Skip to content

Privacy Policy

This Privacy Policy explains how data is handled when a merchant installs and uses Get the Look and when shoppers interact with a look published through the app.

By installing or using Get the Look, you acknowledge this Privacy Policy.

This policy covers data processed through Get the Look, including:

  • look content and style settings created or selected by a merchant,
  • permitted Shopify store resources used to configure and render a look,
  • privacy-gated storefront interaction events,
  • limited paid-order attribution for app-reported conversions,
  • app authentication, operations, recovery, security, and support communications.

This policy does not replace Shopify’s policies, the merchant’s own storefront privacy notice, or the policies of third-party services used by the merchant or Shopify.

  • Merchant: decides why and how Get the Look is used in the store, controls the published content, and is responsible for the store’s legal notices, consent choices, and compliance.
  • App provider: processes data needed to provide, secure, maintain, and support Get the Look.
  • Staff users: use the app under access granted through the merchant’s Shopify account.
  • Shopify: operates the commerce platform and processes data under its own terms and policies.

The merchant remains responsible for determining the legal basis and notices required for the merchant’s store and use of the app.

Get the Look may process:

  • Look content: look IDs, titles, images and image references, product and variant selections, product display information, descriptions, hotspots, templates, style profiles, button and typography settings, visibility choices, discount selections, and publishing settings.
  • Shopify store resources: product and variant information, theme settings, files selected through Shopify, active discount information, and the limited paid-order attribution described below.
  • Installation and staff-session data: store domain, installation and session records, encrypted Shopify access credentials, app configuration, and Shopify-provided staff-session fields when present, such as user ID, name, email, locale, and account-owner or collaborator status.
  • Storefront analytics: store, look ID, event type, random event ID, and event time for a visible look, product-link click, or add-to-cart attempt.
  • Paid conversion attribution: a one-way-hashed order identifier, attributed look IDs taken from Get the Look line-item properties, and the paid-order event time.
  • Operational data: tenant-scoped content revisions, publishing operations, migration state, webhook receipts, analytics queue records, recovery metadata, encrypted content backups, diagnostics, and security logs.
  • Support communications: information sent when a merchant asks for help.

4. Shopper analytics and order attribution

Section titled “4. Shopper analytics and order attribution”

Get the Look does not build shopper profiles and does not request access to Shopify customer records.

Storefront analytics are sent only when Shopify’s customer-privacy API reports that analytics processing is allowed. The app records anonymous interaction events for a look: visible view, product-link click, and add-to-cart attempt. It does not place an advertising cookie or include a shopper name, email address, postal address, payment information, or Shopify customer ID in those event records.

When analytics processing is allowed, Get the Look may add a private look-attribution property to cart lines created through the app. If Shopify later sends the app an orders/paid event, the app extracts only:

  • the attributed Get the Look IDs already present on those lines,
  • a one-way hash of the order identifier,
  • and the event time.

The remaining paid-order payload is not stored in the app’s durable webhook record. Hashed order identifiers are used to prevent duplicate conversion counts and to respond to Shopify customer-redaction requests; they are not used to identify or profile a shopper.

If analytics processing is not allowed or Shopify’s privacy API is unavailable, the app does not send storefront analytics events or add look-attribution data for analytics. Shopping and cart actions can continue without that attribution.

Data is processed to:

  • authenticate the merchant’s app installation and staff sessions,
  • create, update, version, delete, and publish shoppable looks,
  • read permitted Shopify resources selected or needed by app features,
  • render published looks and operate product-link and cart actions,
  • apply merchant-selected, validated discount behavior,
  • report look views, product clicks, add-to-cart attempts, and attributed paid conversions,
  • maintain tenant isolation, service reliability, recovery, and security,
  • reconcile interrupted publishing operations,
  • process Shopify webhooks and privacy requests,
  • troubleshoot issues and provide support,
  • comply with legal and Shopify platform requirements,
  • and establish, exercise, or defend legal rights.

The app does not use merchant or shopper data for advertising or cross-store profiling and does not sell that data.

Depending on the jurisdiction and processing context, processing may rely on:

  • contractual necessity,
  • legitimate interests in operating and securing the service,
  • legal obligations,
  • and valid consent where required.

