Privacy Policy

Applies to storelyapp.com and all subdomains, and to all Storely Tech Shopify applications, including Storely Size, unless a specific application publishes its own supplementary terms.

Effective August 25, 2026 · Last updated August 25, 2026

This Privacy Policy applies to storelyapp.com and all of its subdomains, and to all Storely Tech Shopify applications, including Storely Size, and to any future Storely Tech application, unless that application publishes its own supplementary terms.

1. Who we are

Storely Tech is a sole proprietorship operated by Laksh Dugar, based in Bengaluru, Karnataka, India. "Storely Tech," "we," "us," and "our" refer to this sole proprietorship. If Storely Tech incorporates as a private limited company, LLP, or other entity in the future, this policy will be updated to reflect the new entity's legal name and registration details.

2. Information we collect

2.1 Information you provide directly

  • Contact details, such as name and email address, when you install an application, contact support, or sign up for updates.
  • Shopify store details provided during application installation, such as shop domain, store name, and plan tier.
  • The content of support requests, feedback, or correspondence.

2.2 Information collected automatically

  • Application usage data, such as features used, configuration choices, and error logs, needed to operate and improve the Services.
  • Technical data such as IP address, browser type, and device information when you visit storelyapp.com.
  • Data accessed through the Shopify Admin API, limited to the scopes granted at installation. These currently consist of: read_files and write_files (theme and application files, such as assets used to display a size chart); read_metaobject_definitions, write_metaobject_definitions, read_metaobjects, and write_metaobjects (structured size chart data stored as Shopify metaobjects); read_products and write_products (product and variant data needed to associate size charts with products); read_themes (theme structure, used to place size chart widgets correctly); and unauthenticated_read_metaobjects (permits the storefront-facing size chart widget to display metaobject content, such as a size chart, to shoppers browsing the store without requiring shopper authentication).

2.3 Information we do not collect

Our current application scopes do not include access to customer or shopper personal data. No order, checkout, or customer record scopes are requested. The Services are built to operate on store and product configuration data, not on the personal information of your customers. If this changes in a future version, for example a feature requiring customer data, this policy will be updated before that scope is requested, and merchants will see the updated permission request at that time.

3. How we use information

We use the information described in Section 2 to:

  • Provide, operate, and maintain application functionality, including rendering size charts and managing configurations.
  • Respond to support requests and communicate service updates, such as downtime or breaking changes.
  • Monitor, debug, and improve product performance and reliability.
  • Comply with legal obligations and Shopify Partner Program requirements, and enforce our Terms of Service.

We do not sell personal information, and we do not use merchant or store data to serve third-party advertising.

Because Storely Tech's merchant base may be global, we process personal information on one or more of the following bases, as applicable under the law of the merchant's jurisdiction.

  • Contract necessity: providing the application functionality the merchant installed.
  • Legitimate interest: product improvement, security, and fraud and abuse prevention.
  • Consent: optional analytics cookies and marketing communications, where used.
  • Legal obligation: tax, accounting, and regulatory recordkeeping.

5. Cookies

storelyapp.com uses a small number of essential cookies required for the site to function. Your cookie preference, that is, whether you accept or decline optional cookies, is itself stored as a cookie in your browser. Optional analytics cookies run only after you accept them through the cookie banner. Declining them does not affect site functionality. You may change your preference at any time by clearing your browser's site data for this domain.

No analytics cookies are currently in use. If that changes, this section will be updated to list each cookie, its purpose, and its duration before it is deployed.

6. How information is shared

We do not sell personal information. We share information only with the following categories of service providers, each acting under our instructions.

ProviderPurposeData involved
ShopifyThe platform our applications run on. Store and product data flows through Shopify's Admin API.Shop domain, store data, and product or metaobject data, per the scopes granted.
Google Cloud Platform (Cloud Run, Secret Manager)Application hosting, compute, and credential and secrets management.Application runtime data and infrastructure credentials.
Neon (PostgreSQL)Database hosting and query processing.Shop configuration and size chart data stored by the application.

This table will be updated before any new sub-processor is added, for example, an email delivery, analytics, or support provider.

7. Data retention

While an application remains installed, we retain the shop and configuration data needed to operate it. On uninstallation:

  • Shop-level data is deleted from active systems within 30 days of receiving Shopify's shop/redact webhook.
  • Any remaining data held in backups is purged within 90 days.
  • Our current scopes do not include customer personal data, so customers/redact requests are typically no-ops. Nonetheless, we implement all three of Shopify's mandatory privacy webhooks, customers/data_request, customers/redact, and shop/redact, regardless of scope, as required under the Shopify Partner Program.

8. Your rights

Because our merchant base may span multiple countries, we honor the rights applicable under the law of each merchant's own location.

  • European Union and United Kingdom (GDPR), where applicable: the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
  • California (CCPA/CPRA), where applicable: the rights to know, delete, correct, and opt out of the "sale or sharing" of personal information. We do not sell or share personal information as those terms are defined under the CCPA.
  • India (DPDPA): the rights of access, correction, erasure, and grievance redressal.

To exercise any of these rights, contact us at info@storelyapp.com. As a sole proprietor without a dedicated compliance team, requests are handled personally by the Storely Tech operator. We aim to respond within 30 days.

9. International data transfers

Our infrastructure runs on Google Cloud Platform and Neon, which may process or store data outside a merchant's own country in the ordinary course of operation. Where required by law, we rely on standard contractual clauses or equivalent safeguards for such transfers.

10. Children's privacy

The Services are intended for business use by merchants and are not directed at children. We do not knowingly collect personal information from children.

11. Security

We use reasonable technical and organizational measures to protect information, including encrypted connections, access-scoped credentials, and secrets management through Google Secret Manager. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last Updated" date, and where required by law, we will provide additional notice to merchants.

13. Contact

Questions about this policy or about your data may be directed to info@storelyapp.com.

Storely Tech (sole proprietorship), Bengaluru, Karnataka, India.