Legal
Privacy Policy
Last updated July 13, 2026
This Privacy Policy explains how Seapixel ("we", "us", "our") collects, uses, and protects personal data when you visit seapixel.com (the "Site") and when you use the Shopify apps we publish on the Shopify App Store (the "Apps"). It is written to be read, not to hide behind jargon. If anything here is unclear, email us at hello@seapixel.com.
Who we are
Seapixel is a Shopify studio based in Athens, Greece, working with brands globally. For the purposes of data-protection law (including the EU General Data Protection Regulation, GDPR), Seapixel is the data controller for personal data collected through this Site. For our Apps, our role is described in the "Our Shopify apps" section below.
What we collect on this Site
We keep collection to a minimum. Depending on how you use the Site, we may process:
- Contact form submissions. When you contact us, we collect the name, email address, and message you provide, so we can reply. These are sent to our team's Slack workspace, which we use to receive and respond to enquiries.
- Analytics data. With your consent, we use Google Analytics to understand how the Site is used (for example, which pages are viewed). This may include your approximate location, device and browser type, and pages visited. Analytics only runs after you accept it in the cookie banner.
- Server logs. Our hosting provider may automatically log technical information such as IP address and request time for security and reliability. This is standard hosting behaviour and not used to identify you.
We do not sell your personal data, and we do not use it for advertising or profiling.
Cookies and consent
The Site does not set analytics or marketing cookies unless you accept them. When you first visit, a cookie banner lets you choose what we may store:
- Necessary storage is always on and is only what the Site needs to function and to remember your choice.
- Analytics (Google Analytics) is off by default and only runs if you accept it. You can change or withdraw your choice at any time via Cookie settings in the footer.
We use Google Consent Mode, so no analytics cookies or tracking fire before you opt in.
Fonts and third parties
Our display and body fonts are self-hosted on our own servers, so loading the Site does not send your data to a font provider. The third parties that may process data on our behalf are:
- Google Analytics: website analytics, only with consent.
- Slack: receiving and handling your contact-form messages.
- Our hosting provider: serving the Site and standard server logs.
Each processes data only to provide its service to us.
Our Shopify apps
When a merchant installs one of our Apps on their Shopify store, the App processes store data strictly to provide that app's features. For this data, the merchant is the data controller and Seapixel acts as a data processor on their behalf, under Shopify's Partner Program Agreement and API Terms. Each App's specific data handling is also described in its own listing on the Shopify App Store; this website Privacy Policy does not replace an App's in-context privacy information.
The sections below explain, in plain terms, what our Apps access and why, what we store and for how long, and what happens when an App is uninstalled. They are written for merchants, and they also cover the specific points a Shopify app reviewer verifies.
What our apps access, and why
Our Apps request Shopify API access scopes on the principle of data minimization: each App requests only the scopes its features need, and uses the minimum necessary within them. Grouped by purpose, our Apps may access:
- Storefront content, themes, and navigation — to add blocks, sections, redirects, and on-store widgets (for example theme app extensions, URL redirects, or a store locator). This is store configuration, not personal data.
- Products and product listings — to display, compare, search, or link products in an App's storefront experience. Product catalog data is not personal data.
- Files, locales, and translations — to read media and offer multi-language storefront output.
- Custom data (metaobjects and metafields) — some Apps store their own configuration and content (for example reels, store locations, or app settings) as Shopify metaobjects and metafields inside the merchant's own store, under the App's namespace.
- Orders (protected) — two Apps, our shoppable-video app and our product-comparison app, request
read_ordersonly to attribute a completed purchase back to an in-app interaction (see "Protected customer and order data" below). No other App requests order access. - Customers (protected) — one App, our customer-login app, requests
read_customersandwrite_customersonly to look up a customer by email and send account invitations. No other App requests customer access.
Protected customer and order data
Where an App accesses protected customer or order data through Shopify's Admin APIs, we handle it on these principles:
- Purpose limitation. We use protected data only for the specific feature it was requested for. We never sell it, and we never share it with third parties for their own purposes.
- We never store sensitive personal fields. We do not write customer names, addresses, phone numbers, payment details, or full order contents to our systems.
