Privacy Policy
Smart Product Tagger

# Privacy Policy

Effective date: 20/05/2026
Version: 1.0

## 1. Data Controller

This Privacy Policy describes how Acme sas ("Acme", "we", "us", or "our")
collects, uses, and protects information when you use the Shopify app
"Smart Product Tagger" (the "App").

Data Controller:
- Acme sas
- VAT: 04576370615
- Registered office:  VIA LEONARDO DA VINCI 21 - 81030 - PARETE (CE)
- Contact: acmedigitalagency@gmail.com

## 2. What
Information We Collect

We only collect data strictly required to operate the App. We do NOT
collect any personal data about your store's customers (no buyer names,
emails, addresses, or order details linkable to individuals).

### From Shopify (when you install the App):
- Shop domain (e.g., your-store.myshopify.com)
- OAuth access token (encrypted, stored in our database)
- Store name and basic shop information
- Access scopes you grant during installation

### Created during App usage:
- Language preference (en or it) you set in the App
- Tag operations history: product IDs and tag names from bulk operations
  you trigger, along with timestamps and operation status

We do NOT collect, store, or process:
- End-customer personal data (names, emails, addresses, payment info)
- Order details linkable to individual customers
- Cookies for tracking, advertising, or analytics
- IP addresses for profiling purposes

## 3. Purpose and Legal Basis

We process your data exclusively to:
1. Provide the App's core functionality (product filtering, bulk tagging)
2. Maintain your active subscription and authentication session
3. Comply with legal obligations and Shopify's platform requirements

Legal bases under GDPR (Art. 6):
- Contract performance (Art. 6.1.b): processing necessary to provide the App
- Legitimate interest (Art. 6.1.f): security, fraud prevention, service operation

## 4. Data Retention

We retain your data for as long as the App is installed on your store.
When you uninstall the App, Shopify sends us an "app/uninstalled" webhook,
and we automatically delete:
- All session tokens
- All tag operation records
- All store configurations

Additionally, Shopify's mandatory GDPR webhooks are fully implemented:
- "customers/data_request": we receive and respond to data subject requests
- "customers/redact": we delete customer-related data on request (note:
  our App does not store customer-identifiable data, so these are no-op
  responses)
- "shop/redact": 48 hours after uninstall, we permanently delete all
  data associated with the shop

## 5. Data Sharing and Third Parties

We do NOT sell, rent, or share your data with third parties for marketing
purposes. Data is shared only with the following service providers, strictly
to operate the App:

- Railway (Railway Corp., USA): cloud hosting infrastructure
- Shopify Inc. (Canada/USA): platform integration, billing
- PostgreSQL database hosted on Railway

All providers are bound by Data Processing Agreements (DPAs) ensuring
GDPR-compliant safeguards.

## 6. International Data Transfers

Our hosting infrastructure (Railway) is located in the United States.
Transfers outside the European Economic Area are protected by Standard
Contractual Clauses (SCCs) approved by the European Commission, ensuring
an adequate level of data protection.

## 7. Security

We implement industry-standard security measures including:
- Encryption in transit (HTTPS/TLS)
- Encrypted database connections
- Access tokens stored encrypted at rest
- Limited access on a need-to-know basis
- Regular security updates and dependency audits

## 8. Your Rights Under GDPR

You have the right to:
- Access your data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Lod
ge a complaint with a supervisory authority (Garante Privacy,
www.garanteprivacy.it)

To exercise your rights, contact us at: acmedigitalagency@gmail.com
We respond within 30 days as required by GDPR.

## 9. Children's Privacy

The App is designed for business use by Shopify merchants. We do not
knowingly collect data from individuals under 16. If you believe a minor
has provided data, contact us immediately.

## 10. Cookies

The App itself does NOT use tracking, advertising, or analytics cookies.
Only essential session cookies are used during the Shopify OAuth handshake,
managed by Shopify's own infrastructure.

## 11. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated
via the App interface and/or email to active subscribers. The "Effective
date" at the top reflects the latest version.

## 12. Contact

For any privacy-related questions or to exercise your rights:
- Email: acmedigitalagency@gmail.com
- Postal address: Acme sas,  VIA LEONARDO DA VINCI 21 - 81030 - PARETE (CE)

## 13. Governing Law

This Privacy Policy is governed by Italian law and EU regulations
(GDPR — Regulation EU 2016/679). Disputes are subject to the exclusive jurisdiction of Italian courts.