Skip to content
PopSmart PopSmart
PopSmart AI Upsell & Bundles PopSmart AI Virtual Try On PopSmart Size Chart Fit Finder
English 한국어 日本語 中文 Español Français Deutsch العربية हिन्दी Italiano Português Русский ไทย Tiếng Việt
PopSmart AI Upsell & Bundles PopSmart AI Virtual Try On PopSmart Size Chart Fit Finder
English 한국어 日本語 中文 Español Français Deutsch العربية हिन्दी Italiano Português Русский ไทย Tiếng Việt
Find the right app

Privacy Policy

Effective and last updated: August 20, 2026

PopSmart AI Upsell & Bundles ("Service", "we", "us", or "our") is a campaign application for Shopify merchants. This Privacy Policy explains how the Service collects, uses, discloses, and safeguards information when you install and use the application.

1. Information We Collect

1.1 Store Data via Shopify API

When you install PopSmart AI Upsell & Bundles, we access the following data through the Shopify API with your explicit permission:

  • Product catalog — product names, descriptions, variants, prices (including sale prices), images, tags, and custom metadata
  • Order history — up to 180 days of order data including order totals, line items, and customer IDs (used for co-purchase analysis and product recommendations)
  • Discount information — active discount codes, automatic discounts, and buy-X-get-Y offers
  • Store settings — shop name, domain, currency, and locale

1.2 Merchant Information

We collect information you provide directly:

  • Shopify store domain and admin email (via OAuth)
  • Customization preferences (avatar, theme, tone of voice, trigger settings)
  • Billing and subscription information (managed through Shopify's billing API)
  • Support ticket communications

1.3 Visitor Behavior Data

The Service processes page-level storefront events needed to deliver campaigns and measure attributed performance, including:

  • Page views and product views
  • Cart additions and cart state
  • Scroll depth and engagement signals
  • Time spent on pages
  • Exit intent signals

The Service does not require shopper contact details or payment credentials to select and render storefront campaigns. Shopify and merchant data may still be processed as described in this policy and under the permissions approved during installation.

1.4 Automated Logging

We automatically log:

  • Impression events (when a campaign experience is shown)
  • Click, add-to-cart, order, and attribution events used for campaign reporting
  • Error logs and performance metrics (via Sentry)

2. How We Use Your Information

  • Campaign delivery — deliver merchant-configured offers on the selected storefront placement
  • AI-assisted copy — rewrite matched Storefront Agent messages when a merchant requests it
  • Product recommendations — analyze catalog and order signals for campaign configuration and performance
  • Billing and account management — calculate the applicable attributed-revenue plan band
  • Merchant communications — sending performance reports, usage alerts, and operational notifications (with opt-out per category)
  • Service improvement — aggregated analytics used to maintain and improve the Service

3. Third-Party Services

We use third-party services to operate PopSmart AI Upsell & Bundles, including:

  • AI-assisted workflows — we use AI services for merchant-requested campaign assistance and Storefront Agent message rewriting. Data is limited to the context needed for that function.
  • Email delivery — merchant emails (performance reports, billing alerts) are sent through a trusted email delivery provider.
  • Cloud infrastructure — our services are hosted on secure cloud infrastructure with industry-standard protections.

These services process data only as necessary to provide their specific function and are bound by their own privacy policies and data processing agreements.

4. Data Retention

  • Store data cache — continuously synced and refreshed; deleted upon app uninstall
  • Order history — up to 180 days, refreshed on sync cycles
  • Campaign event data — retained for attribution and performance reporting; deleted in accordance with applicable requests and retention controls
  • Account data — retained while your subscription is active; deleted within 30 days of app uninstall per Shopify's shop/redact webhook

5. GDPR and Data Subject Rights

We support applicable data-subject requests and Shopify's mandatory privacy webhooks, including:

  • Customer Data Request (customers/data_request) — we export all data associated with a customer within 30 days
  • Customer Data Erasure (customers/redact) — we delete all customer-associated data within 30 days
  • Shop Data Erasure (shop/redact) — we delete all store data after the merchant uninstalls the app

As a data processor, we act on behalf of merchants (data controllers). If a store visitor wishes to exercise their data rights, they should contact the merchant directly.

