Bloom
FeaturesHow it worksPricingFAQ
Sign in
FeaturesHow it worksPricingFAQSign in

Legal

Privacy Policy

Last updated 11 October 2026

Bloom collects the smallest set of data that makes a referral program work, and nothing about the shoppers who buy through it beyond the order id and total.

On this page

Who we areData about merchantsData about ambassadorsData about shoppersHow we use dataWho we share data withHow long we keep itYour rightsSecurityCookiesChildrenChanges and contact

Who we are

Bloom is an ambassador and referral program for Shopify stores, operated by CATS22 LLC ("CATS22", "we", "us"). This policy explains what personal data Bloom handles, why, and what rights you have.

It covers three groups of people: merchants who install Bloom on their Shopify store, ambassadors who apply to or join a merchant's program, and shoppers who buy through an ambassador's link.

For a merchant's program, the merchant is the data controller and Bloom processes data on their behalf. For the Bloom website and your account with us, CATS22 is the controller.

Data about merchants

When you install Bloom we receive, through Shopify, the information needed to run the app for your store:

  • Your store's domain, name, storefront URL and the branding you have set in Shopify (logo, colours, slogan, policy links). This builds your ambassador portal.
  • An access token that lets Bloom act on your store within the permissions you approved at install: read orders, read products, manage the program's discount and ambassador codes, manage URL redirects, serve ambassador pages inside your theme, read your legal policies, and read customers.
  • Customer records, read on demand and only inside your admin: when you search for a customer to add as an ambassador, or open "Invite best customers", Bloom reads names, email addresses, order counts, amount spent and last order date from Shopify to show you the list. Bloom does not copy your customer list. A customer's name, email and customer id are stored only when you add that person as an ambassador.
  • Settings you enter in the app: discount percentage, reward milestones, featured collection, portal text and colours, optional portal hostname.
  • If you connect Klaviyo, your private API key. It is encrypted at rest (AES-256-GCM) and only ever used to send the events you enabled.

Data about ambassadors

When you apply to a brand's program on its Bloom portal, or a merchant enrols you, Bloom stores what is needed to run your page and let the brand send your rewards:

  • Name and email address (used to sign you in with a magic link and to tell you about rewards).
  • Your Shopify customer id, if the merchant linked your ambassador record to a customer account.
  • The handle and discount code chosen for you, and the content you publish on your page: message, review, featured product, video link, avatar.
  • Social handles if you provide them. These are optional.
  • Activity on your link: a count of clicks (with a hashed IP and browser string kept for fraud checks), the orders attributed to you (order id, order number, order total and date), and the rewards you have earned.

Bloom does not show you, or store, the names or addresses of the people who buy through your link.

Data about shoppers

If you buy from a store through an ambassador's link, or with an ambassador's discount code, the store's checkout records which ambassador sent you. When the order is paid, Shopify sends Bloom the order id, order number, order total, that referral marker, any discount codes used, and the email address on the order. The email is used for one check, in memory: if it matches the ambassador's own email the order is not credited (self-referral). It is not stored. Bloom stores the order id, order number, total and date against the ambassador, and nothing that identifies you. Bloom does not receive your postal address, phone number or payment details.

The referral discount is applied by a Shopify Function running inside Shopify's checkout; it reads the referral marker or the code you typed, and the store's configured percentage, and nothing else.

If you are already a customer of a store, the merchant may see you in a list of their own repeat customers inside Bloom and invite you to their program. That list is read from the merchant's Shopify records at that moment and is not kept by Bloom.

How we use data

  • To run the program: build the portal, attribute orders, apply the discount, count milestones and notify rewards.
  • To sign people in: magic links sent to the ambassador's email; a signed cookie keeps the session.
  • To prevent abuse: hashed click data, and a self-referral check that compares the email on a referred order with the ambassador's email without storing it.
  • To support merchants: answering questions and investigating problems.

We do not sell personal data, use it for advertising, or train models on it.

Who we share data with

RecipientWhatWhy
ShopifyStore settings, discounts, redirects, order webhooks; for billing, the dollar amount of each credited order or refund (no shopper details)Bloom runs on the Shopify platform, and Shopify calculates and collects Bloom's fee
Supabase (database, US West)Everything Bloom storesHosting the database
Railway (application hosting, US West)Requests to Bloom while they are processedRunning the app
Resend (email delivery)Ambassador or staff email address, name and the message being sentSign-in links, welcome messages, briefs, and order and reward notices, when the merchant uses Bloom's own email
Google Analytics (this website's public pages only)The page viewed, the page you came from, approximate location, browser and device type, and a few actions such as following an install linkCounting visits to the home page and policy pages. Not used in the app or the ambassador portal
Klaviyo (only if a merchant connects it)Ambassador email, name and program eventsThe merchant's own email flows
Shopify Flow (only if a merchant builds a workflow)The ambassador's customer reference, name, email, link and codeThe merchant's own automations inside Shopify

Each processor is bound by its own data processing terms. We will disclose data if the law requires it, and we will tell the affected merchant unless we are prohibited from doing so.

How long we keep it

  • Merchant data stays while Bloom is installed. When a store uninstalls Bloom, Shopify sends a redaction request 48 hours later and Bloom deletes the store's record and every ambassador, click, conversion and reward attached to it.
  • Ambassador data stays for the life of the merchant's program or until the ambassador or merchant asks for it to be removed. On request Bloom anonymises the record: name, email, socials, content and linked customer id are erased and the click log deleted. See Data deletion.
  • Logs on our hosting provider are kept for 30 days.

Your rights

Depending on where you live you may have the right to access, correct, export, restrict or delete personal data about you, and to object to certain processing. Ambassadors can edit their own page and details from the portal at any time.

If you are an ambassador or shopper, the quickest route is the merchant whose store you dealt with: they can act in the app directly, and Shopify forwards customer requests to Bloom automatically. You can also write to us at mariano@cats22.agency and we will respond within 30 days.

If you are in the EEA or UK you can also complain to your local supervisory authority.

Security

Bloom runs over HTTPS only. Third-party credentials merchants connect are encrypted at rest with a key held outside the database. Shopify webhooks are verified by signature before they are processed. Access to production systems is limited to CATS22 staff who need it, protected by two-factor authentication.

No system is perfectly secure. If we learn of a breach affecting your data we will notify the affected merchants without undue delay so they can inform their ambassadors and customers.

Cookies

The ambassador portal and the store owner sign-in each set one cookie: a signed session so you stay logged in after using a sign-in link.

The public pages of this website (the home page and these policy pages) use Google Analytics to count visits. It sets analytics cookies, except for visitors in the European Economic Area, the United Kingdom and Switzerland, where it runs without cookies. It is not loaded in the Shopify app, in the ambassador portal, on the sign-in pages, or on ambassador pages inside a store's theme.

Bloom does not use advertising cookies.

Children

Bloom is for merchants and their adult ambassadors. We do not knowingly collect data from anyone under 16. If you believe a minor has joined a program, contact us and we will remove the record.

Changes and contact

We will post changes to this policy here and update the date at the top. Material changes will be announced to installed merchants in the app.

CATS22 LLC · mariano@cats22.agency

Bloom

Built by CATS22. An ambassador and referral program for Shopify brands.

Product

FeaturesHow it worksPricingFAQ

Account

Sign inShopify App StoreSupport

Legal

Privacy PolicyTerms of ServiceData Deletion

Contact

mariano@cats22.agencybloom.cats22.agency

© 2026 CATS22 LLC