Winslet Age Verification
Privacy Policy
Last updated: August 13, 2026
1. Introduction
Your privacy matters to us. Winsletapps (“we,” “us,” or “our”) develops and operates the Shopify app Winslet Age Verification (the “App”). This Privacy Policy explains how we collect, use, store, share, and protect information when a merchant installs and uses the App, and when a merchant’s storefront visitors interact with the App’s age verification popup and checkout protection.
By installing the App, the merchant agrees to the practices described here.
Scope: This Privacy Policy applies only to information collected through the App.
Roles: When a Shopify merchant installs the App, that merchant is the data controller of its store and customer data. We act as a data processor, handling this data on the merchant’s behalf to provide the App’s features.
2. Information We Collect
2.1 Store data accessed through Shopify
The App requests the following access scopes: write_app_proxy, read_validations, write_validations, read_themes, unauthenticated_write_checkouts. This allows the App to run the storefront age verification endpoint, register and configure the Shopify Function that enforces age restrictions at checkout, embed the age verification popup as a theme app block, and write a signed verification result onto the shopper’s own cart so checkout enforcement can confirm it. The App does not request access to customer names, email addresses, phone numbers, or order history, and does not use those access scopes.
2.2 Age verification submissions
When a storefront visitor responds to the age verification popup, the App receives either a Yes/No confirmation or a self-reported date of birth, depending on how the merchant has configured the App. This value is used only, at the moment of submission, to calculate whether the visitor meets the merchant’s configured minimum age. The App does not permanently store the submitted date of birth. What is retained is the outcome of that check — a signed pass/fail result with a timestamp, minimum age, and verification method — written as an app-owned metafield on the shopper’s cart and, for repeat visits, in a signed cookie on the visitor’s device.
2.3 Customer tags (for logged-in shoppers)
If a merchant configures tag-based exemptions (for example, treating already-verified or B2B customers as trusted), the App reads the tags already present on that customer’s account through Shopify’s checkout validation Function. The App does not modify customer records or tags.
2.4 Usage analytics
The App records aggregate, shop-level counts of verification events — such as how many times the popup was shown, how many attempts passed, failed, or were flagged underage, and how many checkouts were held for verification — to power the App’s analytics dashboard. These counts are not linked to an individual shopper’s identity.
2.5 Information you provide to us directly
If you contact us for support, we collect the details you provide, such as your name, email address, and message.
3. How We Use Information
- Operate the storefront age verification popup and evaluate the merchant’s configured display rules
- Enforce age restrictions at checkout through the Shopify checkout validation Function
- Show the merchant aggregate analytics about verification activity
- Respond to support requests
- Monitor, troubleshoot, and improve the App
- Meet legal and regulatory obligations, including Shopify’s compliance webhook requirements
We do not sell personal information.
4. Legal Bases for Processing (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on: performance of a contract, to provide the App; legitimate interests, to operate and secure the App and enforce configured age restrictions; and legal obligation. For store and customer data processed on a merchant’s behalf, the merchant determines the legal basis as data controller.
5. How We Share Information
- Shopify — the App runs on the Shopify platform and exchanges data with Shopify’s APIs, including the Admin, Storefront, and Functions APIs, to function.
- Service providers (subprocessors) — we use Fly.io and Neon to host the App and its data. These providers process data only under our instructions.
- Legal and safety — we may disclose information where required by law.
- Business transfers — if we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction.
We do not disclose personal information to third parties for their own marketing.
6. Data Retention and Deletion
Verification outcomes are retained only as long as needed to enforce the merchant’s remember-visitor setting or to complete an in-progress checkout, after which they expire automatically. Aggregate analytics counts are retained for as long as the App is installed, to power the App’s reporting.
When a merchant uninstalls the App, we delete the shop’s data within [X hours], unless a longer period is required by law.
We comply with Shopify’s mandatory compliance webhooks:
- customers/data_request — we return any stored data linked to the specified customer. In most cases this is limited to aggregate verification-outcome records, as the App does not retain submitted dates of birth.
- customers/redact — we permanently delete any stored identifiers linked to the specified customer.
- shop/redact — we delete the shop’s data after uninstall.
7. Data Security
We take reasonable technical and organizational measures to protect information, including HTTPS encryption in transit, encrypted database storage at rest, and environment-secured credentials restricting system access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International Data Transfers
We may process and store information in [country/region]. Where required, we put appropriate safeguards in place for international transfers.
9. Your Rights
Depending on your location, you may have the right to access, correct, delete, or restrict the use of your personal information, object to certain processing, request data portability, and withdraw consent. To exercise these rights for data we control directly, contact us using Section 12.
If your request concerns data submitted to a specific merchant’s store, please contact that merchant directly, as they control that data. We will assist the merchant as their processor.
10. Children’s Privacy
The App is business software used by merchants to restrict storefront access by age, and is not directed to children under 16. The App does not permanently store a visitor’s submitted date of birth, and its purpose with respect to underage visitors is limited to denying access — not collecting or retaining their information. We do not knowingly collect personal information from children through the App’s own administrative interfaces.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date. Significant changes may be communicated through the App or by email.
12. Contact Us
Winsletapps
ajmal.developer@gmail.com