Boutiqfy: Size Charts Privacy Policy
This Privacy Policy explains how Boutiqfy (“Boutiqfy,” “we,” “us,” or “our”) collects, uses, discloses, and retains information when a Shopify merchant installs or uses Size Charts by Boutiqfy, visits https://sizecharts.boutiqes.com/, or enables one of our Shopify theme extensions (together, the “Service”).
The Shopify merchant that installs the Service controls its store and is responsible for the personal information it collects from its shoppers. This Policy explains the information Boutiqfy processes for the merchant and the information Boutiqfy processes for its own operation of the Service.
Information we collect
Merchant and Shopify account information
When a merchant installs or uses the Service, we receive information from Shopify and information the merchant or an authorized staff member provides, including:
- the store name, Shopify domain, country, and store-owner or staff name and email address;
- Shopify user, session, authentication, and authorization information needed to operate the Service;
- subscription, plan, and billing-status information supplied by Shopify. Shopify processes payment details separately;
- support requests, chat messages, and other information the merchant chooses to send to us; and
- technical information such as IP address, browser and device type, operating system, timestamps, referring page, and application logs.
We use this information to authenticate users, provide and secure the Service, communicate with merchants, provide support, manage subscriptions, prevent abuse, and maintain the application.
Store and product information
The Service accesses store information through Shopify’s APIs and theme-extension context, including product and variant IDs, titles, options, images, collections, product metafields, size-chart content, display rules, translations, and images or text submitted for import. We use this information to create, display, update, translate, import, and maintain size charts and related settings for the merchant’s store.
Order-related data used for attribution analytics
The production app requests Shopify order access and receives paid-order, refund, and cancellation events so that it can provide the merchant with size-chart attribution and revenue reports. Shopify classifies order and related webhook data as protected customer data.
For this purpose, we use and retain only the minimum information needed to calculate the report:
- Shopify order and line-item identifiers;
- the Boutiqfy attribution token and size-chart identifier attached to an eligible line item;
- item quantity, line-item and refund amounts, currency, event timestamps, and paid, refunded, or cancelled status; and
- derived totals used in the merchant’s report.
We do not request the optional Shopify protected customer fields for name, email, phone, or address. We do not intentionally use or store customer names, email addresses, phone numbers, physical addresses, payment-card data, or customer profiles. Shopify may include or redact limited customer or order identifiers in a webhook or privacy-request payload; our application ignores those optional identifying fields and does not write them to the application database.
Shopper measurements and storefront use
A shopper may enter measurements such as bust, waist, hips, height, weight, or merchant-configured measurement fields into the size recommender. The recommendation is calculated in the shopper’s browser. Boutiqfy does not send these measurement values to its servers or store them.
When a shopper adds the recommended variant to a cart, the theme extension sends Shopify only an opaque random attribution token and a size-chart identifier as private line-item properties. It does not send the shopper’s measurements or contact information to Boutiqfy. Shopify, the merchant, the theme, and other apps may process information independently under their own notices.
The theme extension does not install a Boutiqfy analytics pixel or request a shopper’s Shopify customer profile. It reads the product and size-chart information needed to render the feature and may use Shopify’s same-origin cart endpoints to add and verify a recommended variant.
Cookies and application analytics
Our merchant-facing application and hosting infrastructure may use essential cookies and logs for authentication, security, preferences, and referral attribution. We also use Microsoft Clarity in the merchant-facing application to understand navigation, usability, performance, and feature interaction. Clarity may use cookies or similar technologies and may collect interaction, diagnostic, page, and session-replay information. We do not intentionally send storefront shopper measurements or Shopify customer fields to Clarity.
We use tawk.to to provide in-app customer support. If a user opens or uses the chat, tawk.to may process the chat content and the user’s contact and technical information needed to provide the service.
Where consent is required by applicable law, non-essential analytics and chat technologies are used only after the required consent is obtained. Users can also control cookies through their browser and may use the opt-out or privacy controls provided by the relevant third-party provider.
We do not currently use Google Analytics, Meta/Facebook advertising pixels, or customer data for targeted behavioral advertising. We do not sell or rent customer personal information.
