본문으로 건너뛰기

Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how Codexian Labs ("we," "us," or "our") collects, uses, stores, and protects information when you install and use Codexian Color Swatches (the "App") on your Shopify store.

Shopify requires App Store apps to share a privacy policy so merchants can learn how their data is being used. This page is that policy. It follows Shopify’s privacy requirements for app developers and describes our practices clearly and factually.

By installing or using the App, you agree to the practices described here. If you do not agree, uninstall the App.

Not legal advice

This policy describes our data practices. It is not legal advice. Privacy laws vary by region. If you need advice about how those laws apply to your store, consult a qualified professional.

Who we are

AppCodexian Color Swatches
ProviderCodexian Labs
Support emailcodexianlabs@gmail.com
Websitecodexianlabs.com
App URLcolorswatches.codexianlabs.com

The App helps merchants display color and image swatches, product groups, and product bundles on their Online Store through Shopify’s APIs and theme app extensions.

Who this policy covers

AudienceCovered?
Merchants (store owners and staff who install and use the App)Yes
Store customers / shoppersNo — we do not intentionally collect their personal data

The App configures your storefront. It does not run customer accounts, marketing, checkout forms, or payment collection outside Shopify.

1. Information we collect through Shopify’s APIs

When you install the App, Shopify grants access only to the scopes you approve. We request the minimum scopes needed for the App to work:

ScopeWhat we accessWhy
read_productsProduct and variant IDs, titles, handles, options, images, and availability used for displayPower swatches, product groups, and bundles
write_productsProduct-related configuration required for App featuresSave settings tied to your catalog
read_themesTheme identity and theme editor contextHelp you enable App blocks / embeds and confirm storefront setup

We do not request order, customer, payment, or checkout personal-data scopes. We do not use read_all_orders or other protected customer data scopes.

Through OAuth and session storage, Shopify may also provide:

  • Shop domain (for example, your-store.myshopify.com)
  • Access token and approved scopes
  • Session data needed to keep you signed in inside Shopify admin
  • For online (staff) sessions: limited staff details such as name, email, user ID, and locale — used only for authentication and operating the App

2. Information we collect directly from merchants

We store the configuration you create in the App so it persists between sessions:

  • Swatch styles and appearance (colors, borders, sizes, labels, tooltips, display modes)
  • Product option mappings (which options use which swatch styles)
  • Product groups (linked products, display rules, publish status)
  • Product bundles (products, discounts, layout, and labels)
  • App settings (feature toggles, badge text, page visibility, language preference)
  • Subscription / plan status for your shop (plan name, billing period, active or cancelled state)

We may also receive information you send us voluntarily (for example, a support email describing a bug).

We do not ask merchants for their customers’ contact lists, payment details, or other customer personal information.

3. Information we collect from merchants’ customers

We do not collect personal information from your customers.

Specifically:

  • We do not drop advertising cookies or use tracking pixels on the storefront for our own marketing
  • We do not log how individual shoppers navigate your store for analytics profiles
  • We do not store customer names, emails, addresses, phone numbers, or payment details

Theme app extensions (App block / App embed) render swatches and related UI using configuration you set and product data from Shopify. They are not used to harvest shopper personal data for us.

If a shopper’s browser requests storefront assets, standard technical request metadata may appear in infrastructure logs (for example IP address or user agent) for security and reliability. We do not use that data to identify shoppers or build marketing profiles.

4. How we use the information

We use the information above only to:

  • Authenticate and operate the App inside Shopify admin (session tokens / OAuth — no reliance on third-party cookies for core auth)
  • Provide swatches, product groups, and product bundles as described in our App Store listing
  • Save settings to our database and sync configuration to Shopify app metafields so your theme can display them
  • Enforce plan limits and manage subscriptions via Shopify App Pricing / Shopify Billing API (we never process app charges off-platform)
  • Respond to support requests, fix bugs, and maintain security
  • Comply with law and Shopify’s mandatory privacy webhooks

We do not:

  • Sell merchant or customer personal information
  • Use store data for unrelated advertising or interest-based marketing
  • Contact your customers
  • Circumvent Shopify checkout, billing, or core platform workflows

5. How long we keep data

We keep App data while the App is installed and as needed to provide the service.

