Privacy Policy — Vivid Custom Fields Export
How Vivid Insight processes Shopify shop, session, order, custom-attribute, operational, billing, support, and website data for Vivid Custom Fields Export.
- Effective date
- Version
- 1.1
- Product
- Vivid Custom Fields Export for Shopify
1. Who we are
VIVID INSIGHT UNIPESSOAL LDA, NIF 517951371, Rua Victor de Sá, 33, 4715-586 Braga, Portugal (“Vivid Insight”, “we”, “us”) provides Vivid Custom Fields Export (the “App”). For privacy questions or requests, email info@vividinsight.xyz.
2. Scope and roles
This Policy explains how we handle personal data when a merchant installs or uses the App, contacts support, or visits the App’s product pages and documentation. The merchant generally determines why Shopify order and custom-attribute data is processed. For that data, Vivid Insight acts as a processor or service provider on the merchant’s instructions. We act as an independent controller for our own account, contract, billing administration, security, legal compliance, and support records.
3. Data the App processes
Installation and authentication data: Shopify shop identifier and domain, authenticated session state, access-token state required by Shopify’s official libraries, granted scope information, and lifecycle events.
Billing entitlement data: trusted App, Shop, and domain identifiers derived from the authenticated Shopify context and the current Shopify App Pricing subscription status. The App does not keep a separate paid or trial flag.
Operation coordination data: one short-lived lease row per active shop operation containing the shop, a lease identifier, operation type, and lease timestamps. Field-selection settings: the shop identifier and technical identifiers of excluded custom fields, shared across the shop and saved after a completed CSV download handoff. Original field names and values are not retained in these settings; the identifiers are shop-linked configuration, not anonymous data.
Transient export data: order and line-item records needed for the export, including order identifiers, dates, currency, product or variant details, SKU, and order-level and line-item custom-attribute keys and values. Custom attributes can contain personal or sensitive information even though the App does not request direct customer name, email, postal address, or phone fields.
Operational data: request or correlation identifiers, stable outcome or error codes, duration, and aggregate counts where needed to operate and secure the service. App-owned logs do not contain order contents, SKU, custom-attribute keys or values, CSV contents, customer identity fields, access tokens, secrets, or raw upstream payloads.
Support data: contact details and any information a merchant chooses to include in an email or support request. Merchants should provide sanitized reproduction details and must not send tokens, customer information, order contents, custom-field values, or an unredacted CSV.
Website data: standard network and request metadata needed to deliver and secure the public product pages and documentation, plus aggregate website analytics provided through Cloudflare.
4. Purposes and legal bases
We process data to authenticate the merchant, provide Analyze and Download, remember the shop’s field selection, verify subscription entitlement, prevent overlapping operations, secure and troubleshoot the App, answer support and privacy requests, comply with Shopify lifecycle and privacy requirements, maintain business records, and meet legal obligations. Where we act as controller, the legal basis is performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required. Where we act as processor, the merchant’s instructions and applicable data-processing terms govern the processing.
5. Storage and retention
Order records, line items, custom-attribute keys and values, and generated CSV contents are processed transiently in memory. The App does not intentionally write them to disk, persist them in PostgreSQL, retain them as an order cache or export history, or store a generated CSV.
Shopify session state is retained while needed for an active installation. The active operation lease is retained only for operation coordination and stale-operation recovery. Field-selection preferences remain until the fields are re-enabled or the installation is removed. Authenticated app/uninstalled and shop/redact events delete the shop’s Session, BulkOperationState, and ShopFieldExclusion rows. Encrypted database backups can contain field-selection preferences as well as session and operation coordination data. They are stored in Google Drive and retained for up to 30 days before expiry through the backup retention process. The MVP has no shop-identifiable telemetry model; genuinely anonymous aggregates may be retained longer. Support and legal correspondence is retained only as long as reasonably necessary for the request, security, dispute, accounting, or legal obligations.
6. Service providers and disclosures
We use service providers only for defined operational purposes and require appropriate safeguards. The production App and private PostgreSQL database run on a dedicated Hetzner VPS in Helsinki, Finland. Cloudflare provides DNS, proxy, TLS, network-security, delivery, and aggregate website analytics services. Google Drive stores encrypted logical database backups and is not an application read path. Shopify provides the commerce platform, authenticated APIs, app installation, compliance webhooks, and billing surfaces selected by the merchant. Contentful and Cloudflare Pages deliver public product documentation and do not receive Shopify order, custom-attribute, session-token, or CSV data from the App.
We may disclose data when required by law, to protect rights and security, or in connection with a corporate transaction subject to appropriate safeguards. We do not sell personal data or share it for cross-context behavioural advertising.
7. International transfers
Some providers operate global networks or may process support and network metadata outside the European Economic Area. Where required, we rely on adequacy decisions, standard contractual clauses, or another lawful transfer mechanism. The merchant remains responsible for lawful use and onward handling of the downloaded CSV.
8. Security
The App uses HTTPS in transit, authenticated Shopify session state, minimal read_orders access, private PostgreSQL networking, restricted operational access, fail-closed export behavior, and encrypted off-server backups. Order and custom-attribute contents are excluded from application logs and persistent application models. No method of transmission or storage is completely secure, but we maintain safeguards proportionate to the processing risk.
9. Shopify privacy and lifecycle requests
The App authenticates Shopify’s customers/data_request, customers/redact, and shop/redact compliance webhooks. Because customer, order, custom-attribute, and CSV contents are not persisted, the customer-specific topics require no local content lookup or deletion. shop/redact deletes the shop-specific Session, BulkOperationState, and ShopFieldExclusion records after the authenticated request is accepted.
10. Your rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to a supervisory authority. For data contained in a merchant’s Shopify orders or downloaded CSV, contact that merchant first because the merchant controls the business purpose and the exported file. For data controlled by Vivid Insight, email info@vividinsight.xyz with the subject “Privacy request”. We may need to verify the requester’s identity and authority.
California residents may have rights to know, correct, delete, or obtain information about personal data. Vivid Insight does not sell personal data or share it for cross-context behavioural advertising.
11. Changes and contact
We may update this Policy when the App, providers, or legal requirements change. The page will show the effective date and version. Material changes will be communicated where required. Contact: VIVID INSIGHT UNIPESSOAL LDA, Rua Victor de Sá, 33, 4715-586 Braga, Portugal; info@vividinsight.xyz.
VIVID INSIGHT