Privacy Policy
This Privacy Policy explains how AppX (“AppX”, “we”, “us”, or “our”) handles information in connection with the AppX - Product Specs Table application (the “App”) for the Shopify platform, and this website, hiappx.com (the “Site”).
AppX is operated by Ibnul Ferdous, an independent software developer based in Dhaka, Bangladesh. For any privacy question or request, contact support@hiappx.com. Our full postal address is available on request to that email.
By installing the App or using the Site, you agree to this Policy. If you do not agree, please do not install the App or use the Site.
Who this Policy is for
The App is a business tool used by Shopify merchants. The information in this Policy concerns the merchant (the store owner installing the App). Because the App does not touch shopper data, this Policy is not directed at your customers.
What we collect and store
We store the following in our own database (hosted by Neon - see Section 5):
- Your store’s Shopify domain (e.g.
your-store.myshopify.com). - A Shopify access token that authorizes the App to work with your store. This is used only to operate the App and is deleted when you uninstall.
- Specification-table templates - the table names, row labels, the fixed text you type, and references to which Shopify field or metafield each row should display.
- Styling settings - the visual options you choose for your tables.
- Product-assignment settings - which templates apply to which products, including any exclusions.
- App state - such as onboarding status and, if you subscribe to a paid plan, your subscription and plan status.
When you contact us for support - through the in-app live chat or by email - we process the content of your messages and any details you choose to share (such as your name, email address, and a description of the issue), together with basic technical session metadata. We use this solely to respond to and resolve your request. When you use in-app live chat, we also share limited merchant-account details - your store name, contact email, shop domain, and plan - with our chat provider (Crisp) to identify and route your conversation (see Sections 4 and 5); no shopper or buyer information is involved.
- We do not store your customers’ names, contact details, orders, or any buyer information.
- We do not store payment card details. Billing is handled entirely by Shopify; we never see or store your card information.
Information the App reads from your Shopify store
To do its job, the App is granted permission to access parts of your store, including your product information (for example: vendor, product type, SKU, price, inventory, weight, and your product metafields) and to manage App-owned data (metaobjects and reserved metafields) that the App creates inside your store to deliver spec tables to your storefront.
The App also reads your store’s name and contact/reply-to email live from the Shopify Admin API. These identify you to our support team during in-app live chat - so an operator can see which store they are helping instead of an anonymous visitor - and are shared with Crisp for that purpose only (see Section 5). This is merchant-account data about your store; we still do not read your customers’ names, orders, or any buyer information.
Two things worth knowing:
- We use product information to let you choose what each table row should show (the field and metafield pickers) and to build your tables.
- The actual specification values shown to shoppers on your product pages are read live from your own Shopify store by the storefront component at page-render time. Those resolved values are not copied into or stored in our database - our database stores only which field or metafield a row points to, not its per-product value.
Service providers (sub-processors)
We use a small number of trusted providers to run the App and the Site. Each processes data only to provide their service to us:
These providers operate cloud infrastructure that may be located outside Bangladesh. Where data is transferred internationally, we rely on the safeguards these providers maintain; where required, such transfers are covered by Standard Contractual Clauses or equivalent safeguards. By using the App you acknowledge this processing.
Cookies and tracking
The App and the storefront it powers behave differently, so we describe each separately:
- Storefront (your shoppers): the specification table the App renders on your product pages sets no cookies and performs no tracking of any kind. Only Shopify’s own essential cookies - which Shopify sets to run your store - apply there; our App adds nothing to that page’s cookies or browser storage.
- Embedded app admin (you, the merchant): the App runs embedded in the Shopify admin and uses strictly necessary session cookies to keep you securely signed in. This admin area also loads the Crisp live-chat widget, which sets its own cookies and browser local storage so that a support conversation stays continuous across page loads. These are used only to operate chat and support - not for advertising or cross-site tracking - and the Crisp widget is never loaded on your storefront, so it never touches your shoppers.
We do not use analytics or advertising cookies anywhere. This marketing website (hiappx.com) is a static page that sets no analytics or tracking cookies of its own; our host (Cloudflare) processes only standard, aggregated server-request information to deliver and secure the Site.
If we introduce website analytics in the future, we will update this Policy and, where required, ask for your consent before setting non-essential cookies.
Data retention and deletion
- While the App is installed, we keep your configuration so the App can function.
- When you uninstall the App, your Shopify access token and session are deleted immediately. Your saved templates, styling, and assignment settings are retained temporarily so that if you reinstall shortly afterward, your work is still there.
- Full erasure: in line with Shopify’s requirements, if your store remains uninstalled, Shopify notifies us and we erase all of your store’s data from our database within about 48 hours of that notification. This removes your store record, templates, styling, assignment settings, and related data.
- App-owned data inside your Shopify store (the metaobjects and reserved metafields the App created) is removed automatically by Shopify when you uninstall the App.
- Support conversations (live chat and email) are retained only as long as needed to provide support and to meet our legal obligations.
We also implement Shopify’s mandatory privacy webhooks. Because the App holds no customer personal data, requests to disclose or delete a customer’s data have nothing to return or remove; the store-erasure request is the one that performs a real deletion, as described above.
How we use information
We use the information described above only to:
- Provide and operate the App’s features (building and displaying your spec tables);
- Manage your plan, subscription, and billing status through Shopify;
- Respond to your support requests;
- Maintain the security, integrity, and reliability of the App; and
- Meet our legal and Shopify platform obligations.
We do not sell your data, and we do not use it for advertising or profiling.
Legal bases for processing (EEA/UK). Where the GDPR applies, we process your information on the following bases: performance of a contract (to provide the App you installed); legitimate interests (to secure, maintain, and improve the App); legal obligation (to meet Shopify platform and applicable legal requirements); and consent (where we ask for it, such as any future non-essential cookies).
Your rights
Depending on where you are based (for example, under the EU/UK GDPR or the California CCPA), you may have rights to access, correct, delete, or restrict the processing of your personal information, and to object to certain processing.
Because the App stores merchant configuration rather than personal customer data, most of your data can be removed simply by uninstalling the App (see Section 7). For any other request - including a copy of the data we hold about your store, or our full postal address for a formal inquiry - email support@hiappx.com and we will respond within 30 days (or sooner where required by law).
If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
A Data Processing Agreement (DPA) is available on request to merchants who require one for their own compliance.
Security
We take reasonable measures to protect the information we hold, including encryption of data in transit (HTTPS/TLS) and access controls on our systems and providers. No method of transmission or storage is completely secure, but we work to protect your information and to address issues promptly. If we become aware of a data breach affecting your information, we will notify you and the relevant authorities as required by applicable law.
Children
The App is a business tool intended for Shopify merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, take reasonable steps to notify merchants. Your continued use of the App or Site after an update means you accept the revised Policy.
Contact us
Dhaka, Bangladesh
Our full postal address is available on request.