MerchantWire SMS
Privacy Policy
How MerchantWire SMS processes Shopify and Twilio data for transactional order text messaging.
Effective September 27, 2026
Scope
This policy applies to MerchantWire SMS, a Shopify application offered by Advanced Computer Management. MerchantWire SMS is designed for transactional order-status messaging using a merchant's own Twilio account.
For customer/order data supplied by a Shopify merchant, the merchant remains responsible for its relationship with its customers and for the lawful collection and use of that data. MerchantWire SMS processes that data only to provide the requested application functions, subject to the merchant's configuration and Shopify/Twilio requirements.
Information MerchantWire SMS processes
- Shopify store identity, installation state, billing/entitlement state, locale, locations, orders, fulfillment context and app configuration needed to operate the service.
- Customer name when a merchant enables a greeting that uses it.
- Customer or order phone number used to verify the destination and send transactional text messages.
- Transactional consent evidence, including consent state, timestamp, source, country, locale and disclosure/profile version.
- Operational message metadata such as message type, schedule, Twilio Message SID, delivery state, failure category and timestamps.
- Twilio Account SID, API Key SID, Messaging Service configuration and encrypted Twilio credential material supplied by the merchant.
- Short-lived security/diagnostic information needed to operate and protect the service, including a keyed one-way fingerprint of a merchant-controlled test handset while the guided STOP/START/HELP verification is active. The raw test number is not stored in that verification record, and the fingerprint is cleared when the check completes, expires, restarts, or is invalidated.
Information MerchantWire SMS does not intentionally retain
- Rendered SMS message bodies in the MerchantWire application database.
- Customer email addresses or postal addresses as application data for this release.
- Raw Shopify or Twilio webhook payload archives.
- A historical guest-customer phone index.
- Twilio master Auth Tokens as the normal integration credential.
How information is used
MerchantWire SMS uses the information above to authenticate the merchant, verify subscription access, connect Shopify and Twilio, manage consent, render and schedule transactional messages, process supported replies, reconcile provider delivery status, show message history, respond to Shopify privacy requests, prevent duplicate or stale sends, and operate/support the service.
Service providers and integrations
MerchantWire SMS depends on Shopify for commerce/store data and app distribution, Twilio for SMS delivery and sender controls, Laravel Cloud infrastructure for the application runtime and managed data services, and Cloudflare for the public Advanced Computer Management website and related edge services. Those providers process information under their own terms and privacy commitments.
Retention
Operational scheduled-message, delivery, reply-schedule, webhook-receipt and related message-history records are generally retained for up to 30 days after their retention clock begins, then purged. Completed or revoked U.S. enrollment-confirmation coordination records are also purged after 30 days. Pending work remains only while needed to complete or safely resolve the operation.
MerchantWire SMS may retain daily non-customer aggregate activity counts longer so merchants can view current-year activity. Those aggregates do not contain phone numbers, customer identifiers, Shopify order identifiers/numbers, SMS bodies, Twilio Message SIDs or raw provider payloads. Security/system logs are designed to be redacted and are retained for up to 90 days unless a verified security, contractual or legal requirement requires a different period. Backup/recovery history is limited to the approved operational recovery window and is not intended as a hidden long-term archive.
Consent, STOP, START and HELP
MerchantWire SMS separates transactional/order-status consent from marketing consent. New storefront transactional consent is an affirmative choice. Twilio Advanced Opt-Out remains part of sender-level enforcement. STOP and START are used to stop/resume supported messaging behavior, while HELP provides configured support information and does not itself change consent state.
Shopify privacy requests and deletion
MerchantWire SMS supports Shopify's mandatory customer data request, customer redaction and shop redaction workflows. Data-request exports contain only currently retained MerchantWire operational records associated with Shopify-supplied customer/order references. Customer/shop redaction removes applicable MerchantWire records, and shop redaction removes the tenant record and dependent data.
Security
MerchantWire SMS uses encrypted application secrets, signed Shopify/Twilio webhook validation, tenant isolation, authenticated Shopify sessions, private/no-store API responses, restricted public endpoints, redacted logs, and deployment/runtime checks intended to prevent cross-store access and accidental disclosure. No internet service can guarantee absolute security.
International processing
MerchantWire SMS supports merchants in multiple countries. Depending on the merchant, customer and service-provider locations, information may be processed in the United States or other countries where the providers operate. Merchants are responsible for using MerchantWire SMS consistently with the privacy and communications laws that apply to their business and customers.
Your choices and rights
Customers should normally contact the Shopify merchant they purchased from to exercise privacy rights regarding order/customer data. Merchants can contact MerchantWire support for application-level privacy or deletion questions. Where applicable, requests may also be routed through Shopify's privacy workflow.
Changes
Advanced Computer Management may update this policy as MerchantWire SMS changes or legal/operational requirements evolve. The effective date above will be updated when material changes are published.
Contact
For MerchantWire SMS privacy questions, email hello@acmtechlab.com. Do not include API secrets, access tokens, customer phone numbers, SMS bodies, raw webhooks or database exports in ordinary support email.