Please note that unless otherwise specified any reference in this notice to ‘your personal information’ will include that of your customers and any reference to ‘you’ shall be taken to mean you (the merchant) or your customers.
Personal Information the App Collects
When you install the App, we are automatically able to access certain types of information from your Shopify account: first name, last name and email address of the customers who have purchased an item or product from your online Shopify store.
Additionally, we collect the following types of personal information directly from your customers: age of the child the product/service has been bought for, status of the customer (E.g. mum, dad, other) as well as feedback about the product/service that has been bought,
How Do We Use Your Personal Information?
We use the personal information we collect from you and your customers in order to provide the Service and to operate the App. For such use we are acting as a processor on your behalf.
Additionally, we ask your customers who leave a review for your store whether they would accept their review to also be featured on the public Kinfo app (available here). We would become a controller of the personal information if it is published on the public Kinfo app and would then process it in accordance with our public facing privacy notice (available here).
Sharing Your Personal Information
We may also share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
Otherwise, we don’t share any of your personal information with any other website or third party and it will not be transfer outside of the European Economic Area.
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
When we are acting as a processor on your behalf we will do what we can to support you in responding to your customers’ requests to exercise their data protection rights, however, we note that you will be responsible for ensuring that customers have been provided with a copy of your own privacy notice which confirms a valid legal basis for processing your customers’ personal information.
We will maintain your personal information as long as you continue to use the Service unless and until you ask us to delete this information or you stop using the Service.
We perform staff trainings on the value of personal information and we also operate in accordance with internal data protection policies and procedures. Only selected personnel with the highest admin privileges can access your personal data and we keep access logs to ensure there is an audit trail. We encrypt key information such as your login details. Periodically, we conduct data protection impact assessments to better prepare for any surprises and to give you peace of mind.
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at firstname.lastname@example.org