Product Variant Splitter Pro

Privacy Policy

Last Updated: July 05, 2026

App: Product Variant Splitter Pro  
Developer: Muhammad Waqas  
Contact: info@muhwaqas.com

This Privacy Policy describes how Product Variant Splitter Pro (“we,” “our,” or “us”) collects, uses, stores, and deletes information when you install and use our Shopify app. It is written for **merchants** who use the app and explains our practices regarding **merchant data** and **store customers (buyers)**.

This policy is designed to meet [Shopify’s privacy requirements for apps](https://shopify.dev/docs/apps/launch/privacy-requirements) and to support compliance with applicable privacy laws, including the GDPR, UK GDPR, CPRA, and similar regulations. It does not constitute legal advice.

1. Summary

– We process data to operate a **merchant-facing** Shopify app that splits product variants into separate cards on **collection, search, and homepage listing grids**.
– We collect **merchant and shop data** provided through Shopify OAuth and data you save in the app admin.
– We **do not intentionally collect, store, or sell personal data about your store’s customers (buyers)**.
– Our storefront theme extension **does not use advertising cookies or cross-site tracking** on buyer devices.
– We respond to Shopify **mandatory compliance webhooks** (`customers/data_request`, `customers/redact`, `shop/redact`).
– We do **not sell** personal information.

2. Roles and scope

| Role | Who | Our relationship |
|——|——-|——————|
| **Merchant** | The Shopify store owner or staff installing the app | You are our customer. This policy primarily applies to you. |
| **Buyer / customer** | End shoppers on your storefront | We do not provide services directly to buyers. We do not store buyer profiles. |
| **Shopify** | Platform provider | Shopify processes install, billing, and OAuth. Your use of Shopify is also governed by [Shopify’s Privacy Policy](https://www.shopify.com/legal/privacy). |

If you are a buyer with questions about a merchant’s store, please contact that merchant directly.

3. Information we collect through Shopify’s APIs

When you install the app, Shopify’s OAuth and Admin API provide access to information needed to run the app. Depending on your use of the app and granted scopes, this may include:

3.1 Shop and session data (stored)

– Shop domain and shop identifier  
– OAuth access tokens and related session fields (including token expiry and refresh token metadata where applicable)  
– Granted access scopes  
– Optional staff session fields supplied by Shopify (e.g. user ID, name, email, locale) when you open the embedded admin app  

**Scopes requested:** `read_products`, `read_themes`, `write_app_proxy`

3.2 Product, collection, and theme data (accessed; limited storage)

We access product, variant, collection, and theme information through Shopify’s APIs to:

– Load variant options and product lists in the admin dashboard  
– Resolve collection membership for configured collections  
– Detect theme / app embed status  
– Serve **non-sensitive configuration** to your storefront via the app proxy  

We **do not maintain a separate copy of your full product catalog**. Product and variant details are fetched from Shopify when needed. We store only **merchant configuration** that references product handles, collection handles, and variant display preferences (see Section 4).

4. Information we store in our database

We store the following **per shop** in PostgreSQL:

4.1 Variant configuration (`VariantConfig`)

– Selected variant option to split (e.g. Color, Size)  
– Selected product handles and/or collection handles  
– Feature toggles: hide out-of-stock variants, hover second image, add to cart from grid, search page cards  

4.2 App settings (`AppSettings`)

– Whether the theme app embed appears enabled (synced from theme status checks)  
– Optional custom container selector and debug mode preference recorded in admin  
– Last sync timestamp  

4.3 Billing records (`ShopBilling`)

When you use Shopify App Pricing, we store billing-related metadata such as:

– Plan tier (e.g. Lite, Standard)  
– Shopify shop GID, subscription ID, plan handle, and subscription status (when synced via Shopify Partner / billing APIs)  
– Trial and billing interval preferences where applicable  

Payment card and checkout details are handled by **Shopify**, not by us.

4.4 Operational logs (`VariantOperation`)

If you use variant management API features, we may log:

– Operation type (create, update, delete)  
– Product and variant identifiers  
– Success or failure status and error messages for troubleshooting  

These logs relate to **catalog operations**, not buyer personal data.

4.5 OAuth sessions (`Session`)

– Session identifiers, shop domain, access tokens, scopes, expiry, and related OAuth session fields  

5. Information we collect directly from merchants

We do not require a separate merchant account outside Shopify. Information you provide **inside the embedded app** (configuration choices, selected products/collections, toggles) is stored as described in Section 4.

We may receive support emails if you contact us at **info@muhwaqas.com** (e.g. name, email address, and message content).

We may generate **server and application logs** (IP address, request timestamps, error traces) for security and reliability. These logs are used to operate the service, not for buyer profiling.

6. Information we collect from merchants’ customers (buyers)

**We do not collect buyer personal data for our own purposes.**

Specifically, our storefront theme app extension:

– Does **not** set advertising or analytics cookies on buyers  
– Does **not** build buyer profiles or mailing lists  
– Does **not** receive buyer names, emails, or checkout data  

The extension loads JavaScript on your storefront to read **public** product/collection page content and to fetch **your shop’s app configuration** from the app proxy (e.g. `?shop=your-store.myshopify.com`). That request identifies the **shop**, not individual buyers.

