Last updated 23 September 2026
Scheduly Content Block is operated by Understory. It helps Shopify merchants schedule announcements, banners and promotional content. This policy describes how the app handles information.
We store your Shopify store domain, timezone, installation status, access credentials, placements, campaign content, schedules, publication history and operational audit records. Content may include text, image URLs and links you supply. Please do not put confidential or personal information in promotional content intended for public display.
To let you choose a banner image without leaving the app, we request access to your store's files. With your permission the app lists the images in your Shopify file library and, when you upload one, sends it directly from your browser to Shopify. Image files are never stored on our servers; we keep only the resulting image URL as part of your campaign content.
The app does not request customer or order access. We do not collect customer profiles, orders or payment-card details. If you contact support, we receive your email address and the information you choose to send.
We use this information to authenticate your store, save and publish schedules, provide support and diagnose errors. Cloudflare Workers hosts the app and Cloudflare D1 stores its database. Published schedules and content are also written to app-owned metafields in your Shopify store so your storefront can display them.
The theme extension runs JavaScript to choose and display scheduled content. It does not send shopper profiles or shopping activity to our backend. Images and links supplied by merchants may contact their respective hosts, which have their own privacy practices. The admin interface saves the theme-setup checkbox in browser local storage.
Where paid plans are enabled, Shopify handles plan selection and payment. We use subscription information to apply the selected plan’s limits. We do not receive payment-card details.
Shopify and Cloudflare process data needed to provide the service. Hosting providers may process technical request information, including IP addresses, for delivery, security and diagnostics. Support email is handled through Gmail. Data may be processed in countries where these providers operate. We do not sell merchant or shopper information or use it for advertising.
Access is authenticated through Shopify, and requests are scoped to the store. Access credentials are kept on the server. No method of storage or transmission is completely secure.
We keep app configuration and history while providing the service. Uninstalling removes stored access credentials. Store configuration can remain briefly until Shopify sends its shop-redaction request; that request deletes the store’s app database records. Shopify controls removal of app-owned metafields. Infrastructure logs and backups follow the hosting provider’s retention processes.
To request access, correction or deletion of information we hold, contact us below. We may ask you to verify your connection to the store. Depending on where you live, you may have additional privacy rights or the right to contact your local data-protection authority.
We publish updates here with a revised date. For privacy questions or requests, email support.understory@gmail.com.