6. Data Security

We take the security of your data seriously. All data is encrypted in transit, access is restricted to authorized services only, and we follow Shopify's security best practices for app development.

7. Children's Privacy

PopSmart AI Upsell & Bundles is a B2B service for Shopify merchants. We do not knowingly collect information from children under 13.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify merchants of material changes through an appropriate channel. Continued use of the Service after changes constitutes acceptance of the updated policy.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at: team@popsmart.ai

  • Business Operator: 매드맨스튜디오 (MadmanStudio)
  • Business Registration No.: 167-79-00541
  • Data Protection Contact: team@popsmart.ai

PopSmart AI Virtual Try On ("we", "us", or "our") is an AI virtual fitting and image generation application for Shopify merchants. This Privacy Policy explains how PopSmart AI Virtual Try On collects, uses, discloses, and safeguards data when you or your customers use the application.

1. Information We Collect

1.1 Store Data via Shopify API

With your explicit permission, PopSmart AI Virtual Try On accesses the following data through the Shopify API (OAuth scopes: read_products, write_products, read_themes, read_orders, read_customers, read_returns, write_pixels, read_customer_events, read_reports, read_metaobjects, write_metaobjects, read_locales):

  • Product catalog — product images, titles, descriptions, variants, and metadata (used for AI image generation and Publisher posts)
  • Theme and storefront data — read-only theme information for widget installation
  • Customer data (limited) — customer IDs and Customer Segments are accessed via read_customers to match anonymous try-on interactions with subsequent purchases for Try-On Impact analytics and to surface merchant-defined segments in the dashboard. We do not access individual customer names, emails, or contact details.
  • Orders — orders are queried for up to 60 days (a 30-day analytics window plus a 30-day return-baseline buffer) to measure try-on-attributed conversion and return rates
  • Web Pixel events — try-on widget interactions collected via write_pixels and read_customer_events
  • Store settings — shop name, domain, currency, locale, and admin email
  • Metaobjects — read and write access for optional Body Profile storage
  • Returns — return records used for Try-On Impact return-rate comparison

1.2 Merchant Information

  • Shopify store domain, admin email, and billing plan (via OAuth + Shopify Billing API)
  • Design and configuration preferences (brand colors, preset selections, saved AI generation presets)
  • Support ticket communications

1.3 Customer Photos (Virtual Try-On)

When a store visitor uses the virtual try-on widget, they may upload a photo of themselves so that PopSmart AI Virtual Try On can render how products would look on them. We treat these photos with strict safeguards:

  • Stored in a private Cloudflare R2 bucket (studio-private), accessible only via short-lived signed URLs (1-hour expiry)
  • Automatically deleted within 24 hours of upload by an automated cleanup job
  • Transmitted to Google Gemini over TLS 1.2+ for image generation
  • EXIF metadata (including GPS coordinates) is stripped on upload before storage
  • Never used for AI model training, never shared with third parties beyond the processor (Google Gemini) needed to render the try-on, and never retained beyond 24 hours

1.4 Body Profile Data (Optional)

Store visitors may optionally save a body profile (approximate height, preferred size). This data is:

  • Stored as a Metaobject on the merchant's Shopify store
  • Encrypted at rest using AES-256-GCM
  • Associated only with the visitor's authenticated Shopify Customer Account (via Customer Account API OAuth with PKCE)
  • Deletable by the visitor at any time from their Customer Account

1.5 Social Integration Tokens (Publisher)

When a merchant connects Instagram, Facebook, or Pinterest via the Publisher module, the provider's OAuth access tokens are:

  • Encrypted at rest using AES-256-GCM
  • Used only to post content and fetch account, page, or board information on the merchant's behalf
  • Never shared with third parties
  • Revocable at any time from PopSmart AI Virtual Try On or from the provider's settings