If buyers click product links on split cards, they interact with **your Shopify storefront** under your privacy practices.

7. How we use information

We use collected information only to:

1. **Provide the app** — authenticate installs, save settings, split variants on listing pages, enforce plan limits, and sync billing state  
2. **Operate securely** — prevent abuse, debug errors, and maintain infrastructure  
3. **Support merchants** — respond to support requests  
4. **Comply with law** — respond to lawful requests and Shopify compliance webhooks  

We do **not** use merchant or shop data for unrelated advertising, and we do **not** sell personal information.

8. Legal bases (EEA / UK merchants)

Where GDPR or UK GDPR applies, we rely on:

– **Contract** — processing necessary to provide the app you installed  
– **Legitimate interests** — security, fraud prevention, and service improvement (balanced against your rights)  
– **Legal obligation** — compliance with applicable law and Shopify platform requirements  

Where required, we rely on Shopify and the merchant’s relationship with buyers for any buyer-facing processing on the storefront.

9. Data sharing and subprocessors

We do **not** sell, rent, or trade personal information.

We may share data with:

| Recipient | Purpose |
|————|———|
| **Shopify** | App platform, OAuth, Admin API, App Pricing, compliance webhooks |
| **Infrastructure providers** | Cloud hosting (e.g. VPS / container platform), PostgreSQL database, TLS termination |
| **Professional advisers** | Legal or accounting, when required |
| **Authorities** | When required by law or valid legal process |

Subprocessors process data only on our instructions and for hosting or operating the app. A list of subprocessors is available on request at **info@muhwaqas.com**.

We do not share buyer personal data because we do not collect it.

10. International data transfers

We may process and store data in countries other than your own (for example, where our servers are located). Where required, we use appropriate safeguards for cross-border transfers (such as Standard Contractual Clauses or equivalent mechanisms).

If you need more information about transfers affecting your shop, contact **info@muhwaqas.com**.

11. Data retention and deletion

| Data type | Retention |
|————|———–|
| **OAuth sessions** | Deleted when the app is uninstalled (via `app/uninstalled` webhook) or when sessions expire |
| **Variant configuration, app settings, billing records, operation logs** | Retained while the app is installed; deleted after uninstall or when we receive Shopify’s **`shop/redact`** compliance webhook (see Section 12) |
| **Support emails** | Retained as long as needed to resolve your request, then deleted or anonymized unless law requires longer retention |
| **Server logs** | Typically retained up to **90 days** for security and troubleshooting |

You may request deletion by **uninstalling the app** from your Shopify admin. For additional requests, email **info@muhwaqas.com**.

12. Shopify mandatory compliance webhooks

We subscribe to Shopify’s [mandatory compliance webhooks](https://shopify.dev/docs/apps/build/compliance/privacy-law-compliance):

| Webhook | Our response |
|————|—————-|
| **`customers/data_request`** | We do not store buyer personal data. We acknowledge the request and confirm no exportable buyer data is held by the app. |
| **`customers/redact`** | We do not store buyer personal data. We acknowledge the request; no buyer data deletion is required in our systems. |
| **`shop/redact`** | After a shop closes, we delete shop-associated data we store (configuration, billing metadata, settings, logs, and sessions) for that shop. |

If you are a merchant handling a buyer data request, you remain responsible for data in your Shopify admin and other apps.

13. Your rights

Depending on your location, you may have rights to **access**, **correct**, **delete**, **restrict**, **object to**, or **port** personal data we hold about you as a merchant or installer.

To exercise these rights:

1. **Uninstall the app** from Shopify (this triggers deletion of session data and begins removal of shop configuration), or  
2. Email **info@muhwaqas.com** with your shop domain and request  

We will respond within the timeframe required by applicable law (typically 30 days).

California residents may have additional rights under the CPRA, including the right to know and delete. We do not sell personal information.

14. Security

We use measures appropriate to the nature of the data, including:

– HTTPS/TLS for data in transit  
– Access-controlled production infrastructure  
– Hashed or secured storage of credentials and tokens at rest (via platform and database access controls)  
– Limited access to production systems on a need-to-know basis  

No method of transmission or storage is 100% secure. Report suspected issues to **info@muhwaqas.com**.

15. Children’s privacy

The app is intended for merchants and is not directed at children under 18. We do not knowingly collect personal information from children.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the **Last Updated** date above. Material changes may be communicated through the app listing, admin interface, or email where appropriate.

Continued use of the app after the effective date of an update constitutes acceptance of the revised policy.

17. Contact us

For privacy questions, data requests, or subprocessors information:

**Email:** info@muhwaqas.com  
**Developer:** Muhammad Waqas  

Please include your **shop domain** (e.g. `example.myshopify.com`) so we can respond accurately.

18. Regulatory references

This policy is intended to support compliance with:

– Shopify App Store [privacy requirements](https://shopify.dev/docs/apps/launch/privacy-requirements)  
– EU / UK General Data Protection Regulation (GDPR / UK GDPR)  
– California Privacy Rights Act (CPRA) and similar U.S. state privacy laws  
– Shopify mandatory GDPR compliance webhooks  

*This Privacy Policy applies only to Product Variant Splitter Pro and not to other services we may offer.*