SlideSpark Privacy Policy
Last Updated: May 29, 2026
This Privacy Policy explains how SlideSpark ("we", "us", or "our") collects, uses, and protects information when you use our Shopify app. SlideSpark is a merchant-facing tool for creating and managing image sliders and carousels within your Shopify store.
1. Information We Collect
We collect only what is necessary to provide the service:
- Store domain: Your store's
.myshopify.com URL, used to identify your account and associate your slider data with your store.
- Shopify access token: An OAuth access token provided by Shopify upon installation, stored securely on our servers and used solely to make authorized API calls on your behalf.
- Slider and slide configuration: The names, settings, and layout preferences you create within the app (e.g., slider titles, transition settings, image layout options).
- Image file URLs: References (URLs) to images you upload. Images are transmitted directly to and stored on Shopify's own infrastructure via Shopify's Staged Uploads API. We do not store image files on our servers.
- Billing and subscription status: Information provided by Shopify about your app plan, subscription status, billing approval, and cancellation status. Payments are processed by Shopify; we do not collect or store payment card information.
- Operational logs: Limited server logs used to maintain security, debug errors, and operate the App. These logs do not include customer personal information or payment card information.
2. Information We Do NOT Collect
We do not collect:
- Any personal information about your customers (buyers). SlideSpark operates entirely within the Shopify admin and does not run any code on your storefront that tracks or identifies shoppers.
- Storefront visitor analytics, tracking cookies, or shopper behavior data.
- Your customers' names, emails, addresses, or payment information.
- Any data beyond what is described in Section 1.
3. How We Use Your Information
The information we collect is used exclusively to provide the SlideSpark service:
- To authenticate your store and display your slider configurations within the admin interface.
- To sync your slider data to your Shopify store via metafields so your theme can display the sliders on your storefront.
- To process image uploads on your behalf through Shopify's file APIs.
We do not use your information for advertising, marketing, or any purpose unrelated to operating the app.
4. Data Sharing
We do not sell, rent, or share your data with third parties. Your data is shared only with:
- Shopify: As the platform through which the app operates, Shopify processes data according to their own Privacy Policy.
- Neon: We use Neon (neon.tech) as our database provider. Your store's slider configuration data is stored in Neon's managed Postgres service. Neon processes this data solely to provide database hosting and is bound by their Privacy Policy.
- Railway: We use Railway (railway.app) to host the app's servers. Railway processes data only as necessary to run the service and is bound by their Privacy Policy.
5. Data Retention
Your store's data, including slider configurations and image references, is retained while SlideSpark is installed on your store. When you uninstall the app, we mark your store as uninstalled and remove active session/access data. Shopify sends a shop/redact webhook 48 hours after uninstall, at which point we delete all data associated with your store from our database. You may also contact us at the address below with deletion requests.
6. Compliance with Shopify's Mandatory Privacy Webhooks
As required by Shopify, our app responds to the following mandatory privacy webhooks:
- Customer data request (
customers/data_request): We do not store any customer data, so no customer data will be returned in response to such requests.
- Customer data erasure (
customers/redact): We do not store any customer data, so there is nothing to erase.
- Shop data erasure (
shop/redact): Upon receiving this webhook (sent 48 hours after app uninstall), we delete all data associated with your store from our database.
7. Your Data Rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal data. To exercise any of these rights, please contact us at the address below. We will respond within 30 days.
8. International Data Transfers
Our servers are located in the United States. If you are accessing SlideSpark from outside the United States, your data may be transferred to and processed in the United States. We take appropriate measures to ensure that any such transfers comply with applicable privacy laws.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this page. Continued use of the app after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions or requests regarding this Privacy Policy, please contact us at: hello@bphdev.com.