Always On CommerceAlways On Commerce

Legal

Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how Always On Commerce collects, uses, shares, and protects personal information when you visit our sites, use our dashboard, connect integrations, or participate in experiences powered by Always On Commerce.

Always On Commerce acts as a controller for platform, account, and experience data we decide how to use. For merchant catalog and order data synced under a store’s instructions, and for campaign attribution delivered to that merchant, Always On Commerce typically acts as a processor or service provider.

Overview

Always On Commerce operates a commerce media and attribution network for brands, agencies, and partners. This policy applies to: (1) visitors to our marketing and product sites; (2) merchants, agencies, and dashboard users; and (3) consumers who interact with Always On Commerce-powered experiences (reels, swipe, forms, embeds, claim flows, and checkout handoffs).

White-label or co-branded sites that use Always On Commerce still process data under this policy unless a separate notice is posted.

This policy does not cover third-party merchant checkout pages, payment processors, or storefronts after you leave a Always On Commerce experience.

Who controls your information

Controller. For information we collect for our own purposes (account registration, platform security, product analytics, phone verification for Always On Commerce-issued promotions, session and identity linking on Always On Commerce experiences, and support), Always On Commerce determines the purposes and means of processing.

Processor / service provider. When a merchant connects Shopify (or another commerce tool) and instructs Always On Commerce to sync catalog or order data, or to attribute campaigns to that merchant, Always On Commerce processes that merchant customer and store data on the merchant’s behalf. The merchant remains responsible for its storefront privacy notice and for decisions about what to sync.

If you are a consumer interacting with a brand experience, both Always On Commerce (for verification, session, and platform operation) and the sponsoring brand (for offer rules and post-checkout relationship) may process information related to that campaign.

Information we collect

Account and business data. Name, email, organization details, authentication identifiers (for example Google OAuth), workspace membership, and support messages.

Phone verification. When you claim an offer, we collect your phone number in E.164 format to send a one-time verification SMS. We store a durable hashed form of the phone number (SHA-256 phone hash) to enforce eligibility, prevent duplicate claims, issue coupons, and link identity across sessions. Raw phone numbers are processed as needed for OTP delivery and issuance; we do not put raw phone numbers or email addresses into analytics event properties or error-tracking payloads.

Sessions and identifiers. Always On Commerce session identifiers, PostHog distinct and session IDs, IP address, device and browser type, referral URLs, and interaction events on sites and experiences.

Coupons, checkout, and attribution. Coupon codes, issuance and redemption metadata, checkout session identifiers, UTM and Always On Commerce campaign parameters, and normalized order or transaction snapshots used for attribution.

Forms and handoffs. Fields you enter on Always On Commerce forms or interest flows (which may include name, email, phone, or other survey answers). Some answers are passed to merchant websites as query parameters; server retention of form answers may be limited depending on the experience.

Shopify and commerce APIs. When a merchant installs and authorizes our app, we may receive product and variant catalog data, order and paid-order webhooks, draft-order and discount-code data needed to run checkout handoffs and promotions, and OAuth shop tokens stored encrypted. We do not receive or store payment card numbers from Shopify checkout; cards are handled by Shopify or the merchant’s payment provider.

Integrations. Encrypted connection credentials and metadata for connected tools (for example social or media sources used to build brand profiles).

How we use information

We use personal information to: operate and improve the Always On Commerce (catalog, distribution experiences, identity graph, and integrations); authenticate users; send transactional verification SMS; issue and validate coupons; create checkout handoffs with attribution metadata; sync and normalize catalog and order data for campaign measurement; provide support; prevent fraud and abuse; comply with law; and measure product and campaign performance.

We may use aggregated or de-identified data for analytics and product development. Verification SMS messages are transactional and tied to the offer claim flow.

Cookies and similar technologies

We use cookies, local and session storage, and analytics tools for security, preferences, and measurement.

