Privacy Policy
Last updated: August 5, 2026
This Privacy Policy explains how Codexian Labs ("we," "us," or "our") collects, uses, stores, and protects information when you install and use Codexian Color Swatches (the "App") on your Shopify store.
Shopify requires App Store apps to share a privacy policy so merchants can learn how their data is being used. This page is that policy. It follows Shopify’s privacy requirements for app developers and describes our practices clearly and factually.
By installing or using the App, you agree to the practices described here. If you do not agree, uninstall the App.
This policy describes our data practices. It is not legal advice. Privacy laws vary by region. If you need advice about how those laws apply to your store, consult a qualified professional.
Who we are
| App | Codexian Color Swatches |
| Provider | Codexian Labs |
| Support email | codexianlabs@gmail.com |
| Website | codexianlabs.com |
| App URL | colorswatches.codexianlabs.com |
The App helps merchants display color and image swatches, product groups, and product bundles on their Online Store through Shopify’s APIs and theme app extensions.
Who this policy covers
| Audience | Covered? |
|---|---|
| Merchants (store owners and staff who install and use the App) | Yes |
| Store customers / shoppers | No — we do not intentionally collect their personal data |
The App configures your storefront. It does not run customer accounts, marketing, checkout forms, or payment collection outside Shopify.
1. Information we collect through Shopify’s APIs
When you install the App, Shopify grants access only to the scopes you approve. We request the minimum scopes needed for the App to work:
| Scope | What we access | Why |
|---|---|---|
read_products | Product and variant IDs, titles, handles, options, images, and availability used for display | Power swatches, product groups, and bundles |
write_products | Product-related configuration required for App features | Save settings tied to your catalog |
read_themes | Theme identity and theme editor context | Help you enable App blocks / embeds and confirm storefront setup |
We do not request order, customer, payment, or checkout personal-data scopes. We do not use read_all_orders or other protected customer data scopes.
Through OAuth and session storage, Shopify may also provide:
- Shop domain (for example,
your-store.myshopify.com) - Access token and approved scopes
- Session data needed to keep you signed in inside Shopify admin
- For online (staff) sessions: limited staff details such as name, email, user ID, and locale — used only for authentication and operating the App
2. Information we collect directly from merchants
We store the configuration you create in the App so it persists between sessions:
- Swatch styles and appearance (colors, borders, sizes, labels, tooltips, display modes)
- Product option mappings (which options use which swatch styles)
- Product groups (linked products, display rules, publish status)
- Product bundles (products, discounts, layout, and labels)
- App settings (feature toggles, badge text, page visibility, language preference)
- Subscription / plan status for your shop (plan name, billing period, active or cancelled state)
We may also receive information you send us voluntarily (for example, a support email describing a bug).
We do not ask merchants for their customers’ contact lists, payment details, or other customer personal information.
3. Information we collect from merchants’ customers
We do not collect personal information from your customers.
Specifically:
- We do not drop advertising cookies or use tracking pixels on the storefront for our own marketing
- We do not log how individual shoppers navigate your store for analytics profiles
- We do not store customer names, emails, addresses, phone numbers, or payment details
Theme app extensions (App block / App embed) render swatches and related UI using configuration you set and product data from Shopify. They are not used to harvest shopper personal data for us.
If a shopper’s browser requests storefront assets, standard technical request metadata may appear in infrastructure logs (for example IP address or user agent) for security and reliability. We do not use that data to identify shoppers or build marketing profiles.
