Privacy Policy
Last updated: September 24, 2026
SizeChartKit is a Shopify app that lets a merchant create size charts and show them to shoppers as a size guide on product pages. This policy explains what data the app processes, why, and how it is protected.
SizeChartKit stores no customer (buyer) data. It requests the read_products and write_products scopes (to let the merchant pick products and collections and save a product's chart choice to it), read_files and write_files (to store chart images in the merchant's Shopify Files) and write_app_proxy (for anonymous usage counts). It requests no customer scopes, reads no orders, and never stores a shopper's name, email, address or measurements.
1. What We Process
1.1 Merchant / Store Data
The store's myshopify.com domain, an expiring Shopify access token, the subscription plan tier, and install status — the data needed to run the app for the store and bill it through Shopify. Shopify's session data for a signed-in staff member may include that staff member's name, email address, and admin language, as provided by Shopify.
1.2 Size Charts
The size charts the merchant creates (names, sizes, measurements, notes and an optional image), the rules that assign them to collections, tags, product types, vendors or countries/languages, and the products the merchant picks for a chart (product IDs and titles). Chart images are uploaded to the merchant's own Shopify Files. A published copy of the charts is saved to the store in Shopify (as app metafields) so the storefront can display it.
1.3 Anonymous Usage Counts
When a shopper opens a size guide or uses the fit finder, the storefront sends the chart's ID and the event type to the app through Shopify's app proxy. The app stores only a daily count per chart. It receives nothing that identifies the shopper, sets no cookies, and keeps no IP address. Counts are kept for 90 days.
1.4 Fit Finder
The fit finder runs entirely in the shopper's browser. Measurements a shopper types in are compared with the chart on their device and are never sent to the app or stored.
We process the minimum data needed to provide the app's value and use it only for that purpose. We do not sell data, and we do not use it for advertising or automated decision-making.
2. How We Collect It
- From Shopify, when a merchant installs the app and grants access, and through the Admin API for the products the merchant already holds.
- From the merchant, when staff create charts and assignment rules in the embedded admin.
- From the storefront, as anonymous daily usage counts (see 1.3).
3. How We Protect It
- All traffic is served over TLS 1.2+.
- Data is stored on a DigitalOcean server; production access is SSH-key-only and limited to the operator, and the host runs standard hardening. Development and production data are kept separate.
- Access tokens are stored server-side only and are never exposed to the browser.
- Because SizeChartKit holds no buyer personal data, there is no customer name, address, or payment information at rest to expose.
- We maintain a security incident-response process and will notify affected merchants of a confirmed data breach within 72 hours.
4. How Long We Keep It
- Size charts and assignment rules are kept while the app is installed so the storefront size guide stays current. Usage counts are kept for 90 days.
- When a merchant uninstalls, access tokens are deleted immediately and the store's data held by the app is deleted in response to Shopify's shop-redaction request, in all cases within 30 days of uninstall. Chart images in the merchant's Shopify Files remain part of the merchant's store data.
5. Who We Share It With
We use a small number of sub-processors, only as needed to run the service:
- DigitalOcean — server and database hosting (United States).
- Shopify — the platform the app runs on.
We do not share data with anyone else, and we never sell it.
6. Data Subject Rights (Shopify Privacy Webhooks / GDPR)
SizeChartKit implements Shopify's mandatory privacy webhooks in full. Because the app stores no customer personal data:
- A customer data request returns no customer records, because SizeChartKit holds none.
- A customer redaction has no customer data to remove.
- A shop redaction deletes all of the store's data held by the app (size charts, rules, product picks, usage counts, plan and install records, and sessions).
These support the merchant's obligations under the GDPR, the CCPA/CPRA, and similar laws. Merchants agree to SizeChartKit's terms and this policy when they install the app.
7. Changes
We will update this page when our practices change and revise the date at the top.
8. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at:
NerdLabs (operated by Joren Winge)
Email: support@nerdlabs.us
Website: nerdlabs.us