1.6 Meta Publisher Data (Facebook and Instagram)

What Facebook/Instagram data we access:

  • List of Facebook Pages you administer — Page IDs, Page names, and Page access tokens returned by Meta via pages_show_list
  • Facebook Page publishing permission — permission to publish photos and multi-photo posts to the connected Page via pages_manage_posts
  • Connected Instagram Business account information — Instagram account ID and username via instagram_business_basic (Instagram Basic account-identification data)
  • Instagram content publishing permission — permission to create and publish media containers to the connected Instagram Business account via instagram_business_content_publish
  • Publishing results returned by Meta — platform post IDs, status, timestamps, and post URLs or permalinks for posts created through PopSmart AI Virtual Try On

How we use this data:

  • The Facebook Pages list is used to identify eligible Pages, show connection status, and store the selected or default Page as the Facebook Publisher destination inside PopSmart AI Virtual Try On.
  • Facebook Page tokens are stored encrypted and used only when the merchant asks PopSmart AI Virtual Try On to publish a Facebook post, fetch the resulting permalink, or maintain the connection state.
  • Instagram account information is used to show which Instagram Business account is connected and to send merchant-approved images and captions to that account.
  • Meta post IDs, URLs, and timestamps are used for the in-app Publish History, retry/support diagnostics, billing reconciliation, and merchant-facing "View Post" links.
  • We do not use Meta account, Page, or post data for advertising profiles, resale, cross-merchant targeting, or AI model training.

How long we retain it:

  • Meta OAuth tokens are retained only until the merchant disconnects the integration, removes PopSmart AI Virtual Try On from Meta settings, uninstalls PopSmart AI Virtual Try On, or requests deletion. Tokens are deleted or marked revoked when access is removed.
  • Connected Page and Instagram account identifiers and names are retained with the connection record while the integration remains active, then deleted with the connection or store data.
  • Published post records are retained while PopSmart AI Virtual Try On remains installed so merchants can view Publish History, open published posts, troubleshoot failures, and reconcile credits. They are deleted with store data through Shopify shop/redact after uninstall or earlier on a valid deletion request.

1.7 Pinterest Publisher Data

What Pinterest data we access:

  • Pinterest account information — account ID and username via user_accounts:read
  • Pinterest boards — board IDs and names via boards:read so PopSmart AI Virtual Try On can show board choices and remember the selected board
  • Board creation permission — boards:write is used only to create a default board for the merchant if the connected account has no available board
  • Pin publishing permission — pins:write is used to create Pins from merchant-approved images, titles, and descriptions
  • Pin read permission — pins:read is requested for Publisher verification and history support for Pins created through PopSmart AI Virtual Try On; we do not scan unrelated Pins for profiling or advertising

How we use this data:

  • Pinterest account and board data is used to display the connected account, populate the board selector, and choose the destination board for each Pin.
  • Pinterest access and refresh tokens are stored encrypted and used only to list boards, refresh the connection, create merchant-approved Pins, and store resulting Pin IDs and URLs.
  • For carousel-style publishing, PopSmart AI Virtual Try On creates one Pin per image because Pinterest does not provide a native carousel publishing API.
  • We do not use Pinterest account, board, or Pin data for advertising profiles, resale, cross-merchant targeting, or AI model training.

How long we retain it:

  • Pinterest OAuth tokens are retained until the merchant disconnects Pinterest, removes PopSmart AI Virtual Try On from Pinterest app settings, uninstalls PopSmart AI Virtual Try On, or requests deletion.
  • Selected board IDs/names and connected account identifiers are retained while the Pinterest integration remains active, then deleted with the connection or store data.
  • Published Pin records and permalinks are retained while PopSmart AI Virtual Try On remains installed for Publish History, support diagnostics, retry context, and billing reconciliation, then deleted through Shopify shop/redact after uninstall or earlier on a valid deletion request.

