Back to homeNovalis Studio
Legal

Privacy Policy

Last updated: February 2025

1. Introduction

Novalis Studio is an independent studio that designs and publishes Shopify applications built to optimize online stores — including novalis-free-shipping and our current and future apps. This Privacy Policy explains what data our applications access, how it is used, and how we comply with Shopify's data protection requirements as well as the GDPR and CCPA. This page is the official privacy reference URL provided to Shopify for the review of all our applications.

2. Data We Collect

Store data

To operate our applications, we access a limited set of store information exclusively through Shopify's official APIs: the merchant identifier, store name, primary domain, timezone, currency, and the configuration settings required for the app to function (such as theme block settings and shipping thresholds).

Customer data

We explicitly do not collect, store, process, or sell any personally identifiable information (PII) belonging to your store's end customers. We never access or retain banking details, credit card numbers, or any payment information. Our applications run entirely on non-personal store configuration data.

3. How We Use Data

Store data is used for the sole purpose of providing and improving our application features — for example, rendering dynamic theme blocks, displaying progressive free-shipping tiers, and applying your custom styling preferences. We do not use store data for profiling, advertising, or any purpose unrelated to the app's core functionality.

4. Data Sharing & Third Parties

We never sell, rent, trade, or share your data with advertising networks, data brokers, or any third parties for marketing purposes. Data is only processed by trusted infrastructure providers strictly necessary to host and run the applications (for example, our hosting provider), and only to the extent required to deliver the service.

5. Shopify Mandatory Webhooks Compliance

In full compliance with Shopify's Protected Customer Data requirements, all of our applications implement the mandatory GDPR webhooks:

  • customers/data_request

    When a customer requests their data, we respond to the merchant with the relevant information. As we do not store customer PII, such requests confirm that no personal customer data is held.

  • customers/redact

    Any customer-related data (if applicable) is permanently deleted within 48 hours of receiving the request.

  • shop/redact

    All store data is permanently and irreversibly deleted within 48 hours after the app is uninstalled from a store.

6. Security & Hosting

All data is transmitted over encrypted connections using HTTPS/TLS. We rely on secure session tokens for authentication with Shopify and apply industry-standard encryption for any data at rest. Our infrastructure is hosted on secure, reputable cloud platforms with modern security practices.

7. Your GDPR & CCPA Rights

Depending on your jurisdiction, you may have the right to access, rectify, restrict, or erase the data associated with your store. Because we do not store end-customer PII, these rights primarily concern store-level configuration data. To exercise any of these rights, please contact us using the details below and we will respond promptly.

8. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal and regulatory reasons. Any updates will be posted on this page with a revised "last updated" date. We encourage you to review this page periodically.

9. Contact & Support

If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please reach out to us:

contact@novalis-studio.com