4. How we use the information
We use the information above only to:
- Authenticate and operate the App inside Shopify admin (session tokens / OAuth — no reliance on third-party cookies for core auth)
- Provide swatches, product groups, and product bundles as described in our App Store listing
- Save settings to our database and sync configuration to Shopify app metafields so your theme can display them
- Enforce plan limits and manage subscriptions via Shopify App Pricing / Shopify Billing API (we never process app charges off-platform)
- Respond to support requests, fix bugs, and maintain security
- Comply with law and Shopify’s mandatory privacy webhooks
We do not:
- Sell merchant or customer personal information
- Use store data for unrelated advertising or interest-based marketing
- Contact your customers
- Circumvent Shopify checkout, billing, or core platform workflows
5. How long we keep data
We keep App data while the App is installed and as needed to provide the service.
| Event | What happens |
|---|---|
| App in use | Sessions, settings, groups, bundles, and subscription records are retained to operate the App |
| Uninstall | We delete shop sessions and related App data from our database in response to Shopify’s uninstall webhook |
shop/redact | After Shopify’s required waiting period, we permanently delete remaining shop data from our systems |
| Support emails | Kept only as long as needed to resolve your request |
Configuration stored as Shopify app metafields on your store is governed by Shopify’s uninstall and retention rules after the App is removed.
To request earlier deletion of data we hold, email codexianlabs@gmail.com with your shop domain.
6. Shopify privacy compliance webhooks
We subscribe to Shopify’s mandatory privacy webhooks:
| Webhook | Our response |
|---|---|
customers/data_request | No customer personal data is stored — nothing to disclose |
customers/redact | No customer personal data is stored — nothing to erase |
shop/redact | Delete all shop-related App data from our database (sessions, settings, swatches, groups, bundles, subscriptions) |
7. Where data is stored and international transfers
- Our systems: App sessions and configuration are stored on secure cloud infrastructure (currently hosted in the United States).
- Shopify: OAuth, Admin API access, billing, webhooks, and store metafields remain on Shopify’s platform.
We are not established as a company office in the European Economic Area. If you operate a store in the EEA, UK, Switzerland, or another region, your information may be processed in the United States or other countries where our service providers operate. Where required, we take steps designed to apply appropriate safeguards for international transfers.
8. How we share information
We do not sell personal information. We share data only as needed to run the App:
| Recipient | Purpose |
|---|---|
| Shopify | Authentication, APIs, billing, webhooks, and platform hosting |
| Hosting / infrastructure providers | Server hosting, database, backups, TLS termination |
| Legal authorities | When required by law, regulation, or valid legal process |
Service providers may process data only to perform services for us and are expected to protect it appropriately.
9. Security
Consistent with Shopify App Store security expectations, we protect data in transit and at rest using reasonable measures, including:
- Valid TLS/HTTPS for all App traffic
- Access controls and secure storage of API credentials / session tokens
- Least-privilege API scopes (only what the App needs)
No method of transmission or storage is 100% secure. If you believe your data has been compromised, contact us immediately at codexianlabs@gmail.com.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal information we hold about you.
You can also:
- Uninstall the App to stop further collection and trigger deletion workflows
- Manage staff access and App permissions in Shopify admin
- Contact Shopify for data controlled solely by Shopify
To exercise rights related to data we hold, email codexianlabs@gmail.com with your shop domain and request. We will respond within a reasonable time and as required by applicable law.
California (CCPA/CPRA) and similar US state laws
We do not sell or share personal information for cross-context behavioral advertising. You may request disclosure or deletion of personal information we collect by contacting us.
EEA, UK, and Switzerland (GDPR)
Where GDPR applies, our typical lawful bases are:
- Contract — providing the App you installed
- Legitimate interests — securing and improving the App, balanced against your rights
- Legal obligation — complying with law and Shopify platform requirements
You may lodge a complaint with your local supervisory authority. We encourage you to contact us first.
11. Children’s privacy
The App is for merchants operating businesses. It is not directed at children under 16. We do not knowingly collect personal information from children.
12. Third-party services and links
Our documentation or support materials may link to third parties (for example Shopify or YouTube). Their privacy practices are governed by their own policies. Billing for paid App plans is processed by Shopify under Shopify’s terms.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the Last updated date above. Material changes may also be noted in the App or App Store listing where appropriate.
Continued use of the App after an update means you accept the revised policy.
14. Contact us
Questions about this Privacy Policy or our data practices:
Codexian Labs
Email: codexianlabs@gmail.com
Web: codexianlabs.com
For App Store listing purposes, this page’s public URL is:
https://docs.colorswatches.codexianlabs.com/docs/legal/privacy-policy