- Runtime-only where possible. Several features fetch protected data on demand, use it to compute and show a result to the merchant in the moment, and then discard it — it is never written to our databases. For example, our customer-login app reads a customer's status by email to decide whether to offer an invitation, and does not retain that lookup.
- Minimal derived records where a feature needs history. A small number of features must remember an outcome, and for those we store only the minimal derived fields needed:
- Purchase attribution (shoppable-video and product-comparison apps): when a shopper buys a product they interacted with in-app, we store the Shopify order id, the line amount and currency, and the product id of the attributed item, so the merchant can see revenue their app drove. We identify the attributed line using a private cart property our own storefront code set — we do not read or store customer identity, cart tokens, or the rest of the order.
- Account invitations (customer-login app): when a merchant sends an invitation, we store the Shopify customer id and email for that invite so it can be tracked and not duplicated. This is the only place an App stores a customer email, and only for invitations the merchant chooses to send.
- Technical event data. Our storefront analytics (below) record a visitor's browser user-agent string alongside anonymous interaction events. We do not store shopper IP addresses in any Shopify App.
- Merchant control. Merchants can grant or revoke an App's access at any time through Shopify's permission controls. Revoking access immediately stops all further processing.
- Security. All data is transmitted over encrypted connections (HTTPS/TLS), stored on reputable EU/US cloud infrastructure, with restricted staff access and an incident-response process consistent with the rest of this policy.
Analytics and Insights
Some Apps offer storefront analytics so merchants can see how their app-powered experiences perform (impressions, plays, clicks, add-to-carts, and the attributed purchases described above). These events are anonymous interaction records — an event type, the product or content involved, and the visitor's browser user-agent — and are not linked to a customer's identity.
- For our product-comparison and store-locator apps, this collection is off by default and is only turned on when a merchant subscribes to the paid Insights plan.
- For our shoppable-video app, basic analytics are on by default; a merchant can disable them from the app's settings, after which the storefront stops sending events.
Data retention
We keep app data only as long as it is useful for the feature, and different Apps retain for different periods:
- Shoppable-video analytics are automatically deleted on a rolling 100-day basis.
- Product-comparison and store-locator analytics are kept for as long as the App is installed and the Insights plan is active, and are deleted when the App is uninstalled (see below).
- Redirect 404 logs are kept until resolved and, optionally, purged on a schedule the merchant configures.
- Account invitations and app configuration are kept while the App is installed.
What happens when you uninstall
- On uninstall, an App stops processing store data immediately; scheduled tasks are paused.
- 48 hours after uninstall, in line with Shopify's
shop/redactrequirement, we delete the store's App data from our databases — analytics events, redirect and 404 records, invitations, and app-created metaobject definitions — scoped to that store and that App. - What we preserve: a small, non-personal shop cache (a store's own primary domain and URL settings, keyed only by store domain) is shared across any of our Apps a merchant still has installed and is retained so those Apps keep working; it contains no customer data.
- Customer data requests and erasure: we also honour Shopify's
customers/data_requestandcustomers/redactwebhooks. Because our Apps do not store customer-identifying records against individual shoppers (our event data is anonymous, and the only customer identifiers we hold are merchant-initiated invitations), these requests have no per-shopper personal data to return or erase in our systems; where a merchant needs an invitation record removed, they can contact us.
How we use your data
We use the data above only to:
- respond to your enquiries and provide the services you ask for;
- operate, secure, and improve the Site;
- comply with our legal obligations.
Our legal bases are your consent (for analytics), our legitimate interest in running and securing the Site and replying to you, and compliance with legal duties.
How long we keep Site data
This covers data from this website; retention for our Shopify Apps is described under "Our Shopify apps" above.
- Contact messages: kept as long as needed to handle your enquiry and any follow-up, then deleted or archived.
- Analytics data: retained according to our Google Analytics configuration, in aggregate form.
- Server logs: kept for a short period for security and diagnostics.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent at any time. To exercise any of these, email hello@seapixel.com and we will respond within the timeframe required by law. If you are in the EU/EEA, you also have the right to complain to your local data-protection authority.
Children
The Site and our Apps are intended for businesses and are not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy as the Site or our practices change. When we do, we will revise the "Last updated" date above. Material changes will be made clear on this page.
Contact
Questions about this policy or your data: hello@seapixel.com.