Privacy Policy
Product Option Groups
Last Updated: 2026-03-26
This Privacy Policy describes how eCommerce360 (“we”, “our”, or “us”) collects, uses, and protects information when you install or use our Shopify application (“App”). Our App enables merchants to create product groups with shared attributes, allowing customers to navigate between related products using visual selectors on the storefront.
1. Information We Collect
When you install and use the App, we collect only the data necessary to provide our services. We do not collect or access any customer personal data or order information.
a) Store Information
Collected automatically upon installation:
- Store name and myshopify.com domain
- Merchant contact email
- OAuth access token and refresh token (for secure API authentication)
Why: To authenticate the merchant, manage billing, and deliver app functionality.
b) Product Data (via Shopify Products API)
We read and write product data as follows:
- Read: Product titles, handles, IDs, images, variant information, and metafield values
- Write: A single product metafield (product_option_groups.group) containing option group configuration for storefront rendering
- Delete: The above metafield when a product is removed from a group or the group is deleted
Why: To create product groups based on shared attributes, store group configuration on the product for storefront rendering, render swatches and selectors, and enable product-to-product navigation via unique URLs. Product metafield data written by the app is automatically removed by Shopify when the app is uninstalled.
c) App-Generated Data
- Product group configurations (group names, linked products, primary and additional attributes)
- Click event records (source product handle, destination product handle, attribute key and value selected — no visitor personal data is captured)
- Activity logs (group creation, editing, and deletion events)
- Merchant session data for authentication
Why: To power the app’s core features, provide analytics to merchants, and maintain secure sessions.
d) Data We Do NOT Collect
Our App does not access, collect, or store:
- Customer personal information (names, emails, phone numbers, addresses)
- Order, transaction, or payment data
- Financial or billing information of buyers
- Browsing behavior, cookies, or tracking data of store visitors
2. How We Use Your Information
We use collected information exclusively to:
- Provide and operate the App’s core functionality (product grouping, selector rendering, storefront navigation)
- Display click statistics and recent activity to the merchant dashboard
- Manage billing, subscription plans, and whitelist access codes
- Authenticate merchant sessions via Shopify session tokens
- Improve app performance, fix bugs, and enhance the user experience
3. Data Storage
All app data — including product group configurations, click statistics, activity logs, and session data — is stored in our own PostgreSQL database on secure infrastructure, managed via Prisma ORM. Data is not stored on or shared with third-party analytics, advertising, or marketing platforms.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your data. We may share data only in these limited circumstances:
- With hosting and infrastructure providers solely for operating the App
- To comply with applicable laws, regulations, or legal processes
- To protect our rights, prevent fraud, or address security issues
5. Data Retention & Deletion
We retain your data only for as long as the App is installed and active on your store.
Upon uninstallation: All associated data — including store information, product group configurations, click statistics, activity logs, and session data — is permanently deleted from our database within 48 hours.
You may also request manual data deletion at any time by contacting us at the email address below.
6. Data Security
We implement industry-standard security measures:
- All data transmitted over HTTPS with TLS encryption
- Authentication via Shopify session tokens (no reliance on third-party cookies)
- Database access restricted with role-based controls
- App functions properly without third-party cookies, including in incognito mode
- Regular security updates and infrastructure monitoring
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the data we store about your store
- Request correction of inaccurate data
- Request deletion of your data at any time
- Receive a copy of your data in a structured format (data portability)
To exercise any of these rights, contact us at the email address below.
8. GDPR & CCPA Compliance
Our App does not collect, store, or process any end-customer personal data. GDPR and CCPA obligations are therefore limited to the merchant’s own store information. Merchants may contact us at any time to exercise their data rights as described in Section 7.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. Continued use of the App after changes constitutes acceptance of the revised policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us:
Email: tatia@e360.ge
Company: eCommerce360
Website: https://e360.ge