Effective July 23, 2026
Bloomly is a Shopify app built and operated by Nehemiah Apps ("Nehemiah Apps," "we," "us"). This policy describes the personal data Bloomly processes when a merchant installs it on their Shopify store, why we process it, and the rights available to the people that data belongs to.
Bloomly is installed by merchants ("you," the merchant) to manage their own customers' orders. In most cases, the merchant is the data controller and Nehemiah Apps acts as a data processor on the merchant's behalf — see our Merchant Data Protection Agreement for that relationship.
Bloomly captures the following as part of its core function — adding structured recipient details to flower orders and printing gift cards:
We process only the data required to provide the above functionality — we do not collect browsing behavior, run advertising, or build profiles for any purpose beyond order fulfillment and the specific features described here.
We never sell personal data, and we never use it for advertising or marketing on our own behalf.
Recipient phone number, card message, and any custom field values are automatically deleted 90 days after an order is marked Completed in the merchant's dashboard.
Buyer identity (customer ID, email, name) used for occasion reminders is retained longer than 90 days by design — recognizing an annual occasion requires roughly a year of order history. This is a deliberate, purpose-limited retention period, not indefinite storage: an explicit deletion request (see below) removes it immediately regardless of how recently it was collected.
We share personal data only as needed to provide the service:
We do not share personal data with any other third party, and we do not sell it.
All data in transit between the buyer's browser, the merchant's admin, and our servers is encrypted (HTTPS/TLS). Recipient and sender details, card messages, and buyer identity are also encrypted at rest in our database. We apply security measures appropriate to the nature of the data we process, but no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Bloomly operates on top of Shopify's platform and relies on the subprocessors described above. We are not responsible for the independent privacy or security practices of Shopify or any other third-party service not operated by us, and we encourage you to review their own policies.
Nehemiah Apps is based in the Philippines, and personal data processed through Bloomly may be stored or processed there and in other countries where our hosting provider or other subprocessors operate. By using or interacting with Bloomly, you acknowledge that your data may be transferred to and processed in countries with data protection laws different from those in your own country, to the extent permitted by applicable law.
Bloomly implements Shopify's mandatory data protection webhooks:
Depending on where you're located, you may have additional rights under applicable law (for example, the Philippine Data Privacy Act of 2012 for data processed in the Philippines, or the GDPR for data originating in the EU/UK) — including the right to access, correct, or object to the processing of your personal data. To exercise any of these rights, contact the merchant you ordered from directly, or reach us at support@nehemiahapps.com and we'll assist.
Bloomly is not directed at children and we do not knowingly collect personal data from children.
We'll update the effective date above if this policy changes, and post the updated version at this same address. Continued use of the app after a change takes effect constitutes acceptance of the updated policy.
This policy is governed by the laws of the Republic of the Philippines, without regard to conflict-of-law principles, except where applicable data protection law requires otherwise for data originating outside the Philippines.
Nehemiah Apps
support@nehemiahapps.com