How we use information
We use information to:
- provide, operate, troubleshoot, and improve the Service;
- create and display size charts, recommendations, translations, and product integrations;
- calculate aggregate or merchant-facing attribution, conversion, refund, and revenue analytics;
- authenticate users, maintain sessions, process subscriptions, and communicate with merchants;
- provide support and understand application usability;
- protect the Service, detect fraud or abuse, and maintain technical and security records; and
- comply with legal obligations, respond to lawful requests, and protect our rights.
We limit processing of order-related data to the purposes described above. We do not use it to build customer profiles, contact shoppers, sell or share data for advertising, or make decisions that produce legal or similarly significant effects.
How we share information
We disclose information only as needed to provide the Service, comply with law, or protect the Service and our rights. Our service providers may process information on our behalf and must use it for the applicable service, subject to their own terms and privacy obligations. These providers include:
- Shopify, which provides the APIs, store platform, authentication, and related services. See Shopify’s Privacy Policy;
- Microsoft Clarity, for merchant-application usability and interaction analytics. See Microsoft’s Privacy Statement and Clarity’s data-collection information;
- tawk.to, for in-app support chat. See tawk.to’s Privacy Policy;
- Google Gemini and Anthropic Claude, when a merchant uses an AI-assisted import feature. We send merchant-submitted product text or images for that requested import; the feature is not intended for customer personal information; and
- AliExpress and Bright Data, when a merchant uses the AliExpress import feature. We send the requested product link or import request and receive product or size-chart content.
We may disclose information if required by law, subpoena, court order, or lawful governmental request; in connection with a merger, acquisition, financing, or sale of assets; or when reasonably necessary to prevent harm, fraud, security incidents, or violations of our agreements.
Data retention and deletion
We retain merchant account and store-configuration information while the merchant uses the Service and for as long as reasonably necessary for support, security, accounting, dispute resolution, and legal obligations.
We do not retain shopper measurement values. We retain the limited order-attribution records only for as long as needed to provide the merchant’s analytics and, in any event, no longer than 12 months after the relevant order, refund, or cancellation event, unless a longer period is required by law. We then delete or irreversibly aggregate those records.
When a merchant uninstalls the Service, we delete or anonymize the merchant’s application data through our uninstall and Shopify shop-redaction processes, subject to data that we must retain by law. Backups may persist for a limited period until they are securely overwritten according to our backup cycle.
Privacy rights and requests
Depending on where you live and subject to applicable exceptions, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, withdraw consent where processing is based on consent, and request a copy of your information.
If you are a shopper whose information is held by a Shopify merchant, first contact that merchant because the merchant controls its customer records. If your request concerns information Boutiqfy holds directly, or information processed through the Service on behalf of a merchant, contact us at forboutiqes@gmail.com and identify the Shopify store involved. We will verify and handle the request within the period required by applicable law. Shopify’s mandatory privacy webhooks may also send us requests to provide or delete information associated with a store customer or order.
You may opt out of non-essential cookies through available consent controls, your browser settings, and the relevant third-party provider controls. Because the Service does not use customer data for targeted advertising, we do not offer customer-data advertising profiles or data sales.
Legal bases
Where the General Data Protection Regulation or a similar law applies, we generally process merchant and application information as necessary to perform our agreement with the merchant, for our legitimate interests in operating, securing, supporting, and improving the Service, to comply with legal obligations, and, where required, on the basis of consent for non-essential cookies or analytics. The Shopify merchant is generally responsible for establishing the legal basis and providing notices for its own shopper data processing.
International processing and security
Boutiqfy is based in Brazil. Boutiqfy and its service providers may process information in Brazil, the United States, and other countries where they or their infrastructure operate. Where required, we use an appropriate legal mechanism for international transfers and apply reasonable contractual, technical, and organizational safeguards.
We use HTTPS/TLS for data in transit and access controls designed to limit information to people and systems that need it. No method of transmission or storage is completely secure. Merchants should not submit customer personal information to AI import tools or support chat unless it is necessary and lawful to do so.
Changes to this Policy
We may update this Policy to reflect changes to the Service, our data practices, or legal requirements. We will post the updated Policy at the applicable policy URL and change the “Last updated” date.
Contact us
For privacy questions, requests, or complaints, contact:
Boutiqfy: Size ChartsEmail: forboutiqes@gmail.com
Tabeliao Joao Ramalho Matta, 866
Urai, PR 86280-000
Brazil