← Back to SHOOPIX

Privacy Policy

Last updated: 18 July 2026

This policy explains how SHOOPIX handles personal data across two contexts: this marketing website, and the SHOOPIX suite of apps that merchants install on their Shopify stores. Because our apps run inside a merchant's store, we act as a data processorfor the merchant (the data controller) and process their shoppers' data only on their behalf and on their instructions.

1. Data we collect on this website

When you submit the enquiry form, we collect your name, company, phone number, email address, and message. We use it solely to respond to your enquiry.

We also use Google Analytics to understand how this site is used — which pages are viewed, rough location, device and browser type, and how visitors arrived. This is measurement only: we run no advertising trackers, we do not sell or share this data, and Google Analytics 4 does not store full IP addresses. Analytics cookies are set in your browser; you can block them via your browser settings or an opt-out extension, and the site works fully without them.

2. Merchant store data (the apps)

When a merchant installs a SHOOPIX app, the app accesses their store data through Shopify's official APIs, limited to the permission scopes that app actually needs to work — for example products and pricing for Dynamic Pricing, orders and subscriptions for Subscription, or reviews and product data for Product Reviews. We request the minimum scopes required and do not access data a feature doesn't use. Store access tokens are encrypted at rest (AES-256-GCM) and are never exposed to other merchants or to third parties.

3. Shoppers' personal data

Some apps process personal data belonging to a merchant's customers — always to deliver a feature the merchant switched on, never for our own purposes:

We do not sell shoppers' personal data, and we do not use one merchant's data to serve another.

4. How we store and protect data

Data is processed through Shopify's official APIs and our infrastructure, with scoped access, encryption of sensitive credentials at rest, and transport encryption (HTTPS) in transit. AI features route through our own AI service; prompts and store context are used to generate the merchant-facing output and are not used to train third-party foundation models.

5. Sub-processors

We rely on a small set of service providers to run SHOOPIX: Shopify (platform and store data), our hosting providers (this site and the app backends), Resend (delivering the enquiry email above), Google (Analytics and Search Console for this website only — not merchant or shopper data), and AI model providers (powering in-app AI features). Each processes data only to provide its service to us.

6. Retention and deletion

We keep data only as long as needed to provide the app. When a merchant uninstalls an app, we honour Shopify's mandatory data-erasure webhooks (shop/redact) and delete or anonymise the store's data. Shopper-level erasure and data-access requests (customers/redact, customers/data_request) are actioned through the same Shopify GDPR flow.

7. Your rights

Merchants and shoppers may request access to, correction of, or deletion of their personal data. Shoppers should contact the store they interacted with (the data controller); we will support that merchant in fulfilling the request. You can also reach us directly using the details below.

8. Changes

We may update this policy as the apps evolve. Material changes will be reflected here with a new "last updated" date.

9. Contact

For any privacy question or data request, email contact@cre8tor.work and we will respond. See also our Terms & Conditions.