1.8 Usage and Behavioral Analytics

  • Aggregated try-on widget interactions (clicks, model selections, completions) collected via the Web Pixel Extension on merchant storefronts, and forwarded to Mixpanel via our server-side analytics pipeline
  • Image generation pipeline events (job success/failure, duration, resolution)
  • Publisher post events (platform, success, click-through)
  • Merchant dashboard page views and feature usage (via Mixpanel)
  • Merchant email engagement

Visitor-side tracking uses anonymous session identifiers and device-level identifiers (including session cookies and local storage values scoped to the merchant's store). PopSmart AI Virtual Try On does not collect visitor names, email addresses, physical addresses, or payment information.

1.9 Error Logs and Performance Metrics

We use Sentry to capture application errors and performance metrics. Our Sentry configuration redacts the following sensitive data before reporting: the Authorization, Cookie, x-shopify-access-token, x-internal-auth, x-sdk-token, and x-goog-api-key headers, and URL query parameters named key, token, access_token, and api_key.

1.10 Payment Data

All subscription and one-time-pack transactions are processed entirely by Shopify's billing system. PopSmart AI Virtual Try On does not receive, store, or process payment card numbers, bank account details, or any other payment instrument data. We only receive billing event metadata (plan, charge amount, billing period) from Shopify's Billing API.

2. How We Use Your Information

  • AI image generation — product images (and, for virtual try-on, customer photos) are processed through Google Gemini to generate model photos, remove backgrounds, and compose lifestyle scenes
  • Virtual try-on — customer photos are rendered against your products to preview fit and styling
  • Publisher — your content is posted to connected social platforms with AI-generated captions, SEO metadata, and alt text
  • Analytics — aggregated metrics to calculate try-on conversion lift and return-rate comparisons
  • Billing — tracking credit consumption against your subscription or pack balance
  • Merchant communications — performance digests, usage alerts, moderation and ban notifications, and operational emails (opt-in/out per category where legally permitted)
  • Service improvement — aggregated, de-identified analytics

3. Third-Party Services

PopSmart AI Virtual Try On relies on the following third-party providers. Each processes data only as necessary to deliver its function and is bound by its own privacy policy and data processing agreement:

  • Google Gemini (Google LLC) — AI image generation and virtual try-on processing; receives product images and customer photos in transit
  • Cloudflare R2 — object storage (public bucket for generated images; private bucket with 24-hour TTL for customer photos)
  • Amazon Web Services (SES) — delivery of merchant notification emails
  • Google (Gmail API) — support ticket inbox
  • Sentry — application error monitoring (sensitive data redacted before reporting)
  • Mixpanel — merchant dashboard product analytics
  • Meta Platforms (Instagram, Facebook) — OAuth connections for Publisher
  • Pinterest — OAuth connection for Publisher
  • remove.bg — fallback background removal when client-side processing is unavailable

4. Data Retention

  • Generated image outputs — retained for 30 days after creation; pinned items retained while your subscription is active
  • Customer photos (virtual try-on) — deleted within 24 hours of upload
  • Body Profile Metaobjects — retained until the visitor deletes the profile or requests erasure
  • Social OAuth tokens and connected account identifiers — retained until the merchant disconnects the integration, revokes access at the provider, uninstalls PopSmart AI Virtual Try On, or requests deletion
  • Publisher post records — retained while PopSmart AI Virtual Try On remains installed for Publish History, retry/support diagnostics, and billing reconciliation; deleted with store data through Shopify shop/redact after uninstall or earlier on a valid deletion request. Soft-cancelled Publisher jobs may be deleted after the operational cleanup window.
  • Usage and analytics events — aggregated data retained up to 24 months; individual records deleted on GDPR request
  • Merchant account data — retained while your subscription is active; deleted within 30 days of app uninstall via Shopify's shop/redact webhook
  • Support ticket communications — retained in our support inbox (Google Gmail) for up to 24 months after the ticket is resolved, then deleted; deleted earlier on request
  • Billing and credit transaction records — retained as required by applicable tax and accounting law, de-identified where possible

5. Sale of Personal Information

We do not sell, rent, lease, or otherwise share your personal information or your store visitors' personal information with third parties for monetary or other valuable consideration. We do not disclose personal information to third parties for their own marketing or advertising purposes. The only third-party sharing that occurs is strictly limited to the service providers listed in Section 3, each of which processes data on our behalf under a data processing agreement.

