Last updated: 2026-09-30 · App: 365Nails Customizer · Developer: 义乌市飞鲸科技有限公司 (Yiwu Feijing Technology Co., Ltd.) · Contact: laojin@365nails.com
| Data | Purpose | Stored by the app? |
|---|---|---|
| Shop domain, per-product option & pricing configuration | Render the customization UI and the merchant's admin screens | Yes (shop-level) |
| OAuth access tokens | Call the Shopify Admin API on the merchant's behalf | Yes, encrypted (AES-256-GCM) |
| Customization selections on paid orders (shape, length, size, measurements) | Show order forwarding status; forward the order for fulfillment | Yes (non-personal; order number + selections) |
| Shipping name and shipping address (Protected Customer Data, level 2 fields) | Transmit the order to the merchant's fulfillment partner (365nails) so the goods can be produced and shipped | No — transmitted in the request only, never persisted |
We deliberately do not request or process buyer email, phone number, or payment data, and we do not use personal data for advertising or automated decision-making. Processing is limited to the purposes stated above.
The app requests only read_products, write_products,read_orders, read_publications andwrite_publications. Protected customer fields are limited to the shipping name and shipping address required for fulfillment; every other buyer field in the order payload is discarded before storage.
Shop-level data is deleted automatically when the app is uninstalled (via theapp/uninstalled webhook), with a purge audit record kept as proof. The mandatory Shopify privacy webhooks (customers/data_request,customers/redact, shop/redact) are implemented and HMAC-verified. Because buyer personal data is never persisted, erasure requests have nothing to delete beyond order-forwarding status. The fulfillment partner retains shipping details only for as long as needed to produce, ship, and support that order, under the merchant's agreement with 365nails.
All traffic is served over HTTPS/TLS. OAuth access tokens are encrypted at rest with AES-256-GCM. The production database and its backups are encrypted at rest. Webhooks are verified with HMAC-SHA256 signatures before any processing. Secrets live only in the hosting platform's encrypted environment variables and are never committed to source control. Production and test environments are separate, and production data is never copied into test environments.
Access to production data is limited to the minimum number of staff required to operate the service. Accounts on the hosting platform and the Shopify Partner organisation require strong passwords with two-factor authentication, and access to the production service is logged by the hosting provider. Access is reviewed when responsibilities change, and revoked immediately on departure.
We maintain a written incident response procedure covering detection, severity classification, containment, eradication, recovery, and notification. On suspected unauthorised access to personal data we contain the incident, preserve evidence, assess impact (personal data at risk, number of records, jurisdictions), notify affected merchants and Shopify without undue delay, and notify supervisory authorities within 72 hours where required by GDPR. Post-incident reviews feed corrective actions back into this document.
We review these practices at least annually and whenever the app's data flows change. Material changes are reflected on this page with an updated date.