Examples include: authentication and session cookies for the dashboard; workspace or invite cookies; white-label OAuth handoff cookies; experience instruction-overlay cookies (for example dismissal of first-run controls); sessionStorage for swipe likes or verified credit within an experience; and PostHog cookies or identifiers for product analytics and related session linkage.

Session replay/recording is disabled in our application PostHog initialization by default. If your browser sends a Global Privacy Control (GPC) signal, we attempt to opt that browser out of PostHog capturing.

API requests may carry Always On Commerce session and PostHog headers so server lifecycle events can join to the same person or session after verification.

You can control cookies through browser settings. Disabling cookies may break login, experiences, or analytics.

How we share information

We share information with service providers that help us operate the platform, including: hosting and databases (for example Vercel and Postgres/Supabase-class infrastructure); SMS delivery (Twilio or similar); product analytics and error tracking (PostHog); and commerce platforms (Shopify) when a merchant connects a shop.

We share promotion, verification, and attribution data with the merchant or agency running a campaign so they can fulfill offers, prevent abuse, and measure results. Our identity graph links sessions to verified people for fraud prevention, eligibility, and campaign attribution, not to sell personal information for third-party cross-context behavioral advertising.

We may disclose information if required by law, to respond to lawful requests, or to protect rights, safety, and platform integrity.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are commonly defined under U.S. state privacy laws. See California privacy choices for GPC and Do Not Sell or Share requests.

Data retention

We retain personal information only as long as needed for the purposes described above, including to provide services, meet legal obligations, resolve disputes, and enforce agreements.

Verification challenges and one-time codes are short-lived. Phone hashes, coupon issuances, and attribution records are kept for campaign measurement, fraud prevention, and legal retention needs. Connected-shop data is retained while the integration remains active and for a reasonable period afterward for attribution, audits, and legal compliance.

Our Shopify app implements mandatory compliance webhooks (customers/data_request, customers/redact, and shop/redact). Merchants who uninstall, or individuals seeking deletion, may also contact support@rallynetwork.io. We process verified requests consistent with law and merchant-processor obligations. Order payloads stored for attribution are sanitized to remove customer email, phone, and address fields.

Security

We use administrative, technical, and organizational measures designed to protect personal information, including encrypted storage of integration tokens and access controls on production systems.

No method of transmission or storage is completely secure. You use the services at your own risk regarding residual security risk.

Your choices and rights

Depending on where you live (including the EEA, UK, and certain U.S. states such as California), you may have rights to: access or know the personal information we hold; correct inaccurate information; delete information; portability; restrict or object to certain processing; and appeal a denied request where required.

California-specific disclosures appear in the California privacy choices section.

To make a privacy request, email support@rallynetwork.io. We may need to verify your identity (and, for merchant customer data we process only as a service provider, may direct you to the merchant or coordinate with them).

You may also control cookies via your browser and opt out of marketing messages using the instructions in those messages (STOP for SMS where offered).

California privacy choices

California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and not be discriminated against for exercising privacy rights.

We do not sell personal information or share it for cross-context behavioral advertising as described in this policy. If you believe your information is subject to a Do Not Sell or Share request, email support@rallynetwork.io with “California privacy request” in the subject line. We honor Global Privacy Control (GPC) signals in supported browsers by opting that browser out of PostHog capturing where our client instrumentation is active.

Authorized agents may submit requests as permitted by law; we may require proof of authority and identity verification.

Children

Our services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. Consumer reward flows require the age of majority (or 18, whichever is higher) as described in our Terms.

If you believe we have collected information from a child, contact support@rallynetwork.io and we will take appropriate steps.

International transfers

Always On Commerce is based in the United States. If you access the services from outside the United States, your information may be processed in the United States or other countries where we or our providers operate.

Those countries may have different data-protection rules than your home country. Where required, we use appropriate safeguards for cross-border transfers.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the last updated date.

Material changes may also be communicated through the dashboard or other appropriate channels.

Contact

Privacy questions and data-subject requests may be sent to Always On Commerce at support@rallynetwork.io. Enterprise customers may request our Data Processing Addendum (DPA) and a Master Services Agreement (MSA) at the same address.