Skip to the content
NuFlorist logo
  • Features
  • Pricing
  • FAQ
  • Schedule a Demo
  • Install on Shopify
Menu
  • Features
  • Pricing
  • FAQ
  • Schedule a Demo
  • Install on Shopify
EnglishENEspañolES

Privacy Policy

Last updated: September 7, 2026

Who we are

  • Nuflorist, LLC, a Florida limited liability company
  • 7500 NW 25th St, STE 212, Doral, FL 33122, USA
  • info@nuflorist.com

Nuflorist, LLC ("NuFlorist," "we," "us") is responsible for the personal information described in this notice. Where the EU or UK General Data Protection Regulation (GDPR) applies, we are the "controller" of that information, except where this notice says we process data on a merchant's behalf.

Scope

This notice covers two things:

  1. Our website, nuflorist.com.
  2. The NuFlorist Shopify app, which florists ("merchants") install from the Shopify App Store to manage deliveries and orders on their own Shopify stores. This is the privacy policy for our Shopify App Store listing.

If you buy flowers from a shop that uses our app, that shop — not NuFlorist — decides how your order information is used. We process it on the shop's behalf to make the app work, as described below. Questions about a florist's own privacy practices should go to that florist.

Information we collect — website

Our website has no user accounts, no login, and no online store. The only form on the site is the search box on our "page not found" page; anything typed there is sent to our web host as part of the page request and is not stored by us. Our cookie banner stores only your choices, on your own device. We collect very little:

  • Analytics data — only with your consent. If you enable Analytics in our cookie banner, Google Analytics collects usage data about your visit: the pages you view, how long you stay, your device and browser type, and your approximate (city-level) location inferred from your IP address. Our Google tags load through Google Tag Manager, and Google Tag Manager itself loads only after you enable Analytics. If you leave Analytics off, no Google tag loads and Google Analytics does not collect that usage data. See "Cookies and analytics" below.
  • Information you send us. If you email info@nuflorist.com, we receive your email address and whatever you include in your message.
  • Booking details. If you book a call through our Calendly link, we receive the details you enter to schedule it (such as your name and email). The booking page itself is run by Calendly, and Calendly's own privacy policy governs what you enter there.
  • Your consent choices. Your Analytics and Advertising choices, and the date you made them, are saved in your browser's local storage (the "nf-consent-v3" key) on your own device — not on our servers.
  • Consented campaign attribution. If you enable Advertising and arrive with supported campaign parameters (UTM values) or an "oppref" or "obref" referral identifier from a ChatGPT campaign link, we temporarily keep those values, the landing pathname, and the page language in session storage, and we add them to links that continue to our Shopify App Store listing so Shopify can attribute an install to that campaign. A referral identifier can be unique to the link you clicked. We do not put names, email addresses, phone numbers, arbitrary query parameters, URL fragments, form data, customer data, or order data in this record. Rejecting or withdrawing Advertising deletes it.
  • Font and script requests. Our pages serve their fonts and script libraries from nuflorist.com itself. Loading a page sends no request to a third-party font or script service, so no such service receives your IP address. The only third-party code that can run on our pages is Google Tag Manager and Google Analytics, and only after you enable Analytics in our cookie banner.

Information we collect — Shopify app

If you are a florist using our Shopify app — not just visiting our website — this section is about you.

What we store about merchants

  • Sign-in session records for the staff who use the app: name, email, and the access credentials Shopify issues for the session.
  • Shop details Shopify sends us: shop name, shop owner's name, shop email, country, currency, and timezone.
  • If a shop connects MAS Direct Network (a florist wire-order fulfillment service; an optional Pro-plan feature), the MAS account username and a hashed version of the MAS account password.
  • If a shop connects Hana Florist POS (an optional florist point-of-sale integration), the Hana store identifier, username, and password the merchant enters.
  • App configuration the merchant sets up: delivery zones, rates, delivery dates, custom form-field definitions, feature settings, and similar.
  • Billing records that reference the shop's app subscription in Shopify's billing system. All app charges are billed by Shopify. We never see or store card numbers or bank details.
  • Feedback merchants submit inside the app.
  • Order statistics that do not identify the shopper: order date, a delivery-location label, occasion tags (such as "Birthday"), and add-on products.
  • For shops that connect MAS Direct Network or Hana Florist POS, a log of each order hand-off limited to the order ID and number, the outcome, and operational metadata (such as location and item count).

