Winslet Product Options
Privacy Policy
Last updated: August 21, 2026
1. Introduction
Your privacy matters to us. Winsletapps (“we,” “us,” or “our”) develops and operates the Shopify app Winslet Product Options (the “App”). This Privacy Policy explains how we collect, use, store, share, and protect information when a merchant installs and configures the App, and when the App renders, prices, and validates product options on a merchant’s storefront.
By installing the App, the merchant agrees to the practices described here.
Scope: This Privacy Policy applies only to information collected through the App.
Roles: When a Shopify merchant installs the App, that merchant is the data controller of its store and customer data. We act as a data processor, handling this data on the merchant’s behalf to provide the App’s features.
2. Information We Collect
2.1 Store data accessed through Shopify
The App requests the following access scopes: write_products, write_metaobjects, write_metaobject_definitions, read_cart_transforms, write_cart_transforms, write_app_proxy, read_validations, write_validations. This allows the App to create the metaobjects and metafields used to store option-set configuration, register and configure the Shopify Cart Transform and Validation Functions that price and enforce options at checkout, and serve the storefront option widget through an app proxy. The App does not request read_customers or write_customers, and does not access customer names, email addresses, phone numbers, or order history.
2.2 Storefront eligibility data
When a customer views a product configured with options, the App’s storefront extension may receive that customer’s Shopify customer ID and customer tags directly from the merchant’s theme, in order to determine whether the customer is eligible to see a given option set. This value is used only, at the moment of the page request, for that eligibility check. The App does not permanently store the customer ID or tags, and does not link them to any other personal information.
2.3 Cart and pricing data
Selected option values, calculated measurements, and pricing adjustments are attached to the cart as line item properties and processed by the App’s Cart Transform and Validation Functions. These Functions run inside Shopify’s own infrastructure — this cart and pricing data is never transmitted to or stored on our servers.
2.4 Merchant configuration data
Option sets, fields, logic rules, pricing rules, product and collection assignments, design settings, and storefront integration settings (such as price-display selectors) that a merchant creates in the App are stored in our database, keyed to the merchant’s shop domain. This data does not include any customer personal information.
2.5 Information you provide to us directly
If you contact us for support, we collect the details you provide, such as your name, email address, and message.
3. How We Use Information
- Operate the option-set builder and apply merchants’ configuration on their storefront
- Calculate option pricing and validate required options at cart and checkout
- Respond to support requests
- Monitor, troubleshoot, and improve the App
- Meet legal and regulatory obligations, including Shopify’s compliance webhook requirements
We do not sell personal information.
4. Legal Bases for Processing (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, to provide the App; legitimate interests, to operate and secure the App; and legal obligation. For store and customer data processed on a merchant’s behalf, the merchant determines the legal basis as data controller.
5. How We Share Information
- Shopify — the App runs on the Shopify platform and exchanges data with Shopify’s Admin, Storefront, and Functions APIs to function.
- Service providers (subprocessors) — we use Fly.io and Neon to host the App and its data. These providers process data only under our instructions.
- Legal and safety — we may disclose information where required by law.
- Business transfers — if we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction.
We do not disclose personal information to third parties for their own marketing.
6. Data Retention and Deletion
Merchant configuration data (option sets, pricing rules, logic rules, design and storefront settings) is retained for as long as the App remains installed and is needed to provide its features. Cart and pricing data processed by our Functions is not stored on our servers at all — it is processed transiently within Shopify’s own infrastructure.
When a merchant uninstalls the App, we delete the shop’s data within 48 hours, unless a longer period is required by law.
We comply with Shopify’s mandatory compliance webhooks:
- customers/data_request — the App does not retain any customer personal information, so there is no personal data held about the specified customer to return.
- customers/redact — the App does not retain any customer personal information, so there is nothing to redact.
- shop/redact — we delete the shop’s data after uninstall.
7. Data Security
We take reasonable technical and organizational measures to protect information, including HTTPS encryption in transit, encrypted database storage at rest, and environment-secured credentials restricting system access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Data Transfers
We may process and store information in the United States. Where required, we put appropriate safeguards in place for international transfers.
9. Your Rights
Depending on your location, you may have the right to access, correct, delete, or restrict the use of your personal information, object to certain processing, request data portability, and withdraw consent. To exercise these rights for data we control directly, contact us using Section 12.
If your request concerns data submitted to a specific merchant’s store, please contact that merchant directly, as they control that data. We will assist the merchant as their processor.
10. Children’s Privacy
The App is business software used by merchants to configure product options, and is not directed to children under 16. We do not knowingly collect personal information from children through the App’s own administrative interfaces.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date. Significant changes may be communicated through the App or by email.
12. Contact Us
Winsletapps
ajmal.developer@gmail.com