Privacy Policy
Privacy Policy — Rich Product Options
Last updated: August 1, 2026 Effective date: August 1, 2026
This Privacy Policy explains how North JS Tech (“we,” “us,” or “our”) collects, uses, stores, and shares information in connection with the Rich Product Options Shopify application (the “App”). The App enables Shopify merchants (“Merchants”) to add custom product options and personalization fields (such as text inputs, dropdowns, swatches, and file uploads) to their online stores, which are then displayed to their shoppers (“Shoppers”).
By installing or using the App, you agree to the practices described in this Policy.
1. Who this Policy covers
- Merchants — Shopify store owners and their staff who install and configure the App from the Shopify admin.
- Shoppers — visitors and customers of a Merchant’s storefront who interact with product options rendered by the App.
We act as a data processor on behalf of Merchants for storefront activity, and as a data controller for the limited account and operational data we collect directly from Merchants. Merchants remain the controllers of their own store and customer data.
2. Information we collect
2.1 Information we collect from Merchants (stored in our systems)
When a Merchant installs and uses the App, we store the following in our own database:
- Store identity: your Shopify store domain (e.g.
your-store.myshopify.com). - Authentication credentials: Shopify API access tokens and refresh tokens issued to the App so it can operate on your store. These are secret credentials and are never displayed or shared.
- Merchant/staff account details provided by Shopify when a staff member logs in: first name, last name, email address, Shopify user ID, locale, and account-owner/collaborator status.
- App configuration data: the option sets, option fields, labels, help text, default values, pricing rules, templates, widget text and translations, and design/integration settings you create.
- Targeting rules you configure, which may reference Shopify product IDs, collection IDs, product tags, variant IDs, and — where you choose to target specific audiences — Shopify customer IDs and customer tags. These are audience-targeting rules you author; the App does not build or store profiles of individual customers from them.
- Operational logs: publish/sync history (such as payload size, a content hash, status, and error messages) used for reliability and troubleshooting.
2.2 Information from Shoppers (processed, not stored by us)
When a Shopper personalizes a product using the App on a Merchant’s storefront:
- Option inputs — the text, numbers, selections, dates, dimensions, quantities, and other values a Shopper enters or chooses. These are attached to the Shopper’s Shopify cart as line-item properties and flow into the Merchant’s Shopify orders. We do not store these inputs in our database. They are held and controlled by Shopify and the Merchant.
- Email and phone values — a Merchant may configure email or phone option fields. If so, the values a Shopper enters are handled the same way as other option inputs (stored as Shopify cart/order line-item properties), not in our systems.
- Uploaded files and preview images — if a Merchant enables file uploads, the files a Shopper uploads (and any live-preview image generated from the product image plus personalization) are sent to and stored on Shopify’s file CDN under the Merchant’s store, and referenced by a URL. These files pass through our servers only transiently in memory during upload and are not retained by us. Uploaded files may contain personal information depending on what the Shopper provides; the resulting Shopify CDN URLs are publicly accessible.
- Order data — when an order is created, Shopify sends the App an order notification. The App reads only a hidden option-tagging property to apply Merchant-configured order tags. It does not read, use, or store Shopper names, emails, addresses, or payment information from the order.
2.3 Information stored on the Shopper’s own device
The storefront widget may use the browser’s local storage to remember a Shopper’s previous option selections so fields can be pre-filled on a return visit. This information stays on the Shopper’s device and is never transmitted to us. The App sets no tracking cookies and includes no analytics or advertising pixels.
3. How we use information
We use the information described above only to:
- Provide, operate, and maintain the App’s functionality (rendering options, applying option-based pricing at checkout, handling file uploads, applying order tags, and localizing content).
- Authenticate and communicate with your Shopify store via Shopify’s APIs.
- Save and publish your option configurations and settings.
- Troubleshoot, secure, debug, and improve the App’s reliability.
- Provide customer support and respond to your requests.