What the app can access, and the short-lived copies it keeps

To do its job, the app is granted read access to the merchant's Shopify data, including customer records and orders, plus products, shipping settings, and store locations. Those customer records and orders contain shoppers' names, emails, phone numbers, and billing and delivery addresses. Shopify classifies name, email, phone, and address as protected customer fields; we access them only to provide app functionality.

We do not keep shoppers' names, emails, phone numbers, or addresses in our own database except as short-lived, encrypted processing copies. When an order is created, Shopify sends us the order. We hold that payload encrypted for at most seven days — it is erased as soon as processing succeeds — and use it to:

  • write delivery details back onto the order in Shopify;
  • record the non-identifying order statistics listed above;
  • send the order to MAS Direct Network or Hana Florist POS, if the shop has connected that integration (see "Sharing and processors"); and
  • email an order notification to the shop's own staff, for shops with that feature enabled (see "Sharing and processors").

If a shopper asks a merchant for their data through Shopify, we prepare an encrypted export that the shop owner can download inside the app for 30 days; it is then deleted automatically. When merchant staff use the "Directions" action in the app's Today's orders view, the delivery address and the shop's address are passed to Google Maps in the link that opens; Google's privacy policy governs that request. We do not write order contents, names, contact details, or card messages to application logs, and personal data is removed from error reports before they reach our error-monitoring service (Sentry).

AI-assisted suggestions

When a merchant clicks "Generate with AI" in the app, the shop's name and country, the occasion names the shop already offers, and any hint the merchant types are sent to Google's Gemini API to produce occasion and card-message suggestions for the merchant to review. No shopper data is sent, and nothing is published until the merchant accepts it.

How we use information

  • To respond when you contact us.
  • To operate, secure, and improve the website and the app, including consent-gated analytics and error monitoring.
  • To provide the app's features to merchants: delivery scheduling, order handling, wire-order fulfillment through MAS Direct Network and order hand-off to Hana Florist POS (both merchant opt-in), staff order notifications, and optional AI-assisted setup suggestions.
  • To bill for the app, through Shopify's billing system.
  • To comply with the law and enforce our terms.

Marketing. We may send marketing emails and text messages to business contacts who engage with us — for example, merchants who use our app, people who book a call with us, or contacts we meet directly. We send these messages through third-party email and messaging service providers, which process your contact details on our behalf. Every marketing email includes an unsubscribe link and our postal address. Reply STOP to any marketing text message and we will stop sending them. We honor opt-outs within ten business days. Opting out of marketing does not affect service messages about an app you use.

Advertising. The website can preserve campaign and referral parameters only after you enable the separate Advertising purpose, as described above. Our Google Analytics property is linked to a Google Ads account so that aggregate conversion counts (for example, clicks on our App Store link) can be imported there; ads personalization is turned off on that link, and we do not use remarketing. If you enabled Advertising, arrived from a ChatGPT campaign link, and later install the app, we may report to OpenAI that an install occurred, using the campaign referral identifier — never your name, email, or shop domain. No social pixel, OpenAI Pixel, or advertising-network script runs on our pages.

Cookies and analytics

The website uses Google Analytics 4 behind a consent banner built on Google Consent Mode v2. The analytics_storage, ad_storage, ad_user_data, personalization_storage, and ad_personalization signals default to denied. No Google tag loads, and no analytics cookies are set, unless you enable Analytics or choose Accept all.

If you consent, Google Analytics uses cookies and similar identifiers to collect information about how you use the site — pages viewed, session length, device and browser type, and approximate location. Google processes that information on its servers to give us aggregated usage statistics. Google explains its handling of this data at policies.google.com/technologies/partner-sites. When Analytics is enabled, Google Analytics also receives named events for the site's lead buttons (the Shopify App Store link, the Calendly booking link, and the contact-email link) with the button label, page path, link destination without any query string, and page language, plus an event recording the consent choices you saved.

