1. Who we are
This Privacy Policy applies to the GDPR Cookie Banner Shopify application and related marketing pages hosted at https://gdpr-production-5d03.up.railway.app.
The controller is QAIMOS LTD, a company registered in the United Kingdom. Director: Vasilij Sviridov.
Contact (placeholders for support / general): support@qaimos.co.uk (support) · hello@qaimos.co.uk (general).
2. What this app does
GDPR Cookie Banner is a Shopify embedded app with a Theme App Embed. Merchants design a cookie consent banner in Shopify admin and publish it to the storefront. The app logs anonymous visitor consent decisions for compliance evidence.
3. Data we process
3.1 Merchant / shop data
- Shop domain (e.g. your-store.myshopify.com)
- OAuth / offline access tokens (and related refresh / expiry metadata) so the app can operate for the installed shop
- Banner settings (copy, layout, colours, language/translation overrides, policy URL, feature toggles)
- Optional billing identifiers if paid plans are used (e.g. Stripe customer / subscription references)
- Detected cookie catalog entries associated with the shop (names/categories you configure or detect)
3.2 Storefront consent logs (anonymous)
- visitor_id — anonymous identifier generated/provided by the storefront banner
- Hashed IP address (SHA-256) — not stored in clear text
- User agent string
- Consent choices (e.g. analytics / marketing / social) and optional consent version
- Timestamp of the consent event
We do not store Shopify customer PII profiles (no customer email, phone, or name dossiers from Shopify Customer objects for consent logging).
3.3 Marketing pages (this site)
These static pages are informational. They may set strictly necessary cookies required for hosting/security, and any analytics cookies only if clearly disclosed and consented where required. Prefer browsing without non-essential trackers; contact us if you need a cookie inventory for a specific deployment.
4. Purposes
- Provide, secure, and maintain the Shopify app for the installing merchant
- Render and update the storefront consent banner according to merchant settings
- Record anonymous consent evidence for the merchant’s compliance needs
- Respond to Shopify mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact, app/uninstalled)
- Process subscriptions/billing if a paid plan is active
- Respond to support requests you send us
5. Legal bases (UK GDPR / EU GDPR)
- Contract — processing necessary to provide the app you install and configure (Art. 6(1)(b))
- Legitimate interests — securing the service, preventing abuse, improving reliability, and maintaining anonymous audit logs proportionate to those interests (Art. 6(1)(f)); you may object where applicable
- Legal obligation — where we must respond to lawful requests or platform requirements
Merchants remain controllers for how the banner is presented on their storefront and for their own privacy notices. QAIMOS LTD processes shop and consent-log data as described here to operate the app.
6. Retention
- Shop settings & tokens — retained while the app is installed; deleted or anonymised after uninstall / shop redact webhook processing, subject to short backup windows
- Consent logs — retained for the merchant’s compliance needs while installed; removed with shop data on uninstall/redact, or earlier on customer-linked redact where a matching visitor_id is found
- Support emails — retained as long as needed to resolve the request
7. Processors & subprocessors
- Shopify — app distribution, OAuth, admin embedding, and storefront Theme App Embed delivery
- Railway — application hosting (production URL above) and related infrastructure
- Stripe — payment processing if billing for paid plans is enabled
8. International transfers
Hosting and subprocessors may process data in the UK, EEA, United States, or other countries. Where required, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses offered by providers, plus technical measures (encryption in transit, hashed IPs for consent logs).
9. Your rights
Merchants: you may access, correct, or delete shop configuration by using the app and/or uninstalling; uninstall and Shopify shop/redact flows remove shop-associated data from our database as implemented.
Store visitors: the merchant’s store privacy policy is primary. Our consent logs are anonymous (visitor_id, hashed IP, user agent). Where a Shopify customer data request/redact webhook provides a customer id that matches a stored visitor_id, we search and redact matching consent rows.
Under UK/EU GDPR you may have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with the ICO (UK) or your local supervisory authority. Contact support@qaimos.co.uk.
10. Children
The app is directed at Shopify merchants (businesses), not children.
11. Changes
We may update this policy. The “Last updated” date at the top will change. Material changes may also be noted in the app changelog.
12. Contact
QAIMOS LTD · Director Vasilij Sviridov
Support: support@qaimos.co.uk (placeholder labelled for support)
General: hello@qaimos.co.uk (placeholder labelled for general enquiries)