Legal
Privacy Policy
Effective September 28, 2026
In short
- CleverBooster builds Shopify apps and runs cleverbooster.com. We are based in District 12, Ho Chi Minh City, Vietnam.
- This policy covers cleverbooster.com, CB - Advanced Form Builder Pro, CBmap Store Locator & Stockist, and CB Booking Rentals & Tickets.
- For customer data inside our Shopify apps, the merchant is the controller and Clever Booster is the processor.
- We use personal data only to run the website, provide the apps, support merchants, send app messages, and keep each store's data separate.
- We do not sell personal data, use it for advertising or cross-site tracking, or combine data across merchants.
- Some app features send data to Shopify, map providers, email providers, storage providers, and merchant-enabled integrations.
Who we are
Clever Booster, also styled CleverBooster, is a small product team based in District 12, Ho Chi Minh City, Vietnam. We build Shopify apps and custom development projects. You can contact us at admin@cleverbooster.com.
This policy covers cleverbooster.com and three Shopify apps: CB - Advanced Form Builder Pro, CBmap Store Locator & Stockist, and CB Booking Rentals & Tickets. Custom development work is governed by the written agreement for that project.
1. Website
Our website, cleverbooster.com, is a simple company and app website. It has no analytics, no advertising, no tracking cookies, no contact form, and self-hosted fonts. If you want to contact us, you email us directly.
The website is hosted on Cloudflare. Cloudflare may process visitors' IP addresses and may set strictly necessary security cookies to deliver and protect the site.
2. Form Builder Pro
CB - Advanced Form Builder Pro lets Shopify merchants build storefront forms such as contact, registration, wholesale, survey, application, and customer approval forms.
Merchant and staff data
We process Shopify shop and session data, including shop domain, access tokens, scopes, staff user information, shop name, merchant email, timezone, plan information, counters, app settings, support requests, and merchant-configured SMTP settings. We use this to authenticate the merchant, run the embedded Shopify app, sync plan and scope changes, send app and support messages, and show the merchant their forms and submissions.
Customer and visitor data
Form definitions can include titles, descriptions, custom fields, conditional rules, reCAPTCHA settings, design settings, custom CSS or JavaScript, restrictions, tags, and capture settings chosen by the merchant. Form submissions may include the values a visitor enters, such as name, email, phone, address, note, tags, marketing consent, file uploads, Shopify customer id, submitted page URL and title, IP address, browser id, timestamps, status, and other answers configured by the merchant.
The storefront widget uses the visitor's browser localStorage to cache form JSON for a short time and, when the merchant enables editable submissions, to let the visitor edit a recent submission until the merchant's edit window expires. This is not advertising or cross-site tracking.
If a form uses Google reCAPTCHA, Google's reCAPTCHA script loads in the visitor's browser and the server verifies the token with Google. The widget also loads flatpickr assets from cdnjs when date fields need them. Those providers receive the visitor's IP address when their resources load.
Integrations
Form Builder can send submission data to integrations only because the merchant configured them. These include Mailchimp, Klaviyo, Zendesk, Slack, HubSpot, Segment, Amplitude, Iterable, and custom SMTP. The data then goes to the merchant's own account and is handled under that provider's terms.
3. CBmap Store Locator
CBmap Store Locator & Stockist lets Shopify merchants show store locators and stockists on Google Maps, Mapbox, or OpenStreetMap, manage locations, import locations, display search and filters, and review locator analytics where available.
Merchant and staff data
We process Shopify shop records, Shopify access tokens, company account details, merchant/store name, address, domains, timezone, latitude and longitude, plan name, map provider settings, Google Maps API key, Mapbox API key, staff names, staff email addresses, staff roles, staff access tokens, support requests, and Google Sheets sync details when the merchant uses that feature.
Storefront visitor and lead data
Location records can contain store or stockist names, addresses, phone numbers, email addresses, URLs, images, social links, opening hours, latitude and longitude, filters, actions, and custom fields that the merchant enters.
The storefront analytics store IP address and browser user agent for location-page views. They also store page URL, search terms, approximate location information such as city, state and country, latitude and longitude when available, closest location, and click counts. The storefront lead form stores name, email, phone, message, page URL, website, search query, latitude, longitude, and IP address.