Your choice works like this:

  • Accept all enables Analytics and Advertising. If your browser sends a Global Privacy Control signal, Accept all enables Analytics only.
  • Reject non-essential keeps all optional purposes off. If you previously enabled them, this sends an immediate denied update.
  • Manage choices lets you control Analytics and Advertising separately.
  • Your choices are remembered on this device (in the "nf-consent-v3" browser storage key) for 12 months, after which we ask again. Choices saved under our earlier banners are not carried over; the banner asks afresh.
  • If Advertising is enabled, supported campaign-attribution values are kept only in the session-scoped "nf-campaign-attribution-v1" record; withdrawing Advertising removes the record and the parameters the site added to Shopify App Store links.
  • You can change your choice at any time using the Cookie Preferences control in the site footer or on our Cookie Notice.

For the full list of cookies and storage keys we use, see the Cookie Notice.

Legal bases (GDPR/UK)

Where the GDPR or UK GDPR applies, we rely on:

  • Consent — for analytics cookies, for campaign attribution, and for any future marketing or advertising uses that require it. You can withdraw consent at any time, and withdrawal takes effect immediately (see "Cookies and analytics").
  • Contract — to provide the app to merchants who install it, including the integrations a merchant connects, and to bill for it.
  • Legitimate interests — to answer messages you send us, keep our services secure, diagnose and fix errors, and send marketing to existing business contacts in ways you would reasonably expect — you can object at any time (see "Marketing").

Shoppers' order information that passes through the app is processed on the merchant's behalf and on the merchant's instructions. The merchant is responsible for the legal basis covering its customers' data.

Sharing and processors

We do not sell personal information, and we do not share it for cross-context behavioral advertising. The only advertising-related disclosures are the consented campaign attribution and the aggregate conversion reporting described above. Beyond that, we share information only with the service providers below, in a business transfer, or when the law requires it.

ProviderWhat it does for usInformation involved
ShopifyApp platform and billing: the source of merchant and order data, and the biller of all app charges.Merchant and shop data; app subscription records. With your Advertising consent only: the campaign tags and referral identifier from the link you arrived on, appended to our App Store link.
Google (Analytics, Tag Manager, Ads)Google Analytics 4, loaded through Google Tag Manager only after you enable Analytics. The Analytics property is linked to a Google Ads account for aggregate conversion reporting, with ads personalization turned off.Usage data (with consent).
Google CloudRuns and stores the app (Cloud Run, the Cloud SQL database, and Cloud Tasks and Cloud Scheduler background jobs) in the United States.All app data described in this notice.
Google (Gemini API)Powers the app's optional "Generate with AI" occasion and card-message suggestions, only when a merchant clicks that button.The shop's name and country, the occasion names it already offers, and any hint the merchant types. No shopper data.
Google MapsOpens directions when merchant staff click "Directions" on a delivery in the app.The delivery address and the shop's address, in the link that opens.
VercelWebsite hosting (United States).Standard web-request data for the pages you visit.
MAS Direct NetworkFlorist wire-order fulfillment network. Used only for shops that opt into the integration (a Pro-plan feature); when such a shop receives an eligible order, we send it to MAS to place the fulfillment order.Order details, including buyer and recipient names, addresses, emails, and phone numbers.
Hana Florist POS (Hana POS Services)Florist point-of-sale system. Used only for shops that connect it inside the app; when such a shop receives an eligible order, we send the order to Hana so it appears in the shop's POS.Order details, including buyer and recipient names, addresses, emails, and phone numbers, and the shop's Hana login.
Amazon Web Services (SES)Delivers order-notification emails to a shop's own staff, for shops with that feature enabled, and a notice to a shop owner when a customer data-request export is ready to download inside the app.Order details in staff notifications (customer name, contact information, billing/delivery addresses); the shop owner's email address for data-request notices — no customer data is in that email.
OpenAIReceives an install-conversion report only if you enabled Advertising, arrived from a ChatGPT campaign link, and then installed the app.A hashed event identifier, a timestamp, and the campaign referral identifier — no names, emails, or shop domains.
SentryError monitoring for the app. Personal data is removed from reports before they are sent.Error names, status codes, operation names, and true/false flags such as whether an order had a delivery date.
TermlyHosts our data-request (DSAR) intake form.The information you enter when you submit a request.

Business transfers. If NuFlorist is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor this policy or to tell you about any changes.

Legal requirements. We may disclose information when legally required to — for example, in response to a valid court order.

Calendly is a separate company, not our processor: what you enter on its booking page is governed by Calendly's own privacy policy.

