Privacy Policy

Last updated: August 24, 2026

This policy explains how Section Foundry (“we”, “us”, or “our”) processes information when a merchant installs or uses the Section Foundry Shopify app. We build and deliver Shopify theme sections. If you are a shopper of a merchant using the app, that merchant is generally responsible for your storefront and customer information.

Information we process

We process the minimum information needed to operate the app:

  • Shop and staff information: the shop's.myshopify.com domain, store name, owner or contact email, storefront domain, plan and billing-country code, and the Shopify session credentials needed to authenticate the app.
  • Sections, themes, and billing records: section identifiers, entitlement status, Shopify one-time-purchase ID, status, amount and currency, discounts, selected theme IDs, and the path and verification hashes of Section Foundry files that the app installs. Shopify processes payment-card information; we do not receive or store it.
  • App activity: events such as installation, purchase, section installation, removal, and support-related operational events. The private owner dashboard may also contain merchant-specific discount or support notes.
  • Section suggestions: the title, description, requested features, priority, reference links, and optional reference image that a merchant submits. A reference image might contain personal information if the merchant chooses to include it.
  • Support and diagnostics: information supplied in an email or chat conversation, the shop domain supplied to Tawk.to as the chat visitor name, and limited technical or error data needed to investigate a problem.
  • Owner access: the Google email address of a Section Foundry operator who signs in to the private owner dashboard.

We do not store customer or order data in our application database. Shopify may send limited customer information to our mandatory privacy webhooks. We verify and process those requests in memory and do not write their customer payloads to our application database or logs.

How we use information

  • Authenticate merchants and maintain secure Shopify app sessions.
  • Show the catalog, process Shopify billing, record entitlements, and add or remove Section Foundry files in a merchant-selected theme.
  • Send a one-time welcome email after installation, provide support, and respond to section suggestions.
  • Maintain security, diagnose faults, prevent misuse, and meet legal or Shopify platform obligations.

Browser storage, cookies, and similar technologies

Shopify and the app use necessary cookies and session technology to authenticate merchants. The app also keeps a merchant's wishlist, recently viewed section IDs, and dismissed promotion preference in that browser's local storage. Those browsing preferences are not sent to our database and can be cleared through browser settings.

The optional Tawk.to support widget may set its own cookies or use similar technologies. Disabling required cookies or browser storage can prevent some app features from working.

Service providers and disclosures

We use providers that process information on our behalf as needed to operate the app: Shopify for the app platform, authentication, themes, and billing; Railway and PostgreSQL for hosting and database storage; Cloudflare R2 for private suggestion reference images; Resend for the welcome email; Tawk.to for optional live chat; Sentry for error monitoring when enabled; and Google for private owner-dashboard sign-in. We send each provider only the information needed for that service. Private suggestion images are not made publicly available by the app.

We may also disclose information where required to comply with law, protect rights and security, or in connection with a lawful business transaction. We do not sell personal information or use merchant or customer information for advertising based on that information.

Retention, uninstall, and deletion

We retain merchant information only while it is needed to operate the app, provide support, or meet legal obligations. When you uninstall the app, we immediately delete its Shopify sessions and stop any pending purchase processing. Shopify normally sends us a shop-deletion request approximately 48 hours later. When we receive that request, we immediately delete the shop's remaining app records, including its profile, purchases, section installations, discounts, activity events, section suggestions, and private reference images.

If deletion cannot be completed immediately because of a temporary technical failure, we retain only the shop domain and the limited technical information needed to retry the deletion. We delete that temporary record as soon as the full deletion succeeds.

Some service providers may retain limited security, backup, or transactional records under their own retention policies. We review and handle those records when a valid privacy request requires it.

Shopify customer privacy requests

We support Shopify's mandatory customer data request and customer redaction webhooks. Because we do not store customer or order data, these requests do not normally produce customer records from our database. The merchant remains the primary contact for shoppers and for information held in the merchant's storefront.

Your choices and requests

To request access, correction, deletion, or other privacy assistance concerning information held by Section Foundry, email us at support@sectionfoundry.com. Please include your shop's .myshopify.com domain so we can verify and locate the relevant records. For customer requests about a merchant's storefront, contact that merchant directly.

Security and policy updates

We use reasonable technical and organizational safeguards designed to protect information. No method of transmission or storage is completely secure. We may update this policy as our practices or legal requirements change. The current version and its effective date will always be posted at this URL.

Privacy contact: support@sectionfoundry.com