The storefront widget uses localStorage for caching account data, regions, place predictions, geocodes, current browser geolocation, selected map provider, and recent request responses. This is not advertising or cross-site tracking.
Google Maps, Mapbox, OpenStreetMap and related map assets may receive the visitor's IP address when map resources load. The merchant may use their own map provider account and API keys, and those providers handle that data under their own terms.
4. CB Booking
CB Booking Rentals & Tickets lets Shopify merchants sell and manage appointments, rentals, event bookings, deposits, balances, waitlists, reminders, notices, staff access, and self-service changes through their Shopify store.
Merchant and staff data
We process Shopify store information such as store name, contact email, store address, timezone, currency, Shopify order and booking data, and app configuration. If the merchant connects them, we store credentials or API keys for Google Calendar, Microsoft Outlook, Zoom, Klaviyo, Google Analytics, or the merchant's own SMTP server. Calendar and video credentials are stored encrypted. For the optional staff portal, we process staff email addresses and hashed passwords.
Customer data
When a customer books through a merchant's store, booking page, self-service portal, or point of sale, we store name, email address, phone number, booking details such as service, date and time, attendees, price, deposit and payment status, answers to merchant booking questions, customer notes, and the device timezone used only to display times. Waitlists store the same contact details and requested date. We do not store payment card details; Shopify processes payments. We do not collect customer addresses for Booking.
Copies of booking emails, SMS, and WhatsApp messages are kept so merchants can see what was sent and resend it. For CB Booking, those notification copies are erased after 12 months.
Optional AI features
CB Booking's AI features are off by default. If a merchant enables them, booking notes or waitlist messages may be sent to TypeSafe to suggest a category for staff, and the name, email, and phone from two bookings may be compared to suggest that they belong to the same customer. These features only make suggestions to the merchant and never make automatic decisions about customers.
Integrations
CB Booking sends data to integrations only as needed for the feature or because the merchant connected the provider. This can include Shopify, our hosting provider, email delivery, Twilio for SMS or WhatsApp, Google Calendar, Microsoft Outlook, Zoom, Klaviyo, Google Analytics, TypeSafe, and the merchant's SMTP provider.
5. Our role and the merchant's role
For data about Shopify merchants, staff, website visitors who contact us by email, and people who visit cleverbooster.com, we are responsible for how we use that data.
For customer and storefront visitor data processed through a merchant's Shopify store, the merchant decides what data to collect and why. The merchant is the controller, and we act as the merchant's processor by running the app features they choose to use. Customers should contact the merchant first to access, correct, or delete their data.
6. Sharing and sub-processors
We share personal data only to provide the website and apps, support merchants, comply with law, or follow the merchant's settings.
| Recipient | Data | When |
|---|---|---|
| Shopify | Shop, session, billing, customer, order, app, webhook, and API data needed by the apps | When a merchant installs or uses a Shopify app |
| Hosting and database provider | Website and app data stored or processed by our servers and databases | To run the website and apps |
| Email delivery (SMTP) provider | Email addresses, message content, and delivery metadata | When app, lifecycle, support, customer, or merchant emails are sent |
| File storage (Amazon S3 / S3-compatible) | Uploaded files, images, icons, object keys, filenames, content types, metadata, and file sizes | When merchants or storefront visitors upload files, images, icons, or attachments |
| Cloudflare | Website visitor IP address and strictly necessary security cookie data | When someone visits cleverbooster.com |
| Google reCAPTCHA | Visitor IP address and reCAPTCHA token data | When a Form Builder form uses reCAPTCHA |
| cdnjs | Visitor IP address and resource request data | When Form Builder loads date-field assets from cdnjs |
| Google Maps, Mapbox, OpenStreetMap, Leaflet, and Google Fonts | Visitor IP address, map requests, geocoding or place data, and resource request data | When CBmap loads maps, geocoding, place prediction, map assets, or configured fonts |
| Google Sheets and Google Drive | Location spreadsheet data, file IDs, revision data, and shared member email addresses | Only when a CBmap merchant uses Google Sheets sync |
| Twilio | Customer phone number, SMS or WhatsApp message content, and delivery metadata | Only when a CB Booking merchant enables SMS or WhatsApp notifications |
| Google Calendar, Microsoft Outlook, and Zoom | Booking details and connected-account data | Only when a CB Booking merchant connects their own account |
| TypeSafe | Booking notes, waitlist messages, and names, emails, and phone numbers used for duplicate-customer suggestions | Only when a CB Booking merchant turns on optional AI features |
| Mailchimp, Klaviyo, Zendesk, Slack, HubSpot, Segment, Amplitude, Iterable, Google Sheets, Google Analytics, and custom SMTP | Submission, notification, lead, analytics, booking event, or contact data selected by the merchant | Only when the merchant connects or configures that integration under the merchant's own account and provider terms |
7. Retention and deletion
We keep app data while needed to provide the app to the merchant, support the merchant, and meet legal or operational needs. Some exact retention periods are controlled by the app feature or the merchant's settings.
