Privacy Policy
This policy explains what Hello Studio collects when you install and use the app, why we collect it, who we share it with, and how to have it deleted.
Hello Studio is a Shopify app that installs pre-built theme sections into your store's themes. It runs inside the Shopify admin and works with your themes — it is not a storefront script and it does not process your shoppers' data.
1. Who we are
Hello Studio Ltd., company number 12345678
123 Commerce Way, London, EC1A 1BB, UK
We are the data controller for the information described in this policy.
- Support email: support@hellostudio.Store
Before publishing: replace every bracketed value above. A privacy policy without a named legal entity and a postal address is rejected in Shopify app review.
2. What we collect
2.1 From your Shopify store, at install
When you install the app, Shopify gives us:
| Data | Purpose |
|---|---|
Store domain (your-store.myshopify.com) |
Identifies your store; the key every record is filed under |
| Store name, contact email, currency, plan name | Shown in the app; currency drives price formatting |
| Primary domain, timezone, country code | Display and locale formatting |
| Shopify access token | Lets us read your theme list and write section files into the theme you pick |
The access token is stored server-side, is never sent to your browser, and is deleted the moment you uninstall.
2.2 While you use the app
| Data | Purpose |
|---|---|
| Which sections you add, and to which themes | Your library, and the "in N themes" state on each card |
| The theme id, theme name and filenames we wrote | So we can show where a section lives and re-install it |
| Which presets of a section you installed | Preset-level install state |
| Purchase records: Shopify charge id, amount, currency, status, approval time | Proof of what you own, across reinstalls |
| Bundle orders: the sections in the bundle, the tier discount applied, the charge id | Same, for multi-section purchases |
| Section requests you submit: your description, any reference URL, and any images you upload | So we can read and reply to the request |
| Support emails you send us | To answer you |
2.3 What we do not collect
- Your customers' personal data. The app does not read customer records, orders, checkouts, carts, or any personal information belonging to people who shop with you. Nothing in the app queries those resources.
- Payment card details. All payments run through Shopify's billing API and appear on your Shopify invoice. We never see, receive or store card numbers.
- Storefront analytics or visitor tracking. We install no pixel, no tag, and no tracking script. Sections we install are plain Liquid files that run in your theme; they phone nothing home.
- Cookies for advertising. The app sets one cookie for your Shopify session and one to remember your chosen interface language. Neither is used for advertising or shared with anyone.
Before publishing — action required: the app's Shopify configuration currently requests read_customers, write_customers, read_products and write_products in addition to the theme scopes it actually uses. Remove the unused scopes from shopify.app.toml before submitting for review. A policy that says "we do not collect customer data" while the app requests customer scopes will fail review, and rightly so.
3. Why we collect it (and our lawful basis)
| Purpose | Lawful basis (UK/EU GDPR) |
|---|---|
| Providing the service — a section cannot be installed without access to your themes | Performance of a contract |
| Honouring your purchases across reinstalls, theme changes and app updates | Performance of a contract |
| Answering support messages and section requests | Performance of a contract / legitimate interests |
| Keeping financial records of what was charged | Legal obligation (tax and accounting) |
| Understanding, in aggregate, which sections merchants use | Legitimate interests |
| Preventing abuse (rate limiting on billing and upload endpoints) | Legitimate interests |
We do not sell your data, and we do not use it for advertising or profiling.
4. Who we share it with
We use a small number of processors. Each acts only on our instructions and none receives your data for its own purposes.
| Processor | What it handles | Where |
|---|---|---|
| Shopify | Authentication, billing, theme read/write | Per Shopify's own infrastructure |
| MongoDB Atlas | Application database: store profile, installs, purchases, section requests | AWS Frankfurt (eu-central-1) |
| DigitalOcean Spaces | Object storage for images you upload with a section request | Frankfurt (fra1) |
| AWS / Heroku | Runs the application server | Europe (Frankfurt) |
We disclose data outside this list only where the law requires it.
5. How long we keep it
| Data | Retention |
|---|---|
| Shopify access token | Deleted immediately on uninstall |
| Store profile, installation history, section requests, uploaded images | Deleted when Shopify sends the shop redaction request — 48 hours after uninstall |
| Purchase and bundle records | Retained, with the store domain replaced by a one-way salted hash |
Purchase records are the deliberate exception. Tax and accounting law requires us to keep a record of money charged. After redaction that record can no longer be traced back to your store: the domain is replaced with a salted SHA-256 hash and we keep only the amount, currency, date and charge id.
We honour Shopify's three mandatory privacy webhooks:
customers/data_request— we hold no customer data, so there is nothing to return; the request is acknowledged and logged.customers/redact— we hold no customer data, so there is nothing to delete; the request is acknowledged and logged.shop/redact— deletes your store profile, installation history and section requests, removes your uploaded images from object storage, and hashes the store domain on retained financial records.
6. Your rights
Depending on where you live, you may have the right to:
- access the data we hold about you,
- correct it if it is wrong,
- receive a copy in a portable format,
- have it deleted,
- object to or restrict how we use it,
- withdraw consent where we relied on it,
- complain to your local data protection authority (in the UK, the ICO).
Uninstalling the app starts deletion automatically — no request needed. To exercise any right directly, email support@hellostudio.Store. We respond within 30 days.
7. Security
- All traffic is encrypted in transit (TLS).
- Access tokens are held server-side only and are never exposed to the browser.
- Section source files are fetched server-side and written directly into your theme; they are never published to a public URL.
- Every request is scoped to the authenticated store — a session for one store cannot read another store's data, and a charge belonging to another store can never unlock a section.
- Billing and upload endpoints are rate limited.
- Uploaded images are restricted by type and size; SVG is rejected because it can carry executable script.
No system is perfectly secure, but we will notify you and the relevant authority without undue delay if a breach affects your data.
8. International transfers
Your data may be processed in European Union and United States. Where data leaves the UK or European Economic Area we rely on Standard Contractual Clauses (SCCs) together with appropriate technical safeguards.
9. Children
Hello Studio is a business tool sold to merchants. It is not directed at children and we do not knowingly collect data from anyone under 16.
10. Changes to this policy
If we change this policy we update the date at the top. If a change is material we will also tell you inside the app before it takes effect.
11. Contact
Hello Studio Ltd.
123 Commerce Way, London, EC1A 1BB, UK
support@hellostudio.Store