The merchant is responsible for determining and documenting the legal basis that applies to the merchant’s store operations, storefront content, analytics choices, and shopper notices.

Data may be processed by service providers only as needed to operate Get the Look, including:

  • Shopify platform APIs, webhooks, app infrastructure, and merchant-store storage,
  • hosting and content-delivery services,
  • database and encrypted object-storage services,
  • and operational providers needed for service reliability and security.

Data may also be disclosed where required by law or legal process, or where reasonably necessary to protect rights, safety, security, and service integrity.

Third-party providers operate under their own terms and privacy practices. The app provider does not accept responsibility for third-party acts, omissions, security, downtime, or policy decisions.

Data is retained only for as long as reasonably required to operate and secure the app, maintain recovery and audit records, resolve disputes, enforce agreements, and comply with legal or Shopify platform obligations.

Current service behavior includes:

  • merchant look content and its revision history are retained while needed to operate the app and until the applicable store-erasure process,
  • completed anonymous analytics queue records are removed after 7 days,
  • failed analytics queue records are removed after 30 days,
  • per-look daily aggregate analytics retain up to 400 daily entries,
  • up to 400 hashed converted-order identifiers are retained per look for duplicate prevention and redaction,
  • completed webhook receipts are removed after 90 days,
  • encrypted service backups retain the 35 most recent verified recovery points plus up to 12 older monthly recovery points,
  • expired or invalid session records are removed, and store session credentials are deleted when the app-uninstall webhook is processed.

Look content and aggregate analytics stored in Shopify app-owned fields are also subject to Shopify’s platform behavior and retention practices. Retention periods may be shortened where data is no longer needed or erasure is required.

9. Uninstall, privacy requests, and erasure

Section titled “9. Uninstall, privacy requests, and erasure”

When the app-uninstall webhook is processed, stored Shopify session credentials for that store are deleted and app access ends. Storefront output that depends on Get the Look may stop appearing.

Get the Look supports Shopify’s mandatory privacy webhooks:

  • Customer data request: the app does not maintain customer profiles or customer-addressable analytics records, so there is no customer profile to compile from Get the Look storage.
  • Customer redaction: hashed paid-order identifiers supplied by Shopify for redaction are removed from app analytics records.
  • Shop redaction: the app transitions the store into an erasure workflow and deletes its app-held content revisions, publishing operations, analytics events and snapshots, migration records, feature flags, encrypted backup objects and records, tenant state, sessions, and webhook receipts.

Shopify-hosted data remains subject to Shopify’s own platform handling. Erasure cannot be reversed. Merchants are responsible for retaining any business information they need before uninstalling.

Security measures are designed to reduce risk and include:

  • authenticated, store-scoped access,
  • tenant-scoped database records and operations,
  • encryption of stored Shopify access and refresh credentials,
  • encrypted content-recovery backups,
  • transport encryption for data in transit,
  • restricted storefront projections that omit private editor records,
  • privacy-gated analytics attribution,
  • and automatic cleanup of expired or retained operational records.

No system can guarantee absolute security. Merchants remain responsible for controlling Shopify administrator access, staff permissions, store policies, and their own operational safeguards.

Depending on applicable law, individuals may have rights such as access, correction, deletion, restriction, objection, and portability.

A request must include enough information to verify the requester and locate relevant records. Where applicable, requests may be handled through Shopify’s privacy and compliance mechanisms or through the contact channel below.

Merchants are responsible for:

  • publishing an accurate storefront privacy notice,
  • configuring Shopify customer-privacy and consent settings as required,
  • ensuring their use of analytics and published content complies with applicable law,
  • controlling which staff have Shopify and app access,
  • protecting the rights to product information, imagery, and other published materials,
  • and handling privacy-rights requests relating to their store.

Get the Look does not replace the merchant’s legal, privacy, security, accessibility, or compliance obligations.

Infrastructure providers may process or store data outside the merchant’s or shopper’s country. Where applicable law requires safeguards for those transfers, the relevant provider arrangements and legal mechanisms apply.

Get the Look is intended for business use by Shopify merchants. It is not intended for direct use by children and is not designed to create profiles about children.

This Privacy Policy may be updated from time to time. An updated version becomes effective when posted unless it states a different effective date.

For privacy questions or requests about Get the Look, use the RockStarUI contact page.