6. International Data Transfers

PopSmart AI Virtual Try On processes data in regions operated by Google Cloud, Cloudflare, Amazon Web Services, and the providers listed above, which may include the United States, European Union, and other jurisdictions. Where required, transfers rely on Standard Contractual Clauses or equivalent safeguards.

7. GDPR, CCPA, and Data Subject Rights

PopSmart AI Virtual Try On complies with GDPR, CCPA, and Shopify's mandatory compliance requirements. We implement the three required Shopify webhooks:

  • Customer Data Request (customers/data_request) — we export all data associated with a customer within 30 days
  • Customer Data Erasure (customers/redact) — we delete all customer-associated data (including customer photos, Body Profile, and pixel events) within 30 days
  • Shop Data Erasure (shop/redact) — we delete all store data (including both studio-private and studio-assets R2 prefixes) after the merchant uninstalls the app

Our role under data protection law depends on the data type:

  • For merchant account data, store catalog, orders, returns, and aggregated analytics, PopSmart AI Virtual Try On acts as a data processor on behalf of the merchant (controller).
  • For customer photos uploaded through the virtual try-on widget and Body Profile data (both provided directly by the shopper), PopSmart AI Virtual Try On and the merchant act as joint controllers with respect to the decision to collect such data and its technical processing, while the merchant remains the primary controller responsible for consent, notice at the point of collection, and responding to shopper requests.

Store visitors may contact PopSmart AI Virtual Try On directly at team@popsmart.ai to request access, correction, or deletion of their try-on photos or Body Profile, or they may contact the merchant — either route will result in erasure via the Shopify redact webhook or our internal cleanup procedure.

Step-by-step instructions for deleting data associated with Meta (Instagram, Facebook) and Pinterest integrations — including the uninstall timeline and the information required for a manual deletion request — are provided on our Data Deletion Instructions page.

8. Data Security

  • TLS 1.2+ encryption for all data in transit
  • AES-256-GCM encryption at rest for OAuth tokens and Body Profile data
  • Private R2 buckets accessed only via short-lived signed URLs for customer photos
  • MIME type and magic-byte validation on customer photo uploads
  • EXIF/GPS metadata stripping before storage
  • HMAC-signed webhooks and unsubscribe links
  • SSRF protections on all external image URL fetches
  • Role-restricted internal service access
  • Regular security audits and dependency updates
  • Incident response procedures aligned with Shopify security best practices

9. Children's Privacy

PopSmart AI Virtual Try On is a B2B service for Shopify merchants. The virtual try-on widget may collect photographs from store visitors. Merchants who operate stores selling products intended for children under 13 (COPPA) or under 16 (GDPR) are responsible for obtaining verifiable parental consent before allowing minors to use the try-on widget. PopSmart AI Virtual Try On does not knowingly collect photographs or personal data directly from children under these ages.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide reasonable advance notice of material changes via email or in-app notification. Continued use of PopSmart AI Virtual Try On after the effective date constitutes acceptance of the updated policy.

11. Contact Us

For questions, data requests, or concerns about this Privacy Policy, contact us at: team@popsmart.ai. We respond within 7 business days to all privacy inquiries.

  • Business Operator: 매드맨스튜디오 (MadmanStudio)
  • Business Registration No.: 167-79-00541
  • Data Protection Contact: team@popsmart.ai

PopSmart Size Chart Fit Finder (the "App", "we", "us", or "our") is a Shopify application operated by MadmanStudio under the PopSmart brand. It helps merchants create and publish size charts, offer optional size recommendations, and understand size-and-fit activity. This section explains how the App processes personal data belonging to merchants, their staff, and shoppers.

