Privacy Policy & Data Security Standards

Last Updated: August 26, 2026 • Fully compliant with Shopify App Store Partner Requirements, EU GDPR, and California CCPA

01Overview & Scope of Policy

This Privacy Policy is issued by PGS Tech Limited (Gray Poplar, "we", "us", or "our"), governing the collection, processing, and protection of data when you install and operate the GP Product Options & Customizer application (the "App") on your Shopify-powered merchant storefront.

We respect the commercial sensitivity of merchant configurations and the privacy of end-consumers. This policy details the lifecycle of all data ingested during option mapping, conditional logic evaluation, storefront rendering, and checkout payload dispatch.

Global Compliance Certifications

The App complies with the Shopify Partner Program Agreement, EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Canada PIPEDA standards.

02Information We Collect

To deliver sub-millisecond custom option rendering, differential price addons, and dynamic If/Then logic, we collect only the minimal necessary dataset categorized into four streams:

Merchant Account Details

• Registered `myshopify.com` domain identifier • Primary store contact email and business legal name • Primary store currency code (e.g. USD, EUR, GBP) • Installed active Shopify Theme ID (Online Store 2.0)

Option Configurations & Assets

• Custom field titles (e.g. Monogram, Swatch Colors) • High-resolution swatch assets and pattern preview URLs • Conditional logic If/Then rule expressions • Variant addon pricing surcharges and custom CSS rules

Shopper Customization Inputs

• Buyer-submitted personalization strings (monograms, text) • Buyer-uploaded artwork files for print-on-demand • Selected swatch finish, accessory, or MagSafe values (Mapped via Line Item Properties to Shopify Orders)

Performance & Security Logs

• Global CDN asset fetch latencies and cache hits • Aggregated anonymized JavaScript error telemetry • Anonymized IP hash tokens for DDoS rate limiting

03Information We NEVER Collect

GP Product Options enforces a strict zero-sensitive-data ingestion architecture. Our frontend scripts and backend microservices are physically decoupled from buyer checkout credentials:

Zero Financial & Identity Data Access Guarantee

• WE NEVER parse, intercept, or record full credit card numbers, CVVs, or bank checkout tokens; • WE NEVER track buyer cross-site browsing histories, geo-location trails, or social credentials; • WE NEVER inspect or ingest unrelated merchant financial records, inventory ledgers, or tax filings.

04How We Use Information

All collected datasets are utilized strictly to execute the core operational capabilities of GP Product Options:

  • Storefront Option Rendering: Dynamically render swatches, text fields, drop-down menus, and If/Then rules on merchant product pages.
  • Order Properties Injection: Transmit shopper selections and engraving text securely into Shopify Order Line Item Properties upon checkout for merchant fulfillment.
  • Price Surcharge Evaluation: Calculate addon charges (e.g. MagSafe Ring +$8.00) and sync differential line item totals via Shopify native checkout.
  • Merchant Support & Diagnostics: Provide responsive 1-on-1 merchant assistance to resolve theme CSS conflicts and rule troubleshooting.

05Theme Extension With Zero Residual

Legacy Shopify plugins frequently inject persistent script tags into Liquid files, causing page speed degradation even after uninstallation. GP Product Options re-architects this completely:

Shopify 2.0 Official App Embed Sandbox

• Zero Liquid Mutation: Front-end components mount strictly through native Shopify App Embed blocks without altering theme liquid files; • Instant Uninstall Cleanliness: When the App is uninstalled, Shopify immediately purges all embed scripts in milliseconds. Zero residual code remains.

06Data Storage, Security & Retention

We deploy enterprise-grade cryptographic protocols to guarantee the confidentiality, availability, and integrity of all merchant assets:

  • Dual-Layer Encryption: All API payloads mandate TLS 1.3 encryption in transit; all database tables and S3 asset buckets enforce AES-256 encryption at rest.
  • Tier-1 Cloud Infrastructure: Hosted in SOC 2 Type II and ISO/IEC 27001 certified AWS and Google Cloud data centers with 99.99% uptime SLA.
  • Role-Based Access Control: Internal access is restricted strictly to authorized engineers with mandatory Multi-Factor Authentication (MFA) and immutable audit logging.

07Shopify Mandatory GDPR Webhooks

To streamline merchant privacy compliance, GP Product Options maintains automated 24/7 integrations with Shopify's mandatory data lifecycle webhooks:

customers/data_request

Upon receiving a consumer data disclosure request via Shopify, we compile and deliver associated custom metadata within 30 days.

customers/redact

When a customer requests personal data erasure, our automated workers permanently anonymize and wipe upload assets within 48 hours.

shop/redact (店铺数据彻底擦除)

48 hours following app uninstallation, Shopify dispatches this webhook. Our database immediately and permanently purges all merchant option configurations, swatch assets, access tokens, and store records from active storage.

08Third-Party Service Providers

We NEVER monetize, sell, or rent merchant or shopper datasets. We partner exclusively with world-class, audited infrastructure sub-processors:

  • Shopify Inc.: Core ecommerce platform & Checkout APIs (Canada/USA)
  • Cloudflare, Inc.: Global edge CDN, DDoS mitigation & low-latency caching
  • Amazon Web Services (AWS): ISO-27001 certified cloud database & AES-256 asset storage

09Merchant & Shopper Privacy Rights

Under applicable global privacy frameworks (including GDPR & CCPA), you possess the following statutory rights:

  • Right of Access: Request a verifiable copy of all store configurations maintained in our systems.
  • Right to Rectification: Update or rectify inaccurate shop metadata directly in the admin dashboard.
  • Right to Erasure ("To Be Forgotten"): Request immediate and permanent purging of all merchant datasets.
  • Right to Opt-Out of Sale/Sharing: We maintain a default 100% non-sale policy for all commercial datasets.

10Contact Information & DPO

If you have questions regarding this Privacy Policy, wish to exercise privacy rights, or require an enterprise Data Processing Addendum (DPA), please contact us:

Gray Poplar Data Protection Office

PGS Tech Limited • Hong Kong R&D Center • Dedicated compliance specialists available 24/7

Contact on WhatsApp