Privacy Policy
Privacy Policy
Section titled “Privacy Policy”This Privacy Policy explains how data is handled when merchants install and use the app, and when visitors view pages published with it.
By installing or using the app, you acknowledge this Privacy Policy.
1. What this policy covers
Section titled “1. What this policy covers”This policy covers data processed through app features, including:
- page, template, and style content created in the app,
- store data read from Shopify to power page components,
- storefront view measurement for pages published with the app,
- app authentication, configuration, and support communications.
This policy does not replace Shopify platform policies, your own store privacy policy, or the policies of any third-party service you choose to connect.
2. Roles and responsibilities
Section titled “2. Roles and responsibilities”- Merchant (store owner): controller for the store data and published content handled in the store context.
- App provider: processor / service provider operating the page building and rendering service on behalf of the merchant.
- Staff users: authorized users acting under the merchant’s Shopify account.
3. No shopper personal data is collected
Section titled “3. No shopper personal data is collected”The app does not collect, request, or store personal data about your shoppers.
The app has no access to order data, customer records, or payment data, and does not request those permissions from Shopify.
Storefront measurement records that a published page was viewed, using a randomly generated identifier that exists only for the duration of that browsing session. It is not a cookie, is not linked to a person, is not shared for advertising, and cannot be used to identify or re-identify a visitor.
4. Data categories processed
Section titled “4. Data categories processed”The app may process the following categories of data:
- Merchant content: page documents, sections, component settings, saved templates, saved sections, design system style profiles, and page version history.
- Store data read from Shopify: product, collection, blog, page, theme, and uploaded file information used to render and configure components, under the permissions you grant at installation.
- Installation and account data: your store domain, installation and session records, subscription status, and app configuration.
- Measurement data: page view records for published pages, consisting of the page reference, the store, a session-scoped random identifier, the page path, and a timestamp.
- Integration data: access records for any AI assistant connections you create, including when they were created and last used.
- Technical and service data: authentication data, diagnostics, and operational logs needed for service reliability and security.
- Support communications: what you send us when you ask for help.
5. How data is used
Section titled “5. How data is used”Data is processed to:
- build, store, and version your pages, templates, and styles,
- render published page content on your storefront,
- read the store data your chosen components display,
- authenticate the app and any connections you authorize,
- report page views, sessions, and editing activity back to you,
- create, restore, and import backups at your instruction,
- maintain security, prevent abuse, and keep the service reliable,
- troubleshoot issues and provide support,
- and comply with legal obligations and platform requirements.
Data is not sold, and is not used for advertising or cross-store profiling.
6. Legal bases
Section titled “6. Legal bases”Depending on jurisdiction and use case, processing may rely on:
- contractual necessity,
- legitimate interests,
- legal obligations,
- and, where required, valid consent.
Merchants are responsible for determining and documenting the lawful basis applicable to their store operations.
7. Data sharing and subprocessors
Section titled “7. Data sharing and subprocessors”Data may be shared with service providers only where needed to operate the app, including:
- Shopify platform APIs and infrastructure,
- hosting, database, and content delivery providers,
- operational service providers needed for reliability and security.
If you connect a third-party AI assistant, app content you make available through that connection is processed by that provider under its own terms and privacy practices. That connection is optional, is created by you, and can be revoked by you at any time.
Data may also be disclosed when required by law, legal process, or to protect rights, safety, and service integrity.
8. Retention and deletion
Section titled “8. Retention and deletion”Data is retained only as long as reasonably required to operate the app, maintain security, resolve disputes, and comply with legal obligations.
Specific retention behavior:
- Page view records are retained for 90 days and then deleted.
- Page version history keeps a limited number of recent versions per page; older versions are superseded.
- Backups are retained as a limited number of most recent snapshots per store; creating a new backup removes the oldest. Backups you download are stored by you, outside the app.
- Temporary records created during uploads, authentication, and webhook handling are deleted automatically once they are no longer needed.
9. Uninstall and erasure
Section titled “9. Uninstall and erasure”On uninstall, app access to your store ends and stored session credentials for that store are removed.
The app supports Shopify’s mandatory privacy webhooks:
- Customer data request — no shopper personal data is stored by the app, so there is nothing to compile or return.
- Customer redaction — no shopper personal data is stored by the app, so there is nothing to erase.
- Shop redaction — on receipt, all data held for that store is erased, including pages, version history, templates, style profiles, backups, view records, assistant connections, insights, and session records.
Because erasure is final, export and download anything you want to keep before uninstalling.
10. Security
Section titled “10. Security”Security measures are designed to reduce risk and protect data, including:
- authenticated, store-scoped access, so one store’s content is not reachable from another,
- encryption of stored access credentials,
- least-privilege platform permissions — the app requests only what a page builder needs and does not request order, customer, or payment access,
- revocable, individually managed access records for any assistant connection you create,
- transport encryption for data in transit,
- and automatic deletion of temporary and expired records.
No system can guarantee absolute security. Merchants should maintain their own access, policy, and operational controls, including who has admin access to the store.
11. Privacy rights
Section titled “11. Privacy rights”Depending on applicable law, individuals may have rights such as access, correction, deletion, restriction, objection, and portability.
Requests should include sufficient identifying information to verify identity and locate relevant records. Where applicable, privacy requests can be handled through Shopify privacy and compliance mechanisms, or through the contact channel below.
12. Merchant obligations
Section titled “12. Merchant obligations”Merchants are responsible for:
- publishing a compliant store-facing privacy notice,
- ensuring content published through the app complies with applicable law,
- controlling which staff and which third-party assistants have access,
- and handling privacy rights requests relating to their store in accordance with applicable law.
13. International transfers
Section titled “13. International transfers”Data may be processed and stored by infrastructure providers in locations outside your country. Where required by law, appropriate safeguards are applied to such transfers.
14. Children’s data
Section titled “14. Children’s data”The app is intended for business use by merchants and is not intended for direct use by children.
15. Changes to this policy
Section titled “15. Changes to this policy”This Privacy Policy may be updated from time to time. Updated versions are effective when posted unless a different date is stated.
16. Contact
Section titled “16. Contact”For privacy questions or requests related to the app, contact: rockstarui.com/contact