Our role depends on the context. For Shopify customer and storefront data that we process to provide the App to a merchant, the merchant generally determines the purposes of processing and acts as the controller or business, while we act as its processor or service provider. We act as a controller for our own merchant account, billing, security, support, and legal-compliance records.

1. Information We Process

1.1 Shopify Store and Merchant Data

When a merchant installs or uses the App, Shopify provides data authorized through the App's approved access scopes:

  • Store and account data — Shopify shop domain, store name, custom storefront domain, locale, currency, installation status, merchant or staff identifiers, and a notification or account-owner email address
  • Catalog and storefront data — product and variant identifiers, titles, vendors, product types, tags, collections, SKUs, option values, product images, theme information, and storefront locale data used to build, assign, and render size charts
  • App configuration — chart measurements and labels, product assignments, display layouts, uploaded or linked media, widget placement, language, style, consent, and notification preferences
  • Billing data — plan, price, currency, billing interval, trial and subscription status, and Shopify charge identifiers. Shopify processes payment instruments; we do not receive card or bank-account details.

1.2 Protected Customer and Order Data

If Shopify approves and the merchant authorizes the relevant Level 1 protected-customer-data access, the App processes limited customer-linked data needed for fit, merchant analytics, and the optional merchant-configured size-recommendation follow-up:

  • Shopify customer, order, product, and variant identifiers
  • The current Shopify email-marketing consent state and the time it was observed
  • Product title, vendor, purchased size, quantity, order currency, and order total
  • Fulfillment timestamps, refunded-line-item size, and merchant-provided return reason or note
  • Recommendation identifier and the recommended-to-purchased-size linkage
  • Follow-up eligibility status, delivery event identifier, delay, and frequency reservation

The App does not request or store customer names, email addresses, phone numbers, billing or shipping addresses, or payment details through these protected order, fulfillment, refund, or follow-up workflows. For an optional follow-up, Shopify Flow resolves the customer's email from a Shopify customer reference inside the merchant's own workflow; PopSmart does not receive or store that email. These workflows operate only when Shopify has granted the App the required protected-customer-data access and the merchant has authorized the relevant scopes; otherwise they remain unavailable.

1.3 Shopper Size and Fit Information

When a shopper opens the fit finder, the App may process information the shopper chooses to provide:

  • Height, weight, sizing category or gender selection, usual size, fit preference, and selected reference brand or shoe size
  • The recommended size, alternatives, confidence information, and whether feedback says the recommendation was correct, too small, or too large
  • A store-scoped, pseudonymous shopper identifier derived from the signed Shopify customer identifier when the shopper is logged in
  • Optional post-fulfillment fit feedback and the related product, variant size, recommendation, and order identifiers

The widget uses first-party local storage on the merchant's storefront to remember entered body information and the shopper's save preference. Local-only information remains in that browser until it is replaced or the shopper clears it. If a logged-in shopper affirmatively chooses to remember measurements, the App also stores a store-scoped profile until the shopper withdraws that choice or requests deletion.

Providing size-and-fit information is optional. A shopper who does not provide it can still view the merchant's size chart, but the App cannot generate a personalized recommendation or remember a profile.

1.4 Storefront and Usage Events

Through Shopify's Web Pixel environment and the App's storefront widget, we may collect:

  • Product views and cart additions, including product and variant identifiers or titles, vendor, selected size, quantity, and timestamps
  • Checkout start and completion events, including order identifier, order total, and line-item count
  • Widget opens, recommendation displays, recommendation-to-cart actions, size selections, placement success or failure, and random event identifiers used to prevent duplicates
  • Technical request data such as origin domain, request and error identifiers, approximate network information, and service performance or security logs

These events do not include a shopper's name, email address, phone number, street address, or payment instrument. Shopify's customer-privacy settings and applicable consent signals govern the Shopify Web Pixel where required.

