Privacy policy
This policy explains what information Tagsy ("the app," "we," "us") collects when a merchant installs it on a Shopify store, why we collect it, and how it's stored, retained, and deleted. It applies to the Tagsy Shopify app only.
When you install Tagsy, Shopify's OAuth process shares basic account details with us: your store's domain, the installing staff account's name, email address, and locale, whether that account is the store owner, and an access token that lets the app make requests to your store on your behalf. We use this solely to authenticate requests and identify which store a request belongs to.
Tagsy reads product, inventory, and theme data from your store — for example, product titles, inventory levels, tags, collections, and pricing/discount status — so that badge rules can evaluate correctly and so we can confirm the app embed is enabled in your theme. Tagsy does not modify your products, themes, or any other store data.
Badge definitions, styling choices, placement rules, and campaigns that you configure inside Tagsy are stored so the app can render them on your storefront and let you edit them later. This content is created by you, not collected from a third party.
When a badge is shown or clicked on your storefront, we record an anonymous event containing only your store's domain, the badge definition ID, the product ID, and a timestamp. We do not collect any visitor-identifying information as part of this — no name, email, IP address, device ID, or cookie is attached to these events, and the app does not set cookies or use browser storage on your storefront.
Tagsy never accesses or stores your customers' personal information — names, email addresses, physical addresses, order history, or payment details. The app has no functionality that reads customer or order data.
We use the information above only to operate Tagsy: authenticating requests, evaluating your badge rules against current product and inventory data, rendering badges on your storefront, showing you analytics inside the app, and confirming your subscription status. We don't use it for advertising, don't build profiles of your customers, and don't sell or rent any data to third parties.
App and analytics data is stored in a PostgreSQL database hosted by Supabase. A short-lived cache of storefront badge data is kept in Redis, hosted by Upstash, purely to speed up storefront rendering; entries expire automatically and are not a system of record. The app itself is hosted on Vercel. These providers act as our data processors and only process data on our instructions to operate the app.
If you uninstall Tagsy, all data associated with your store — badges, rules, campaigns, analytics, configuration, and your session — is deleted automatically. As a safety net, Shopify's mandatory shop/redact webhook triggers the same deletion again 48 hours after uninstall in case the immediate deletion was ever missed. Because Tagsy never stores customer personal information, the customers/data_request and customers/redact mandatory webhooks are acknowledged but require no action — there is no customer data to return or delete.
Depending on where you or your business are located, you may have rights under laws such as the GDPR or CCPA to access, correct, or delete data associated with your store. You can exercise these rights at any time by uninstalling the app, which deletes all associated data as described above, or by contacting us using the details below.
Tagsy is intended for use by Shopify merchants and is not directed at children. We do not knowingly collect information from children.
We may update this policy as the app changes. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or your data can be sent to contact.omega23@gmail.com.