Security

We protect information with safeguards appropriate to its sensitivity, including encryption in transit, encrypted storage of order payloads and data-request exports, access controls, and monitoring. If a security incident affects your information, we will notify you and the relevant authorities as the law requires, and we will report any breach affecting a merchant's Shopify data to Shopify within 24 hours of discovery.

International transfers

We are a US company. Our website is hosted in the United States, and our service providers process data in the United States and in other countries where they operate. If you visit from the EEA, the UK, or Canada, your information will be transferred to the US.

Where the GDPR or UK GDPR applies to a transfer, we rely on the safeguards those laws recognize: our providers' certifications under the EU-U.S. Data Privacy Framework (and its UK extension) where they hold them, and the Standard Contractual Clauses included in our providers' data-processing terms. For Canadian residents, we remain accountable for your information under Canada's federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), even when it is processed by a service provider outside Canada. You can ask us for more detail about a specific transfer using the contact details below.

Retention

  • Analytics data exists only if you consented, and is retained on Google's systems according to the data-retention setting in our Google Analytics account.
  • Your consent choice stays in your browser's storage on your device for 12 months, or until you clear or change it. It is not stored on our servers.
  • Emails you send us are kept as long as needed to handle your inquiry and for our routine business records.
  • App data (merchants): when you uninstall the app, we automatically delete the data we hold about your shop — staff sign-in session records, shop details, app configuration, integration credentials (MAS Direct Network, Hana Florist POS), integration logs, non-identifying order statistics, billing references, in-app feedback, and any pending order payloads. This runs once at uninstall and again when Shopify sends its follow-up shop/redact webhook (about 48 hours later), which meets Shopify's requirement to delete merchant data within 30 days of uninstall. We keep only a pseudonymized audit record of each deletion — a keyed hash of the shop domain and webhook ID, the action, and the date — for seven years; it cannot be used to re-identify your shop. You can also ask us to delete your data at any time while the app is installed by emailing info@nuflorist.com.
  • Order webhooks: when Shopify notifies us of a new order, we hold the order payload encrypted for at most seven days so it can be processed reliably; it is erased as soon as processing succeeds.
  • Customer data-request exports: when a merchant forwards a shopper's data request through Shopify, we prepare an encrypted export the shop owner can download inside the app for 30 days; it is then deleted automatically and we notify Shopify with metadata only.
  • Technical logs and error reports (including those captured by Sentry) are kept for a limited period set in those services, then deleted automatically.
  • Data-request records are kept as long as needed to show we handled your request properly.

Your rights — US state residents

No US state comprehensive privacy law (such as the California Consumer Privacy Act) currently applies to NuFlorist — each of those laws sets revenue or data-volume thresholds far above our size. We honor the core rights they describe anyway, voluntarily, for all US residents:

  • Know and access — ask what personal information we have about you and get a copy.
  • Delete — ask us to delete it.
  • Correct — ask us to fix inaccurate information.
  • Opt out of sale or sharing — we do not sell personal information. The only advertising-related disclosure is the campaign attribution you can decline or withdraw in our cookie banner, and we honor the Global Privacy Control signal as an opt-out from it (see "Global Privacy Control").

We do not use personal information for targeted advertising, and we do not disclose personal information to third parties for those parties' own direct-marketing purposes. Except for the MAS Direct Network and Hana Florist POS account credentials described above (stored only if a shop connects those integrations), we do not process "sensitive" personal information as those laws define it. We will not discriminate against you for exercising any of these rights.

What we collect, using the category labels these laws use:

CategoryCollected?Details
Identifiers (name, email, phone, IP address)YESWhen you email us or book a call; merchant contact details through the app; device identifiers and IP via analytics, only with consent; a campaign referral identifier, only with Advertising consent.
Commercial informationYESRecords of app subscriptions billed through Shopify; order statistics that do not identify shoppers.
Internet or other network activityYESWebsite usage data via Google Analytics, only with consent.
Geolocation dataApproximate onlyCity-level location inferred from IP address by Google Analytics, only with consent. We do not collect precise geolocation.
Protected classification characteristicsNO—
Biometric informationNO—
Audio, video, or other sensory dataNO—
Professional or employment informationNO—
Education informationNO—
Inferences or profiles drawn about youNO—
Sensitive personal informationYESMAS Direct Network and Hana Florist POS account credentials — stored only for shops that connect those integrations.