1.5 Smart Chart Materials

If a merchant uses Smart Chart, we process the text, image, spreadsheet, PDF, HTML table, product context, file name, and file metadata the merchant submits. Raw source files are used transiently to extract and normalize chart measurements. The material may be routed through OpenRouter to a supported model provider, including MiniMax, or processed by Google Gemini. PopSmart does not use Smart Chart material to train its own general-purpose models. Upstream model providers have their own retention and model-improvement practices, so merchants must not submit personal data, trade secrets, or other confidential material that is unnecessary to create the chart. The merchant must review the resulting draft before publishing it.

1.6 Support, Communications, and Logs

We process support-ticket subjects and messages, attachments, replies, notification preferences, email delivery identifiers, and operational communications. We also maintain authentication sessions, security and webhook logs, rate-limit counters, request identifiers, and error details needed to operate and protect the App.

2. How and Why We Use Information

  • Provide the contracted service — authenticate merchants, synchronize catalog context, create and publish charts, assign charts to products, render the storefront widget, calculate recommendations, save an optional shopper profile, and provide support
  • Merchant analytics — show store-scoped, aggregated size distribution, funnel, recommendation, fit-feedback, attributed-order, and return information
  • Optional size-recommendation follow-up — after at least 24 hours, make a same-merchant Shopify Flow trigger eligible only when an identified customer is currently subscribed to email marketing, has not purchased the recommended product, remains within the merchant's frequency limits, and the merchant has activated the workflow. The merchant chooses whether to connect a messaging action.
  • Billing and account administration — manage plan entitlements, quotas, trials, subscription lifecycle, and required operational notices through Shopify
  • Security and reliability — authenticate requests and webhooks, prevent abuse and duplicates, investigate faults, and monitor service health
  • Legal compliance — respond to privacy requests, preserve required transaction records, and enforce our terms
  • Service improvement — evaluate de-identified or aggregated performance. We do not use one merchant's identifiable customer data to make recommendations for another merchant.

Where applicable, processing is based on performance of our agreement with the merchant, the merchant's instructions and lawful basis, the shopper's consent for an optional saved profile, our legitimate interests in securing and improving the App, and legal obligations. Size recommendations are advisory. They are not used to determine price, credit, employment, access to essential services, or another legal or similarly significant decision.

How automated recommendations work. The App compares shopper-provided size-and-fit inputs with the relevant product, merchant chart, brand, category, and statistical fit information to return a suggested size, alternatives, and confidence information. The shopper and merchant may disregard the result and use the underlying size chart instead. Choosing not to use the fit finder has no effect on the shopper's ability to buy from the merchant.

3. Service Providers and Disclosures

We disclose only the information reasonably necessary for the following providers or processing channels to perform their functions:

  • Shopify — app installation and authentication, APIs, Customer Privacy and Web Pixel infrastructure, storefront extensions, Flow, and subscription billing; see Shopify's privacy policy
  • Merchant-configured Klaviyo through Shopify Flow — if the merchant chooses this optional action, Shopify Flow supplies the customer email from Shopify's customer reference and sends the event properties selected by the merchant to the merchant's Klaviyo account. The merchant supplies and controls the Klaviyo public API key; PopSmart does not store it or call Klaviyo directly. Klaviyo's practices are described in Klaviyo's privacy notice.
  • Railway — application, PostgreSQL database, Redis, and supporting cloud infrastructure in our configured United States region; see Railway's privacy policy
  • Cloudflare R2 and Cloudflare delivery services — private transient Smart Chart source storage and global delivery of App storefront assets; see Cloudflare's privacy policy
  • OpenRouter, routed model providers (including MiniMax), and Google Gemini — Smart Chart extraction and normalization when the merchant chooses the AI-assisted workflow; they receive only the submitted chart material and bounded product context needed for that task. OpenRouter's routing-layer and downstream-provider practices are described in its privacy policy and data-collection documentation; Google's practices are described in the Gemini API terms.
  • Google Workspace / Gmail API — support and operational email, including delivery of customer privacy exports to the responsible merchant; see Google's privacy policy
  • PopSmart's size-recommendation service — recommendation inputs and de-identified outcome data. Customer names, contact details, Shopify customer IDs, order IDs, and payment details are not included in recommendation outcome records.

