cannot recognise a returning visitor and does not try to.
  • No raw user agent strings. A visitor is classified as a browser, a bot or unknown before anything is written, and only that classification is kept.
  • No customer records and no order data. We do not have the Shopify permissions that would allow it.

Visitors to a store that uses Klofy

If you land on a page that no longer exists in a Shopify store running Klofy, the app records that the page was missing. It stores the address you asked for, where you came from, whether your browser looked like a person or a bot, and the time.

The address you asked for is stored as it was requested, which means it includes anything the link carried, such as campaign parameters or an advertising click identifier added by Google, Microsoft or TikTok. Those identifiers come from the link you clicked, not from us, and we do not use them to build a profile, combine them with anything else, or pass them on. Their only purpose is to let the merchant see which broken link is costing them.

Nothing is stored that identifies you personally, and no cookie is set.

Where your data is

Everything the apps record lives on servers in Germany, inside the European Union, and is not copied to any other region. That covers all of the data described above.

Support email is the one exception, and it is worth being exact about it. If you write to us, that message sits in our mailbox at Google Workspace rather than on our own servers. Google may process it outside the European Union under its own terms, which is why it is named below.

Who else is involved

PartyRole
Hetzner Online GmbHHosting and backups, in a data centre in Germany
ShopifyThe platform the apps run in. Shopify holds the store data itself and has its own privacy policy
The Internet ArchiveAsked what it knows about a page that no longer exists. We send it a web address, never personal data
Google Ireland LimitedRuns the mailbox that receives support requests, through Google Workspace. Only what you send us yourself ends up there

How long we keep it

App data lives as long as the app is installed. When a merchant removes a Klofy app, Shopify notifies us roughly forty eight hours later and everything belonging to that store is deleted in one go, including sessions, audit results, recorded dead URL hits and the change log.

One thing is deliberately left alone: the URL redirects themselves. Those are ordinary Shopify data belonging to the merchant, and they stay in the store after Klofy is gone. That is the point of the app.

Backups are made nightly and kept for fourteen days, so deleted data disappears from backups within that window.

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, or object to how we use it. Write to support@klofy.app and we will answer within thirty days.

If you shopped in a store that uses Klofy and want to exercise a right, contact that store. They decide what happens with their data, and we act on their instruction. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Changes

If this policy changes in a way that matters, the date at the top changes with it and merchants with the app installed are told by email.