- Comply with legal obligations.
We do not sell personal information, and we do not use it for advertising or profiling.
4. Shopify permissions (access scopes)
To function, the App requests the following Shopify access scopes: write_products, read_files, write_files, write_cart_transforms, write_discounts, read_themes, write_orders, and read_locales. The App does not request access to customer records (no customer read/write scope).
Because the App reads product-option line-item properties from orders (to apply order tags), the App’s Shopify App Store listing operates under Shopify’s Protected Customer Data requirements at the order level, even though the App does not persist customer personal data.
5. How information is stored and shared
5.1 Where data is stored
- Our database: Merchant configuration and account data (Section 2.1) is stored in a PostgreSQL database hosted on a Linode (Akamai) virtual private server, secured behind an HTTPS reverse proxy.
- Shopify: Published option data is written to your store’s Shopify metafields (some marked storefront-readable so the widget can render options), and Shopper option inputs and uploaded files live within Shopify’s cart, order, and file-storage systems.
5.2 Third parties (sub-processors and services)
We keep third-party sharing to a minimum. The App relies on:
ProviderPurposeData involvedShopifyCore platform: Admin API, order/cart data, metafields, file (CDN) storage, session tokens, webhooksMerchant store data, Shopper option inputs, uploaded filesLinode (Akamai)Hosting of the App backend and PostgreSQL databaseMerchant configuration and account dataGoogle Fonts (fonts.googleapis.com, fonts.gstatic.com)Delivery of web fonts used by the option widget and admin previewRequests to Google expose the visitor’s IP address and user-agent when fonts loadGitHub Container RegistryStorage of deployment build images (infrastructure only)No Merchant or Shopper personal data
We do not use any analytics, tracking, advertising, error-telemetry, email-marketing, payment, or AI/LLM third-party services in the App.
We may disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer (e.g. merger or acquisition), subject to this Policy.
6. Data retention and deletion
- Sessions & tokens: When a Merchant uninstalls the App, we delete the store’s authentication sessions and access tokens.
- Merchant configuration: Option sets, settings, templates, and logs may be retained after uninstall so your configuration is preserved if you reinstall. A Merchant may request permanent deletion of this data at any time by emailing support@northjstech.com; we will delete it within 30 days of a verified request.
- Shopper inputs & files: Because these are stored within Shopify (cart/order line-item properties and Shopify Files), they are governed by the Merchant’s own data-retention practices and Shopify’s policies. Requests to delete this data should be directed to the relevant Merchant.
GDPR mandatory data requests
The App implements Shopify’s mandatory compliance webhooks — customers/data_request, customers/redact, and shop/redact. Because the App stores no Shopper personal data, customer data requests and redaction requests are acknowledged with no data to return or erase; shop-level uninstall/redaction removes the store’s sessions as described above.
7. Your rights
Depending on where you live, you may have rights over your personal information.
7.1 EU/UK (GDPR)
If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, restrict, or object to processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your local data protection authority.
7.2 California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion, to correct inaccurate information, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. We will not discriminate against you for exercising your rights.
7.3 How to exercise your rights
- Merchants can contact us directly at support@northjstech.com.
- Shoppers should contact the Merchant whose store they used, as the Merchant controls Shopper personal data. We will assist Merchants in responding to such requests.
We may need to verify your identity before acting on a request.
8. Data security
We protect information using industry-standard measures, including encrypted connections (HTTPS/TLS) for data in transit, restricted access to production systems, and secure storage of Shopify credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International data transfers
Our infrastructure and sub-processors may process data in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers of personal data.
10. Children’s privacy
The App is intended for use by businesses and is not directed at children. We do not knowingly collect personal information from children under the age of 16.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and where appropriate we will provide additional notice. Continued use of the App after changes take effect constitutes acceptance of the updated Policy.
12. Contact us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact:
North JS Tech
Email: support@northjstech.com
Last updated: