Shopify App, last updated on 05th May, 2026

This Privacy Policy explains how RadiusTheme (“we,” “our,” “us”) collects, uses, stores, and shares information when you install and use the Shopify app (the “App”). We’ve written this in plain language so you know exactly what data we touch, why, and what control you have over it.

By installing the App, you agree to the practices described below.

1. Who We Are

2. Information We Collect

When you install our app, the App accesses the following data through the Shopify Admin API and webhooks. We’ve grouped it by category so you can see exactly what’s involved.

2.1 Merchant store information

  • Shop domain (e.g. your-store.myshopify.com), shop name, currency, plan, locale, country, and time zone.
  • App installation status, subscription status, and trial dates.
  • Encrypted Shopify access tokens (used to call the Shopify Admin API on the merchant’s behalf).

2.2 Merchant’s customer information

We do not collect personal data from your customers. No names, emails, phone numbers, addresses, or payment details are stored by the App. The only customer-related data we process is anonymous session identifiers used to deduplicate analytics events — these cannot be traced back to an individual and are automatically discarded when the browser session ends.

2.3 Product and catalogue data

  • Product IDs, titles, descriptions, vendors, types, variants, prices, compare-at prices, SKUs, and inventory status
  • Product images and media URLs
  • Collections and tags

2.4 Order and analytics data

  • Order data received through the orders/create webhook (line items, totals, currency) — used solely to track conversion performance
  • Aggregated app metrics: views, add-to-cart events, purchases, and revenue
  • Anonymous session identifiers — used only to deduplicate analytics. We do not store names, emails, phone numbers, addresses, or payment details.

2.5 App configuration data

  • Widget appearance settings (layout, colours, typography, custom CSS).
  • App preferences and feature toggles.
  • Webhook delivery logs (used for retries and reliability).

2.6 What we never collect

  • Buyer payment details, credit card numbers, or banking information
  • Buyer email addresses, phone numbers, or postal addresses
  • Customer account passwords or authentication credentials
  • Any data outside the OAuth scopes listed in our App Store listing

3. How We Use Your Information

Here’s a straightforward breakdown of why we use what we collect:

  • Run the App — deliver core functionality on your storefront and at checkout
  • Show the widget — fetch product details to render the App’s interface for your customers
  • Power your analytics — track key metrics for your reporting dashboard
  • Authenticate securely — communicate with Shopify on your behalf using encrypted tokens
  • Process billing — manage subscription charges through Shopify’s Billing API
  • Provide support — diagnose issues when you contact us
  • Meet legal obligations — respond to GDPR data requests, tax/audit requirements, and lawful authority requests

We do not sell, rent, or trade your data to third parties for advertising or marketing purposes.

4. Where Your Data Lives

  • Database: PostgreSQL on Amazon Web Services (AWS), deployed in Asia Pacific
  • Application servers: AWS EC2
  • File uploads: Stored through Shopify’s Files API (MediaImage) — not on our servers

5. Third-Party Services

The App relies on two sub-processors. Each is contractually bound to confidentiality and security standards equivalent to this policy.

ProviderPurposeData shared
Shopify, Inc.Platform hosting, OAuth, billing, webhook deliveryAll app data flows through Shopify
Amazon Web Services (AWS)Database hosting, application servers, infrastructureAll structured app data and request logs

6. How Long We Keep Your Data

  • While the App is installed: We retain all data needed to operate the App for as long as it’s installed on your store.
  • After you uninstall: The app/uninstalled webhook immediately disables further data processing and revokes access tokens. We hold remaining shop data for 48 hours in case of accidental uninstall, then permanently delete everything.
  • GDPR shop/redact webhook: Sent by Shopify 48 hours after uninstall. On receipt, we permanently delete all merchant data — analytics and configuration.
  • GDPR customers/redact webhook: When Shopify sends this webhook, we delete any anonymous session identifiers associated with the specified customer from our analytics tables.

7. Your Rights

Whether you’re a merchant or a shopper whose data we process, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectify — correct inaccurate personal data.
  • Erase — request deletion of your personal data (“right to be forgotten”).
  • Restrict — limit how we process your personal data.
  • Portability — receive your personal data in a machine-readable format.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — at any time, where processing is based on consent.

How to exercise your rights

  • Merchants: Uninstall the App from your Shopify admin. Shopify automatically sends the shop/redact webhook 48 hours later, triggering full deletion. For faster action, email support@radiustheme.com
  • Shoppers: Contact the merchant whose store you visited. They’ll forward your request to us through Shopify’s customers/data_request or customers/redact webhooks.
  • Direct inquiries: Email support@radiustheme.com. We respond to all verifiable requests within 30 days.

GDPR webhook compliance

The App implements all three Shopify-mandated GDPR webhooks:

  • customers/data_request — we compile and return all data we hold about a specified customer
  • customers/redact — we permanently delete all data about a specified customer
  • shop/redact — we permanently delete all data about a specified shop

8. Cookies and Tracking

The App uses Shopify session tokens for authentication. We do not use third-party cookies, tracking pixels, advertising identifiers, or cross-site tracking in the embedded admin app.

The storefront widget uses a single anonymous session identifier (stored in sessionStorage, not a cookie) to deduplicate analytics events. This identifier resets when the shopper closes their browser and is never linked to personally identifiable information.

9. Children’s Privacy

The App is intended for Shopify merchants who are at least 18 years old. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact support@radiustheme.com and we will delete it promptly.

10. International Data Transfers

Depending on where you’re located, your data may be processed in a different country from where our hosting providers operate. We protect these transfers using safeguards required by applicable data protection laws, including Standard Contractual Clauses where necessary. Using the App means you agree to this.

11. Security

We implement industry-standard security measures to protect your data:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption at rest for sensitive credentials
  • HMAC verification on all incoming Shopify webhooks
  • Token-based authentication using Shopify session tokens (no third-party cookies)
  • Rate limiting on App Proxy endpoints
  • Multi-tenant data isolation enforced at the database query level
  • Regular dependency audits and security reviews

No system is 100% secure. If we become aware of a data breach affecting your information, we will notify affected merchants without undue delay and report to relevant authorities as required by law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the “Last updated” date at the top of this page
  • Notify merchants in-app of material changes
  • For significant changes, provide 30 days’ notice before they take effect

Continued use of the App after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

For any questions, requests, or complaints:

If you’re not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.