Legal
Privacy Policy
Last updated 12 September 2026. This describes how the Qinci Shopify app handles data. It is written for the merchants who install Qinci and for the shoppers whose data may pass through it.
Who we are
Qinci ("we", "the app") is a Shopify app that reads the ingredient lists in a merchant’s catalogue and recommends complementary products, with a stated reason for each suggestion. When you install Qinci, you (the merchant) are the data controller for any personal data of your customers; we act as your data processor. Contact: qinci@qavlar.tech.
What we process
Catalogue data (not personal): product titles, descriptions, prices, images, handles, and ingredient (INCI) lists, read from the Shopify Admin API and product metafields.
Order data, from the orders/paid webhook: the order ID, its line items, order total, the customer’s email address, and the customer’s locale. Used only to measure which orders included a product Qinci recommended (attribution reporting shown to the merchant).
Storefront widget: the current cart contents (product titles and ingredient lists), the shop domain, and a random per-visitor identifier stored in the browser’s localStorage to keep a placement A/B assignment stable. No advertising cookies, no cross-site tracking, no device fingerprinting.
Routine Planner: the quiz answers a shopper submits (skin type, concerns, routine preferences) and, only if the shopper enters it, their email address, used to send that shopper their generated routine.
Authentication: the OAuth access tokens Shopify issues for the merchant’s store, stored server-side so the app can call the Admin API on the merchant’s behalf.
Why we process it
- To generate deterministic product recommendations and routines from ingredient data (performance of the service to the merchant).
- To give the merchant attribution and usage analytics for their own store (our and the merchant’s legitimate interest in measuring the app).
- To email a shopper the routine they requested (their request), and, where a merchant enables follow-up emails, to send refill reminders only to shoppers whose Shopify email-marketing consent is active (consent).
What we do not do
- We do not sell personal data.
- We do not use personal data for automated decisions that produce legal or similarly significant effects.
- We do not combine data across different merchants’ stores.
Retention
Order-attribution records are deleted automatically 24 months after they are created. When a merchant uninstalls the app, all of that store’s data is hard-deleted within 48 hours (Shopify shop/redact). When a merchant or Shopify sends a customers/redact request, the stored email for that customer’s records is removed.
The production database is also backed up nightly for disaster recovery. Backups, including any older ones that briefly still hold data since redacted or deleted from the live database, are kept for 30 days on a rolling basis, then automatically overwritten; a backup is never restored in a way that reinstates a customer’s data after a deletion or redaction request.
Sub-processors
We share the minimum data necessary with:
- Shopify: the platform the app runs on and the source of all merchant and order data.
- netcup GmbH: our cloud hosting and database provider (Karlsruhe, Germany; data centre in Nuremberg, Germany). Runs the application server and the PostgreSQL database, encrypted at rest and in transit.
- Hetzner Online GmbH (Gunzenhausen, Germany; data stored in Falkenstein, Germany): holds the nightly encrypted database backup described under Retention above. Access is key-based only; no password authentication.
- Mailjet (Sinch, France; processed in the EU): sends the planner routine and, where enabled, refill-reminder emails. Only the recipient address and message content are shared.
- Sentry and PostHog (United States; transfers covered by EU Standard Contractual Clauses): error monitoring and product analytics. Dormant unless configured by us; events are keyed to the shop domain, not to individual shoppers.
Security
All traffic is over TLS. The database is encrypted at rest. Access tokens are stored server-side and never exposed to the browser. The app requests the narrowest set of Shopify scopes it needs.
Shopper rights
If you are a shopper, the merchant whose store you bought from is the controller of your data. Direct access, correction, or deletion requests to that merchant; we action Shopify’s customers/data_request and customers/redact webhooks automatically on their behalf.
Changes
We will update this page and its "last updated" date when our processing changes materially.
This document is provided for transparency and does not itself create a contract. The Data Processing Agreement governs the processor relationship between Qinci and the merchant.
