Política de privacidad

Draft — release and policy review pending

This Privacy Policy applies to the “365 Theme Kit” Shopify app provided by 365Store. Theme injection and upgrades are currently disabled pending safety review and required Shopify approval.

1. Data We Process

The App does not request customer, order, discount, inventory or payment-card data for its theme features. Merchant/staff account information is distinct from storefront customer data.

CategoryContentPurposeStorage and deletion
Authentication and store identityShop domain, session identifiers/state, scopes, access tokens, optional refresh tokens and expiry information; where Shopify supplies online-session information, staff user ID, name, email, locale and account flagsAuthenticate the installation and authorized Shopify accessStored in the Session table; deletion is described below
Theme accessTheme identifiers, metadata and file contents needed for enabled theme featuresTheme inventory and, only if released, merchant-requested injection/upgradesShopify hosts merchant themes; app job records track identifiers, paths, status and errors rather than a backup of the merchant theme
Job recordsShop/theme identifiers, item/package keys or versions, idempotency keys, timestamps, written-file paths, status and error summariesOperation history, duplicate prevention and diagnosticsStored in InjectionJob and UpgradeJob; deletion is described below
BillingSubscription status provided by ShopifyDetermine plan accessShopify handles billing and its own records; the App does not store payment-card details

Authentication data uses the standard Prisma session adapter. The App does not implement application-level encryption of stored tokens. Infrastructure security and retention settings require operational review; we do not claim verified token encryption or a fixed retention period.

2. Data Use

We use this information to operate and support the App. We do not sell App data or use it for advertising. Theme features do not collect storefront visitor behavior or call external AI or translation services. Hosting services may process request metadata and operational logs.

3. Service Providers

  • Shopify processes platform, authentication, theme and billing data under its own terms and policies.
  • Railway provides app/database hosting infrastructure; Cloudflare provides website and delivery infrastructure. These providers may process data and technical metadata needed to host, deliver and secure the service. Provider configurations, locations and retention need review before release.

4. Theme Writes and Release Status

Injection and upgrades are disabled pending safety review and required Shopify approval. File-collision handling, preservation of merchant customizations, recovery and verification still require validation. The current updater must not be treated as guaranteeing preservation of all existing files, templates or settings. Do not rely on the App as a theme backup; duplicate your theme before any future write operation.

5. Deletion and Merchant Requests

  • After an authenticated app/uninstalled or shop/redact webhook is successfully processed, the App deletes that shop’s Session, InjectionJob and UpgradeJob rows in one database transaction, even if no session remains. Repeated delivery is safe; a processing failure is not acknowledged as success.
  • This removes rows from the active app database, not Shopify-hosted theme files or Shopify billing records. Shared LibraryItem and ThemePackage catalogs are not shop-owned and remain.
  • These handlers do not purge infrastructure logs or backups. Copies may remain there subject to provider configuration and applicable legal requirements. Backup/log retention and deletion procedures are pending review; we do not promise immediate deletion from all systems or an unverified deadline.
  • Contact support@365storedev.com to request access, correction, export or deletion. We may need to verify your authority. Customer privacy webhook handlers acknowledge that the App does not maintain storefront customer records; production delivery and operational procedures still require verification.

6. Contact

Privacy-related requests: support@365storedev.com

← 365Store