Privacy Policy — 365Nails Customizer

Privacy Policy

Last updated: 2026-09-30 · App: 365Nails Customizer · Developer: 义乌市飞鲸科技有限公司 (Yiwu Feijing Technology Co., Ltd.)

1. What this app does

365Nails Customizer lets Shopify merchants offer made-to-order press-on nails: merchants configure nail shape, length and size options with optional price adjustments; buyers pick those options on the product page; the selections travel with the order as line-item properties; and the merchant can optionally forward customized orders to the 365nails fulfillment backend for production and shipping.

2. Data we collect

From merchants (store owners): the shop's myshopify.com domain, the app's configuration for each product (option lists and pricing rules created by the merchant), and OAuth access tokens (stored encrypted with AES-256-GCM).

From buyers, via order webhooks: when an order containing customized items is paid, we receive the order's line items including the buyer's customization selections (shape, length, size, finger measurements). If the merchant has enabled order forwarding to 365nails, the order's shipping name and address are transmitted to the 365nails fulfillment backend solely to produce and ship the order.

Protected customer data we request: the shipping name and shipping address only (Protected Customer Data level 2 fields). We do not request or process buyer email, phone number, or payment data.

3. What we do NOT store

We do not persist buyer names, email addresses, phone numbers, or payment information in our database. Shipping name and address are transmitted to the fulfillment backend at the moment of order forwarding and are not retained by the app. Payment processing happens entirely within Shopify Checkout; we never see card data.

4. How we use data

Merchant configuration data is used to render the customization UI on the merchant's storefront. Order customization data is used to display order forwarding status to the merchant and to transmit fulfillment information to 365nails when the merchant has enabled that integration. Processing is limited to these stated purposes. We do not sell personal data, do not use it for advertising or automated decision-making, and do not disclose it to any other third party.

5. Who receives the data (processing partners)

Shipping name and address are disclosed only to the fulfillment partner designated by the merchant — 365nails — and only when the merchant enables order forwarding, for the sole purpose of producing and shipping the order. The 365nails fulfillment backend retains the shipping details for as long as needed to produce, ship, and provide after-sales support for that order, under the merchant's agreement with 365nails. Where the fulfillment facility is located outside the buyer's or merchant's country, the transfer is necessary to perform the merchant's order with the buyer; merchants are responsible for the international transfer terms in their own agreement with 365nails.

Infrastructure sub-processors host the app and its database (Railway and its managed PostgreSQL service). They process shop-level data (shop domain, configuration, encrypted access tokens, order push status) and never receive buyer personal data, because the app does not persist it.

6. Data retention and deletion

When a merchant uninstalls the app, all of that shop's data (configuration, sessions, order forwarding records) is deleted immediately and automatically via the app/uninstalled webhook; a purge audit record is kept as proof of deletion. We honor Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact, and shop/redact. Because we do not persist buyer PII, data requests generally have nothing to export or erase beyond shop-level configuration and order push status.

7. Security

All traffic is served over HTTPS (TLS in transit). Access tokens are encrypted at rest (AES-256-GCM). The production database and its backups are encrypted at rest. All webhooks are verified with HMAC-SHA256 signatures before processing. Production and test environments are separated. Access to production data is limited to the minimum staff required, protected by strong passwords with two-factor authentication on hosting and Partner accounts. We maintain a written security incident response procedure — see Security & Data Protection Practices.

8. Your rights

Merchants and buyers in the EEA/UK have GDPR rights of access, rectification, erasure, and portability. To exercise them, contact us at the address below.

9. Contact

Data protection contact: laojin@365nails.com
义乌市飞鲸科技有限公司 (Yiwu Feijing Technology Co., Ltd.)