Eidosify

Public apps/Variant Specific Images/Privacy

Variant Specific Images

Privacy Policy

Effective date: September 16, 2026

This Privacy Policy describes how Eidosify ("we," "us," or "our") collects, uses, and shares information when you install or use the Variant Specific Images application ("App") from the Shopify App Store, or when you visit eidosify.com.

1. Who we are

Eidosify provides the Variant Specific Images Shopify app, which helps merchants show variant-specific product images on their Online Store product pages. If you have questions about this policy, contact us at [email protected].

2. Scope

This policy applies to merchants who install the App on a Shopify store. It also describes limited technical processing that occurs when shoppers view a product page where the merchant has enabled the App's theme app embed.

The App is built for Shopify merchants. It is not directed at children. Merchants are responsible for their own store policies toward their customers.

3. Information we collect

3.1 Merchant and store data (via Shopify)

When a merchant installs the App, we receive and store information through Shopify's APIs and OAuth, including:

  • Shop domain and shop identifier
  • API access tokens and session data required to operate the App (stored in our application database)
  • Optional staff profile fields associated with an admin session (for example name, email, user ID, locale) when provided by Shopify during authentication
  • Product and media information needed to build variant-to-image mappings (for example product IDs, variant IDs, media IDs, and image URLs)
  • App configuration the merchant saves, such as selected theme script, variant-image settings, product scope preferences, and onboarding progress (stored in Shopify app installation metafields and, where applicable, product metafields for scope)
  • Billing and subscription status through Shopify's Billing API (we do not collect or store payment card numbers)

3.2 Storefront (shopper) data

The App's storefront extension runs on product pages to filter the product gallery by selected variant. For that purpose, the merchant's theme may output technical configuration in the page (for example shop ID, shop domain, product ID, selected variant ID, and a JSON map of product media and variant featured images). This data is used only to display the correct images in the browser.

We do not require shoppers to create accounts in our App, and we do not intentionally collect end-customer names, emails, or checkout data in our own database. Customer and order information remains in the merchant's Shopify store unless you separately integrate other services.

3.3 Server and diagnostic data

Our hosting infrastructure may automatically log standard technical information (for example IP address, request time, user agent, and error logs) when merchants use the embedded app or when the storefront loads our app proxy scripts. We use this information for security, reliability, and troubleshooting.

4. How we use information

  • Provide, operate, and improve the App
  • Authenticate merchants and maintain secure API access to their store
  • Apply variant-specific image filtering on the merchant's storefront according to their settings
  • Process subscriptions through Shopify Billing
  • Respond to support requests and comply with legal obligations
  • Detect abuse, fraud, and security incidents

We do not sell merchant or shopper personal information. We do not use storefront data for unrelated advertising profiles.

5. Legal bases (EEA/UK merchants)

Where applicable law requires a legal basis, we process personal data to perform our contract with the merchant (providing the App), for our legitimate interests in operating and securing the service, and to comply with legal obligations. Merchants may have additional obligations to their customers under applicable privacy laws.

6. How we share information

We share information only as follows:

  • Shopify — the App runs on Shopify's platform; data is accessed and stored according to Shopify's terms and the permissions the merchant grants at install
  • Service providers — infrastructure providers that host our application and database (currently Render and Neon (PostgreSQL)), under contractual confidentiality and security obligations
  • Legal requirements — when required by law or to protect rights, safety, and security
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy

7. International transfers

We and our service providers may process information in countries other than the merchant's country. Where required, we rely on appropriate safeguards for cross-border transfers.

8. Data retention

We retain merchant session and configuration data while the App is installed and as needed to provide the service. When a merchant uninstalls the App, we delete shop session data from our database in response to Shopify's app uninstall webhook. Other data in the merchant's Shopify admin (such as metafields) may remain until the merchant removes it.

Server logs are retained for a limited period for security and operations, then deleted or aggregated.

9. Security

We use reasonable administrative, technical, and organizational measures to protect information, including encrypted connections (HTTPS), access controls, and secure credential storage. No method of transmission or storage is completely secure.

10. Merchant privacy obligations

Merchants determine what product and customer data they manage in Shopify. If you are a merchant, you are responsible for providing any required notices to your customers and for responding to customer privacy requests relating to your store, in accordance with applicable law and Shopify's policies.

11. GDPR / privacy law requests (Shopify compliance webhooks)

The App subscribes to Shopify's mandatory privacy compliance webhooks:

  • customers/data_request — we acknowledge requests; we do not store end-customer personal data in our database beyond what may appear transiently in server logs
  • customers/redact — we acknowledge redaction requests; we do not maintain a separate customer database to erase
  • shop/redact — we delete remaining shop session data from our systems after uninstall, in line with Shopify's process

Merchants and data subjects may also contact us at [email protected].

12. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, or to object or withdraw consent. Merchants can uninstall the App at any time through Shopify Admin. To exercise rights relating to data we control, contact [email protected].

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date. Material changes may be communicated through the App or by email where appropriate.

14. Contact

This page describes the Variant Specific Images Shopify app. Shopify's own privacy practices are governed by Shopify's policies.