YOUR DATA & PRIVACY

Privacy policy

How Mindworks Product Options processes information to provide custom product options and addon offers.

Effective date:

Who operates the app

Mindworks Product Options is operated by Muhammad Awais Afzal, an individual freelancer based in Pakistan.

Privacy contact: awais@mindworks.agency.

This notice covers the Shopify app and its public privacy and support pages. Individual merchants are responsible for the privacy notices and information collected through their own stores.

Information processed

Store and account information

The app uses Shopify authentication. Its session database stores store domains, access permissions, authentication tokens and expiry details, and related session information. When provided by Shopify, session records may also contain a merchant or staff user ID, name, email address, locale and account-role flags. These records support authorized store access; they are not shopper profiles.

Products and app configuration

The app reads or manages product and variant information, product images and files, product and collection assignments, option sets, addon sets, discounts and theme setup information to provide its features. Sets and assignments are stored in the merchant's Shopify store. The app reads subscription status and store-plan information to determine available features and billing behavior.

Shopper selections

Storefront components process selected options, entered text, addon variants and quantities, and parent/addon relationship identifiers. Selections are sent to Shopify's cart APIs and may become cart or order line properties. The app's session database does not maintain a separate customer directory or copy of shopper order records.

Merchants should not request sensitive personal information through custom product-option fields. Information retained in a merchant's Shopify store is also governed by that merchant's privacy notice and Shopify's practices.

Support communications

When you email support, your email address, store details, issue description, attachments and other information you provide are processed to respond to your request. Do not send passwords, API tokens, payment details or unnecessary customer information.

Operational information

The app logs operational information such as webhook topic, store domain and processing outcome. Hosting infrastructure may process request metadata, such as IP addresses and timestamps, to provide and protect the service.

Why information is used

Information is used to authenticate the app, save merchant configuration, display product options and addon offers, manage cart relationships and applicable discounts, determine subscription access, diagnose faults, respond to support requests and process Shopify compliance notifications.

Providers and location

Shopify provides authentication, store product and custom-data services, cart services and app subscription billing. The app does not collect merchants' payment-card details itself.

The backend and PostgreSQL session database use Fly.io infrastructure configured in London. Provider processing, support access and backup locations may differ from this deployment region.

Support email is handled by Zoho Mail. The operator uses Hostinger for domain and website hosting. These are separate from the Fly.io-hosted Shopify app backend.

The operator is based in Pakistan, and service providers may process information in other countries. Information may therefore be processed outside your country of residence. Contact the privacy email for questions about the providers involved in your request.

Browser storage

The addon popup uses browser session storage to remember which cart offers have already been answered, so checkout is not repeatedly interrupted. The stored values identify offers rather than creating a customer profile. Shopify separately operates its own cart and authentication technologies.

This public privacy page does not set cookies or load analytics or advertising scripts. That statement does not describe tracking that a merchant independently adds to their Shopify store.

Retention and deletion

App sessions

Session records support the installed app's access to the store and are retained while needed for that connection.

The uninstall webhook deletes session records for the store and clears store-specific in-memory caches. Shopify's shop-redaction webhook also deletes remaining session records and clears these caches. Successful processing depends on webhook delivery and service availability.

Shopify store records

Option and addon configuration, uploaded files, and cart or order selections stored in Shopify are not separate records in the app's session database. Their retention and deletion depend on Shopify's platform behavior and the merchant's store controls. Uninstalling this app does not mean that all product, file, cart or order information is deleted from Shopify.

Database snapshots

The Fly.io database volume is configured for automatic snapshots with a five-day retention period. A snapshot can temporarily retain a copy of information removed from the active database until that snapshot expires.

Support messages and logs

No automatic retention period has been configured for support emails. Emails sent to awais@mindworks.agency are stored in the Zoho Mail account under the mailbox's current settings, not in the app's session database. They are not automatically deleted when a merchant uninstalls the app. You can request deletion of support correspondence by emailing the privacy contact.

No separate operator-defined log retention period has been configured. Fly.io currently documents a seven-day retention period for its searchable application logs. Other infrastructure or provider records can have different retention periods; this is not a promise that every provider record is deleted after seven days.

Privacy requests

Depending on applicable law, you may have rights relating to access, correction, deletion, restriction, objection or portability. Contact awais@mindworks.agency with your request. Avoid sending secrets or unnecessary identity documents.

Shoppers should also contact the store's merchant about information entered into product-option fields, because resulting cart and order properties reside in Shopify. The app authenticates and acknowledges Shopify's customer-data-request and customer-redaction notifications; its session database does not contain shopper records for those notifications to export or erase.

Include your store address and a description of the information or request so the relevant records can be identified. Verification of your identity or authority may be needed before information is disclosed or deleted. Depending on the laws that apply, you may also be able to raise a concern with the relevant data-protection authority.

Changes and contact

Updates to this notice will be published on this page with an updated effective date when the app's data practices change.

For privacy questions, email awais@mindworks.agency.

Muhammad Awais Afzal ยท Pakistan