Legal

Privacy Policy

This page explains the information ShowFi collects to operate the product, support customers, and improve the reliability of wallet-pass and reminder workflows.

Last updated: July 28, 2026

Information we collect

We collect account information, usage data, workflow configuration, and support communications needed to provide the service and maintain account security.

We also use analytics and advertising technologies, including Google Analytics and the Meta Pixel and Conversions API, to understand visits, measure advertising performance, and attribute actions such as registration, checkout, and purchase. These technologies may use cookies, browser identifiers, IP address, device information, and hashed account identifiers such as email address.

GoHighLevel integration data

When you install or connect ShowFi through GoHighLevel (also called HighLevel or LeadConnector), we receive and store OAuth access and refresh tokens; company, sub-account/location, app, installer, and plan identifiers; the locations selected for installation; and install or uninstall lifecycle metadata.

When a configured workflow runs, ShowFi may receive the GoHighLevel contact ID, location ID, name, email, phone number, event selection, and workflow fields you map. We use this data only to authenticate the integration, create and deliver wallet passes and claim links, write the configured ShowFi custom fields back to the matching contact, prevent duplicate processing, troubleshoot delivery, and provide support. ShowFi does not use GoHighLevel contact data to build advertising audiences.

How we use data

We use data to authenticate users, deliver product functionality, troubleshoot incidents, process billing, and communicate important service updates.

Data sharing

We share information only with service providers and integrations required to run ShowFi, process payments, or comply with legal obligations.

For advertising measurement, we may share website events and privacy-protected identifiers with Meta. We honor supported browser Global Privacy Control and Do Not Track signals by not loading Meta advertising tracking for that browser.

Integration and service data may be processed by infrastructure providers that help us host and secure ShowFi, including Vercel and Supabase, and by Apple or Google when a user chooses the corresponding wallet. GoHighLevel receives only the configured ShowFi custom-field updates and requests needed to operate or disconnect the integration. We do not sell GoHighLevel contact data.

Security

OAuth credentials are kept in server-side storage and are not exposed to the browser. We restrict database access, verify HighLevel lifecycle webhook signatures, use encrypted transport, request limited OAuth scopes, and delete usable credentials when a connection is removed. No system can guarantee absolute security.

Retention and access

GoHighLevel OAuth credentials are retained while the integration is connected and are deleted when you disconnect it in ShowFi or uninstall it in HighLevel. Authentication and lifecycle event metadata used for replay protection is retained for up to 90 days. Existing ShowFi events, wallet passes, registrant records, audit logs, billing records, and support communications are not automatically deleted by disconnecting an integration; they are retained while needed to provide your account, meet contractual or legal obligations, prevent abuse, and resolve disputes.

You may request access, correction, or deletion of account-related personal information by emailing us. We may need to verify the request and may retain information where law, security, fraud prevention, or an active contractual obligation requires it.

Contact

Privacy questions and deletion requests can be sent to hello@showfi.io.