To exercise any of these rights, use the data-request form or email address in "Contact" below. We verify requests by corresponding with the email address you used or provided. If we decline a request, you may appeal by replying to our response, and we will review the appeal and answer within the same timeframes.

Your rights — EEA/UK

If the GDPR or UK GDPR applies to you, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to our processing;
  • receive your data in a portable format; and
  • withdraw consent at any time — turning Analytics off through Reject non-essential or Manage choices takes effect immediately.

You are never legally required to give us personal data. For merchants, some data — such as a Shopify sign-in session — is necessary to provide the app; without it, the app cannot run. We do not make automated decisions about you that have legal or similarly significant effects.

We are established only in the United States, and we offer the app to merchants in the United States and Canada. We have not appointed a representative in the EU or the UK under Article 27 of the GDPR/UK GDPR: we do not target EEA or UK residents, and any processing of their data is occasional, small in scale, and consent-based. We have not appointed a Data Protection Officer because we are not required to. Privacy questions go to info@nuflorist.com.

You also have the right to complain to your data protection authority — in the UK, the Information Commissioner's Office (ICO).

Your rights — Canada

We follow the fair-information principles of Canada's PIPEDA. In practice, that means:

  • we identify our purposes in this notice, before or when we collect information;
  • we collect, use, and disclose personal information only with your knowledge and consent, except where the law allows otherwise;
  • we limit collection to what those purposes require, and we do not keep information longer than necessary;
  • we keep information as accurate as its use requires and protect it with safeguards appropriate to its sensitivity; and
  • you can ask what personal information we hold about you and how it is used, ask us to correct it, and challenge our compliance.

The person in charge of the protection of personal information at Nuflorist, LLC (our privacy officer under PIPEDA and Quebec's Law 25) is Danny Sanchez, owner and CEO — info@nuflorist.com, 7500 NW 25th St, STE 212, Doral, FL 33122, USA. If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada.

Quebec. Quebec's Law 25 sets stricter rules, including opt-in consent. Our practices already work that way — nothing is collected on our website for analytics or marketing without your affirmative consent — and Quebec residents can exercise all of the rights above through the contact details below.

Global Privacy Control

If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to keep the Advertising purpose off: "Accept all" then enables Analytics only, and Advertising stays off unless you turn it on yourself in Manage choices. We do not sell personal information. We do not read the older "Do Not Track" header; analytics never starts unless you affirmatively enable it in our banner, with or without a browser signal.

Children

Our website and app are business tools. They are not directed to anyone under 18, and we do not knowingly collect personal information from minors. If you believe a minor has given us personal information, email info@nuflorist.com and we will delete it.

Changes

When we change this policy, we will update the "Last updated" date at the top and post the revised version on this page. If a change is material, we will flag it prominently here. The current version always governs.

Contact

  • Nuflorist, LLC
  • 7500 NW 25th St, STE 212, Doral, FL 33122, USA
  • info@nuflorist.com

To exercise any privacy right described in this notice, submit a request through our data-request form at app.termly.io/dsar/81c8d300-c742-4874-856a-9e78f1582cb5, or email info@nuflorist.com.

We respond to data requests without undue delay and within one month. If a request is complex, we may take up to two additional months; if so, we will tell you within the first month and explain why. Responding to your request is free of charge.

InstagramFacebookTikTokThreadsYouTubeLinkedIn
  • Features
  • Learn
  • Blog
  • Why Nuflorist
  • Pricing
  • Features
  • Learn
  • Blog
  • Why Nuflorist
  • Pricing
NuFlorist logo
  • Privacy Policy
  • Cookie Notice
  • Terms of Service
  • Refund & Cancellation Policy
  • Accessibility
  • Privacy Policy
  • Cookie Notice
  • Terms of Service
  • Refund & Cancellation Policy
  • Accessibility

Nuflorist, LLC, a Florida limited liability company · 7500 NW 25th St, STE 212, Doral, FL 33122, USA · info@nuflorist.com

Shopify and Shopify App Store are trademarks of Shopify Inc. Order Printer Pro, Hana Florist POS, and MAS Direct Network are trademarks of their respective owners; references describe integrations and do not imply endorsement.

© 2026 Nuflorist, LLC. All rights reserved.