Polishd.

Legal

Privacy Policy

How Polishd handles information across our site and Shopify apps — written to be read, not just filed.

Effective

August 10, 2026

Updated

August 10, 2026

Applies to

Site + StockTie

01

Merchant data stays in service of the app

We access Shopify store data only to run the app you installed — not to sell it, rent it, or train unrelated models.

02

You stay in control

Uninstall ends our access to your shop. You can ask us what we hold, correct it, or request deletion where the law allows.

03

No customer marketing lists

Polishd apps are built for merchants and staff. We do not build advertising audiences from your customers’ personal data.

01

Who we are

Polishd Studio (“Polishd”, “we”, “us”) builds small Shopify apps and operates the website at https://polishd.studio. This Privacy Policy explains how we handle information when you visit our site, contact us, or install and use our apps — currently StockTie: Inventory Sync.

For the purposes of the EU General Data Protection Regulation (GDPR) and similar laws, Polishd is the controller of personal data we collect directly (for example, emails you send us). When we process data from your Shopify store through an installed app, we typically act as a processor on behalf of the merchant (you), who remains the controller of that store’s customer and catalogue data.

02

What this policy covers

This policy applies to:

  • polishd.studio and related pages we publish
  • Polishd Shopify apps available on the Shopify App Store (including StockTie)
  • Communications you send us (support, privacy requests, partnership inquiries)
03

Information we collect

We collect only what we need to run the site, deliver the apps, and meet legal obligations.

  • Account & shop identifiers — Shopify shop domain, shop ID, staff user identifiers provided by Shopify when you install or open an app, and installation / billing status.
  • App configuration & product data — for StockTie: product and variant identifiers, SKUs, barcodes, titles, inventory quantities and locations, inventory ties (links between variants), soft-deleted ties, and dismissed suggestions so rejected matches do not keep resurfacing.
  • Usage & diagnostics — coarse technical logs (timestamps, app routes, error traces, approximate region) used to keep the product reliable and secure.
  • Website data — standard server and edge logs, and any information you voluntarily submit through forms or email.
  • Support correspondence — the content of messages you send us, including any attachments you choose to include.
04

Where information comes from

Most app data comes from Shopify’s APIs after you install an app and grant the requested scopes. Website and support data come from you directly, or from your device when you load our pages.

We do not knowingly purchase merchant or customer personal data from data brokers.

05

How we use information

We use information to:

  • Provide, operate, and improve StockTie and other Polishd apps (including inventory ties, suggestion workflows, and soft-delete / restore behavior)
  • Authenticate sessions and enforce Shopify billing / installation state
  • Diagnose outages, prevent abuse, and secure our systems
  • Respond to support and privacy requests
  • Comply with law, App Store requirements, and enforceable legal process
  • Communicate service-related notices (for example, material changes that affect how an app works)
07

Shopify, merchants, and customers

When you install a Polishd app, Shopify shares certain shop and resource data with us according to the permissions you approve. Your relationship with Shopify is governed by Shopify’s own terms and privacy policy.

Merchant store data processed through our apps (catalogue, inventory, ties, dismissed suggestions) is used to deliver the app’s features for that shop. We do not sell that data. We do not use it to advertise to your customers.

If your store’s customers’ personal data is ever included in payloads needed for an app feature, it remains subject to your privacy notices and Shopify’s platform rules. You are responsible for lawful use of customer data in your shop.

08

When we share information

We do not sell personal information. We share information only in these situations:

  • Infrastructure providers — hosting, edge delivery, databases, error monitoring, and email delivery that process data on our instructions
  • Shopify — as required to authenticate, bill, and operate apps on the platform
  • Professional advisers — lawyers, accountants, or auditors under confidentiality where needed
  • Legal / safety — if required by law, or to protect rights, safety, and integrity of our services
  • Business transfers — if Polishd is involved in a merger, acquisition, or asset sale, information may transfer under continued confidentiality commitments
09

How long we keep information

We keep information only as long as needed for the purposes above:

  • Active installations — app configuration and tie data while the app is installed and for a short wind-down period after uninstall to complete deletion and billing reconciliation
  • Dismissed suggestions & soft-deleted ties — retained while useful for the product’s integrity (so dismissals stay dismissed and audit history remains coherent), then removed when the shop data is deleted
  • Logs — typically short windows measured in weeks, unless needed longer for security investigation
  • Support emails — for as long as needed to resolve the request and keep a reasonable business record
10

Security

We use administrative, technical, and organizational measures appropriate to the sensitivity of the data — including encrypted transport (HTTPS), access controls, and least-privilege practices for production systems.

No method of transmission or storage is perfectly secure. If we become aware of a breach that requires notice under applicable law, we will notify affected parties as required.

11

International transfers

We may process information in the European Economic Area, the United Kingdom, the United States, or other countries where our providers operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms.

12

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may also have the right to lodge a complaint with a supervisory authority.

To exercise these rights, email us at the address below. We may need to verify your identity and your authority to act for a Shopify shop before fulfilling a request involving merchant store data.

If you are a consumer of a merchant who uses StockTie, please contact that merchant first — they are typically the controller of customer data in their store.

13

Cookies and similar technologies

Our marketing site aims to stay light. We may use strictly necessary cookies or local storage required for security, routing, and basic preferences. If we introduce analytics or non-essential cookies, we will update this policy and, where required, ask for consent.

Shopify’s admin and App Store may set their own cookies when you install or open apps; those are governed by Shopify’s policies.

14

Children

Polishd services are directed at businesses and professionals. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

15

Changes to this policy

We may update this Privacy Policy as our apps, infrastructure, or legal requirements change. We will revise the “Last updated” date at the top of this page. For material changes that affect how we handle merchant data, we will provide additional notice through the app or site where appropriate.

16

Contact

Questions, privacy requests, or data-processing inquiries: privacy@polishd.studio

Website: https://polishd.studio

Questions about your data?

Write to us. We treat privacy requests like product work — clear, tracked, and finished.