Privacy Policy
Who this covers
This policy describes how the Variac Shopify app handles data belonging to the merchants who install it. Variac is operated by Ariel Lezen ("we"), and applies to the app itself and to this website.
It does not cover Shopify's own handling of your data, which is governed by Shopify's privacy policy.
What the app can access in your store
Variac requests exactly two permissions, and no others:
| Scope | Why |
|---|---|
write_products |
Reading and modifying products, variants, options, and their prices — this is the app's function, turning variants into bundles. |
read_inventory |
Reading inventory levels so bundle availability can be calculated. |
What we do not collect
Variac holds no personal data about your customers. It does not request access to customers, orders, checkouts, or payment information, so that data is never sent to us and never stored by us. When Shopify sends a customer data request or customer redaction request on a shopper's behalf, we acknowledge it and there is nothing to return or erase.
What we store
The app keeps a small amount of data per installed shop, on its own server. Nothing else is retained.
| Data | Purpose |
|---|---|
| Shop domain and Shopify access token | Authenticating requests to your store. Tokens are held server-side and are never sent to a browser. |
| Staff account details for the signed-in user — name, email, locale, and whether the account is the owner or a collaborator | Supplied by Shopify when a staff member opens the app, and used to establish the session. |
| Subscription state — plan, billing period, trial and renewal dates | Cached from Shopify's Partner API so the app can tell which features your plan includes without querying Shopify on every page load. |
| Shop owner's email address and a random support identifier | Threading the in-app support chat, so a conversation continues across visits and a reply can reach you by email. |
Server logs record the shop domain involved in a request. They are rotated and overwritten continuously and are not used for any purpose beyond diagnosing faults.
Support chat
The app embeds a support chat provided by Crisp. If you use it, your messages and the email address associated with your shop are held by Crisp on our behalf so we can answer you. Do not send payment details or passwords through it.
Where your data is held, and who processes it
| Provider | Role |
|---|---|
| Amazon Web Services | Hosting for the application and its database, in the US East (Northern Virginia) region. |
| Cloudflare | DNS and the encrypted network path between your browser and the application. |
| Shopify | The platform itself, and the source of the store data the app reads. |
| Crisp | Support chat, if you use it. |
How long we keep it
- When you uninstall the app, its session and access token for your shop are deleted immediately, and the app loses all ability to reach your store.
- Forty-eight hours after an uninstall, Shopify sends a shop redaction request and everything else we hold for your shop — the cached subscription state and the support identifier and email — is erased.
- Support conversations held by Crisp are deleted on request, and as part of handling a shop redaction.
Security
- All traffic to the app is encrypted in transit.
- The server accepts no inbound connections from the public internet other than the application itself; administrative access requires an SSH key.
- Access tokens and other credentials are stored server-side with restricted file permissions and are never exposed to a browser or embedded in the app's source.
- Requests claiming to come from Shopify are cryptographically verified, and rejected if the signature does not match.
Your choices and requests
You can uninstall the app at any time from your Shopify admin, which immediately revokes its access and starts the deletion described above. To ask what we hold about your shop, or to have it erased sooner, contact us at lezen.ariel@gmail.com from an address associated with the shop.
Changes
If this policy changes materially, the effective date above changes with it. Continuing to use the app after that date means the revised policy applies.
Contact
Ariel Lezen
lezen.ariel@gmail.com