For Form Builder Pro, uninstall deletes Shopify sessions, deactivates the shop, and clears the active plan. When Shopify sends customers/redact, matching submissions are redacted and uploaded files are purged. When Shopify sends shop/redact after uninstall, uploaded submission files are purged and submission rows are deleted. Form definitions are kept. For customers/data_request, we provide matching submission data to the merchant on request.
For CBmap Store Locator, when you uninstall the app your account is deactivated and its data is kept, so your locations and settings come back if you reinstall. When Shopify sends us a shop/redact request after an uninstall, or a customers/redact request for a shopper, or when you ask us by email, we delete that store's or that shopper's data, including locations, leads, analytics records and uploaded images, within 30 days.
For CB Booking, booking data is kept while the merchant uses the app so the merchant can keep business records. Temporary booking holds expire automatically within minutes. Notification copies are erased after 12 months, access records after 12 months, and encrypted backups after 30 days. When Shopify sends customers/redact, we erase the customer's name, email, phone, notes, booking answers, related AI suggestions, and copies of messages sent to them, while keeping only an anonymous booking record. When a merchant uninstalls CB Booking, all of that store's data is deleted within 48 hours after Shopify's shop/redact notification.
For the website, we do not run analytics or collect form submissions. If you email us, we keep the email as long as needed to respond and keep business records.
8. Security
We use Shopify authentication for embedded app access. We keep store data separated by shop. Access to production data is limited to our team and used to operate, support, and protect the apps. App and website traffic uses HTTPS in transit. Some app features also use signed URLs, private file storage, domain checks, scoped API queries, and provider authentication.
For CB Booking, data is encrypted in transit with HTTPS/TLS, including the database connection, backups are encrypted, calendar and video-conferencing credentials are encrypted in our database, passwords and login links are stored only as hashes, access to customer personal data is logged for 12 months, and affected merchants will be notified without undue delay and no later than 72 hours after we confirm an incident affecting personal data.
No method of transmission or storage is perfect. If you believe there is a security issue, contact us at admin@cleverbooster.com.
9. International transfers
We are based in Vietnam and use service providers that may process data in other countries. By using our website or installing our apps, data may be processed in Vietnam and in the countries where Shopify, our infrastructure providers, and merchant-enabled providers operate.
10. Your rights
If you shopped at, submitted a form on, found a location through, or booked with a merchant's store, contact that merchant first. The merchant controls the storefront data and can use Shopify's privacy tools or contact us for help. Merchants, staff, and website visitors can email us at admin@cleverbooster.com to ask for access, correction, deletion, export, or objection where applicable. People in the EEA, UK, and California may have additional privacy rights under GDPR, UK GDPR, CCPA, CPRA, and similar laws, depending on their location and role.
11. Children
Our website and apps are for Shopify merchants and their stores. They are not directed to children. Merchants are responsible for deciding whether their storefront forms, locators, bookings, and notices are appropriate for their customers.
12. Changes
We will update this page when our practices change and will post the new effective date at the top.
13. Contact
Clever Booster, District 12, Ho Chi Minh City, Vietnam. Email: admin@cleverbooster.com.
Questions about this page? Email admin@cleverbooster.com.