Privacy Policy — Inner Image Zoom Shopify App

Effective date: September 16, 2026
Last updated: September 16, 2026

Lauren Ashpole (“we,” “us,” or “our”) operates the Inner Image Zoom application for Shopify merchants (“App”). This Privacy Policy explains what information we collect, how we use it, and your choices when you install or use the App.

Who this policy applies to

This policy applies to merchants who install the App on their Shopify store. The App adds product image zoom to the merchant's storefront via a theme app embed. Storefront shoppers are not asked to create accounts in our App, and we do not intentionally collect personal information from your customers.

Information we collect

When you install or use the App, we may collect or receive:

From Shopify (via OAuth and Admin API)

  • Store domain and shop identifier
  • OAuth session and access tokens needed to run the App
  • Granted app permissions (read_themes, read_products)
  • Theme and product information needed for onboarding (for example, whether the app embed is enabled and a product preview URL)
  • Basic information about the Shopify user who opens the App (such as name and email), as provided by Shopify during authentication

Billing

  • Subscription status is checked through Shopify's billing systems. We do not collect or store payment card details.

Technical data

  • Standard server logs (for example, request time, IP address, and error logs) used to operate and secure the App

Information we do not collect

We do not intentionally collect or store:

  • Your customers' names, emails, addresses, or order history
  • Customer browsing behavior on your storefront
  • Payment card or bank account information

Product image zoom on your storefront runs through Shopify's theme extension infrastructure. That storefront functionality does not send shopper personal data to our servers.

How we use information

We use the information above to:

  • Install, authenticate, and operate the App
  • Show embed status and onboarding in the Shopify admin
  • Verify an active subscription before granting access
  • Respond to mandatory Shopify compliance webhooks
  • Maintain security, troubleshoot issues, and improve reliability

We do not sell your personal information.

How we share information

We share information only as needed to run the App:

  • Shopify — hosting, authentication, billing, webhooks, and API access
  • Railway — application hosting
  • PostgreSQL database provider (via Railway) — encrypted storage of OAuth session data

We may also disclose information if required by law or to protect our rights, users, or the public.

Data retention

  • OAuth sessions are stored while the App is installed and are deleted when you uninstall the App or when we receive a applicable data-deletion webhook from Shopify.
  • Server logs are kept for a limited period for security and troubleshooting, then deleted or aggregated.

Because we do not store customer data, customer data export or erasure requests typically do not apply to data held by us.

Your rights and Shopify's privacy tools

Merchants can uninstall the App at any time from Shopify admin, which revokes our API access and triggers deletion of stored session data.

If you are a merchant subject to privacy laws (such as GDPR or CPRA), you may contact us using the details below. Shopify also provides tools for merchants to handle customer privacy requests; our App responds to Shopify's mandatory compliance webhooks as required for App Store apps.

Security

We use industry-standard measures to protect data in transit and at rest, including HTTPS and access controls on our hosting infrastructure. No method of transmission or storage is completely secure.

International transfers

Our service providers may process data in the United States or other countries. By using the App, you understand that information may be transferred to jurisdictions with different data protection laws.

Children

The App is intended for merchants and is not directed to children.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version at this URL and change the “Last updated” date above. Continued use of the App after changes means you accept the revised policy.

Contact us

If you have questions about this Privacy Policy or our data practices, contact lauren@laurenashpole.com.