Privacy policy
This policy explains which data the Shopify app Lineup ("the app") processes, why, and what rights you have. It applies to merchants who install the app on their Shopify store.
Controller
BeardStyle.ch di Bonazzi, Via Rivamonte 10, 6572 Quartino, Switzerland. Contact: [email protected].
Data the app processes
- Store data: your store's myshopify.com domain and the access token Shopify issues when you install the app, used to read and reorder your collections on your behalf.
- App settings: the collections you choose to manage, the sorting criterion, the IDs of pinned products and the reference order of each managed collection (product IDs only).
- Technical records: the queue of reorder jobs with their status and errors, and the IDs of webhook notifications received from Shopify, used to run the service reliably.
- Server logs: technical logs with your store's domain, collection IDs and error messages, used to operate and troubleshoot the service.
The app reads product and collection information from Shopify (status, availability, order) only to compute the new order; it does not store product details such as names, prices or stock. The app does not access, collect or store any personal data of your customers (no customer, order or payment data).
Purpose and legal basis
The data is processed only to provide the service you install: keeping your collections in order (performance of a contract, Art. 6(1)(b) GDPR; Swiss Federal Act on Data Protection, nLPD). Subscription billing is handled by Shopify; the app only checks which plan your store has.
Service providers and data location
- Shopify (platform, authentication and billing).
- DigitalOcean (application hosting, Frankfurt, Germany).
- Neon (database hosting, Frankfurt, Germany, on Amazon Web Services).
Data is stored in the European Union. Some providers are companies based in the United States; where data may be accessed from outside Switzerland or the EU, transfers rely on the safeguards the providers offer (such as standard contractual clauses or the Swiss-U.S. and EU-U.S. Data Privacy Frameworks).
Retention and deletion
- Completed and failed reorder jobs and webhook records are deleted after 7 days.
- When you uninstall the app, your settings, queued jobs and access token are deleted. Shopify also sends a deletion request 48 hours after uninstall, which erases any remaining data for your store.
Cookies
The app runs inside the Shopify admin and uses Shopify's session tokens for authentication. It sets no tracking or advertising cookies.
Your rights
Under the nLPD and the GDPR you can request access to, correction or deletion of your data, restriction of processing and data portability, and you can object to the processing. Write to [email protected]. You can also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or with a data protection authority in the EU.
Changes
If this policy changes, the new version is published on this page with its date.