Privacy Policy
Last updated: July 2026
InfoPin is a Shopify app that lets merchants place informational hotspots (tooltips) on their product images. This policy explains what data the app collects, how it is used, and how it is deleted. It covers the InfoPin app only.
What we collect from merchants
When you install and use InfoPin, we store:
- Your shop domain (for example, your-store.myshopify.com).
- The Shopify product IDs and product image URLs that you attach hotspots to.
- The hotspot content you create: labels, descriptions, positions, colors, and shapes.
- Your billing plan status (Free, Starter, or Pro), read through the Shopify Billing API.
- A Shopify session record required to authenticate your store with the app (access token and the identifiers Shopify provides during install).
We access your product catalog through the Shopify Admin API using the read_products and write_products permissions you grant at install. Product data is read to show your products in the app; we do not copy your full catalog into our database.
Shopper (customer) data
InfoPin does not collect, receive, or store any personal data about your customers or store visitors. The storefront widget runs in the shopper's browser and only reads public product information (the product being viewed and its image) to decide which hotspots to display. It does not read carts, orders, accounts, contact details, or any personally identifiable information, and it sends none of that to us.
How we use data
Merchant data is used only to operate the app: to render your product list, save and serve the hotspots you create, and enforce the limits of your billing plan. We do not sell data, and we do not use it for advertising.
Where data is stored
App data is stored in a PostgreSQL database hosted on Railway, in the United States. Data is transmitted over HTTPS.
GDPR and data requests
InfoPin implements Shopify's three mandatory compliance webhooks:
- customers/data_request — Because InfoPin holds no customer personal data, there is no shopper data to return. We acknowledge the request accordingly.
- customers/redact — There is no customer data to erase, so this is a no-op that we confirm back to Shopify.
- shop/redact — When a store uninstalls the app, we delete all of that store's data (product configurations, hotspots, and session records) within 30 days.
Data retention and deletion
Your hotspot and configuration data is kept for as long as the app is installed. When you uninstall InfoPin, your session is removed and your store data is deleted within 30 days, as described above. You can also contact us to request deletion at any time.
Contact
Questions about this policy or your data? Email hello@infopin.app.
Changes
We may update this policy as the app changes. Material changes will be reflected on this page with a new "last updated" date.