EventWhat happens
App in useSessions, settings, groups, bundles, and subscription records are retained to operate the App
UninstallWe delete shop sessions and related App data from our database in response to Shopify’s uninstall webhook
shop/redactAfter Shopify’s required waiting period, we permanently delete remaining shop data from our systems
Support emailsKept only as long as needed to resolve your request

Configuration stored as Shopify app metafields on your store is governed by Shopify’s uninstall and retention rules after the App is removed.

To request earlier deletion of data we hold, email codexianlabs@gmail.com with your shop domain.

6. Shopify privacy compliance webhooks

We subscribe to Shopify’s mandatory privacy webhooks:

WebhookOur response
customers/data_requestNo customer personal data is stored — nothing to disclose
customers/redactNo customer personal data is stored — nothing to erase
shop/redactDelete all shop-related App data from our database (sessions, settings, swatches, groups, bundles, subscriptions)

7. Where data is stored and international transfers

  • Our systems: App sessions and configuration are stored on secure cloud infrastructure (currently hosted in the United States).
  • Shopify: OAuth, Admin API access, billing, webhooks, and store metafields remain on Shopify’s platform.

We are not established as a company office in the European Economic Area. If you operate a store in the EEA, UK, Switzerland, or another region, your information may be processed in the United States or other countries where our service providers operate. Where required, we take steps designed to apply appropriate safeguards for international transfers.

8. How we share information

We do not sell personal information. We share data only as needed to run the App:

RecipientPurpose
ShopifyAuthentication, APIs, billing, webhooks, and platform hosting
Hosting / infrastructure providersServer hosting, database, backups, TLS termination
Legal authoritiesWhen required by law, regulation, or valid legal process

Service providers may process data only to perform services for us and are expected to protect it appropriately.

9. Security

Consistent with Shopify App Store security expectations, we protect data in transit and at rest using reasonable measures, including:

  • Valid TLS/HTTPS for all App traffic
  • Access controls and secure storage of API credentials / session tokens
  • Least-privilege API scopes (only what the App needs)

No method of transmission or storage is 100% secure. If you believe your data has been compromised, contact us immediately at codexianlabs@gmail.com.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal information we hold about you.

You can also:

  • Uninstall the App to stop further collection and trigger deletion workflows
  • Manage staff access and App permissions in Shopify admin
  • Contact Shopify for data controlled solely by Shopify

To exercise rights related to data we hold, email codexianlabs@gmail.com with your shop domain and request. We will respond within a reasonable time and as required by applicable law.

California (CCPA/CPRA) and similar US state laws

We do not sell or share personal information for cross-context behavioral advertising. You may request disclosure or deletion of personal information we collect by contacting us.

EEA, UK, and Switzerland (GDPR)

Where GDPR applies, our typical lawful bases are:

  • Contract — providing the App you installed
  • Legitimate interests — securing and improving the App, balanced against your rights
  • Legal obligation — complying with law and Shopify platform requirements

You may lodge a complaint with your local supervisory authority. We encourage you to contact us first.

11. Children’s privacy

The App is for merchants operating businesses. It is not directed at children under 16. We do not knowingly collect personal information from children.

Our documentation or support materials may link to third parties (for example Shopify or YouTube). Their privacy practices are governed by their own policies. Billing for paid App plans is processed by Shopify under Shopify’s terms.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the Last updated date above. Material changes may also be noted in the App or App Store listing where appropriate.

Continued use of the App after an update means you accept the revised policy.

14. Contact us

Questions about this Privacy Policy or our data practices:

Codexian Labs
Email: codexianlabs@gmail.com
Web: codexianlabs.com

For App Store listing purposes, this page’s public URL is:

https://docs.colorswatches.codexianlabs.com/docs/legal/privacy-policy