Privacy policy

Tagsy Privacy Policy

Last updated: July 25, 2026

This policy explains what information Tagsy ("the app," "we," "us") collects when a merchant installs it on a Shopify store, why we collect it, and how it's stored, retained, and deleted. It applies to the Tagsy Shopify app only.

Information we collect

Merchant account information

When you install Tagsy, Shopify's OAuth process shares basic account details with us: your store's domain, the installing staff account's name, email address, and locale, whether that account is the store owner, and an access token that lets the app make requests to your store on your behalf. We use this solely to authenticate requests and identify which store a request belongs to.

Store data accessed through the Shopify API

Tagsy reads product, inventory, and theme data from your store — for example, product titles, inventory levels, tags, collections, and pricing/discount status — so that badge rules can evaluate correctly and so we can confirm the app embed is enabled in your theme. Tagsy does not modify your products, themes, or any other store data.

Content you create in the app

Badge definitions, styling choices, placement rules, and campaigns that you configure inside Tagsy are stored so the app can render them on your storefront and let you edit them later. This content is created by you, not collected from a third party.

Storefront badge analytics

When a badge is shown or clicked on your storefront, we record an anonymous event containing only your store's domain, the badge definition ID, the product ID, and a timestamp. We do not collect any visitor-identifying information as part of this — no name, email, IP address, device ID, or cookie is attached to these events, and the app does not set cookies or use browser storage on your storefront.

What we don't collect

Tagsy never accesses or stores your customers' personal information — names, email addresses, physical addresses, order history, or payment details. The app has no functionality that reads customer or order data.

How we use this information

We use the information above only to operate Tagsy: authenticating requests, evaluating your badge rules against current product and inventory data, rendering badges on your storefront, showing you analytics inside the app, and confirming your subscription status. We don't use it for advertising, don't build profiles of your customers, and don't sell or rent any data to third parties.

Where data is stored

App and analytics data is stored in a PostgreSQL database hosted by Supabase. A short-lived cache of storefront badge data is kept in Redis, hosted by Upstash, purely to speed up storefront rendering; entries expire automatically and are not a system of record. The app itself is hosted on Vercel. These providers act as our data processors and only process data on our instructions to operate the app.

Data retention and deletion

If you uninstall Tagsy, all data associated with your store — badges, rules, campaigns, analytics, configuration, and your session — is deleted automatically. As a safety net, Shopify's mandatory shop/redact webhook triggers the same deletion again 48 hours after uninstall in case the immediate deletion was ever missed. Because Tagsy never stores customer personal information, the customers/data_request and customers/redact mandatory webhooks are acknowledged but require no action — there is no customer data to return or delete.

Your rights

Depending on where you or your business are located, you may have rights under laws such as the GDPR or CCPA to access, correct, or delete data associated with your store. You can exercise these rights at any time by uninstalling the app, which deletes all associated data as described above, or by contacting us using the details below.

Children's privacy

Tagsy is intended for use by Shopify merchants and is not directed at children. We do not knowingly collect information from children.

Changes to this policy

We may update this policy as the app changes. Material changes will be reflected by updating the "Last updated" date above.

Contact

Questions about this policy or your data can be sent to contact.omega23@gmail.com.