We may also disclose information when required by law, to protect the App, merchants, shoppers, or others, or as part of a merger, financing, acquisition, or transfer of assets subject to appropriate confidentiality and notice. We do not sell personal information, share it for cross-context behavioral advertising, or use it for third-party advertising profiles. The App does not send protected customer data to a merchant's GA4, Meta, or Google advertising destination.

4. Retention and Deletion

We apply the following maximum periods unless earlier deletion is required by a valid request or a longer period is required by law:

  • Smart Chart raw source files — normally 30 minutes and never more than 24 hours; deleted after extraction, failure, expiry, or publication. Normalized unpublished drafts expire after 7 days.
  • Published chart, configuration, catalog mapping, merchant account, and subscription records — while the App is installed or needed to provide the service. Charts moved to trash are scheduled for permanent deletion after 30 days.
  • Storefront and checkout pixel events — 30 days
  • Recommendation outcomes without fit or purchase feedback — 90 days
  • Recommendation outcomes with feedback and customer-linked order, return, contribution, or attribution analytics — 13 months
  • Pending or shown fit-rating prompts — expire after 30 days and are purged within a further 30 days; answered or dismissed prompts are purged 30 days after terminal activity
  • Consented shopper profile — until the shopper withdraws consent, the merchant or shopper requests erasure, or store data is erased
  • Webhook audit metadata — 90 days; successful Flow delivery records are removed after delivery and dead-letter records after 7 days
  • Size-recommendation follow-up — an accepted-delivery outbox record is removed after 24 hours; suppressed or dead-letter delivery records after 7 days; eligibility and frequency reservations after 30 days; and the minimal customer/order/product purchase ledger after 31 days when no pending or eligible follow-up depends on it
  • Support and communication records — for as long as reasonably necessary to resolve and document the request, protect the service, and meet legal obligations
  • Billing and tax records — for the period required by applicable accounting, tax, and commercial laws

Shopify customers/redact and shop/redact requests override the ordinary schedules for covered App data. Store erasure removes store-scoped database records, sessions, Smart Chart source objects, and support attachments. De-identified aggregate information that can no longer reasonably be linked to an individual or store may be retained.

When a retention period ends, we delete electronic records from active systems and object storage using automated jobs or verified administrative procedures, then allow encrypted provider backups to expire on their ordinary rotation. We do not ordinarily create paper records from App data.

5. Privacy Rights and Choices

Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, withdraw consent, and appeal or complain to a supervisory authority. We do not discriminate for exercising a privacy right.

  • Shoppers: contact the Shopify merchant whose storefront you used. The merchant can initiate Shopify's customers/data_request or customers/redact process. You may also contact us, and we will coordinate with the merchant as needed to verify and fulfill the request.
  • Marketing follow-up: unsubscribe through the merchant's message or change the Shopify marketing preference available from that merchant. The App requires Shopify's current status to be exactly subscribed before it emits the merchant-owned follow-up trigger; an unknown, unavailable, or non-subscribed status prevents delivery.
  • Saved profile: turn off the save option in the widget to request deletion of the server-side profile; clear the site's local storage in your browser to remove the local copy.
  • Merchants: update notification preferences in the App, uninstall the App to end future processing, or contact us for access, correction, deletion, portability, or restriction requests.

Shopify's mandatory privacy webhooks support customer access and deletion requests and deletion of store data after uninstall. We may request information reasonably necessary to verify the requester and locate the relevant store without collecting unnecessary identity fields.

6. International Transfers

We are based in the Republic of Korea. The providers in Section 3 may process information in the United States, Canada, the European Economic Area, Korea, and other locations identified in their linked policies. Our principal application, database, Redis, and batch infrastructure is currently configured in a United States Railway region.

Transfers occur over encrypted network connections when the App is installed or used, when support or privacy email is sent, and—only if the merchant invokes Smart Chart—when chart material is submitted for AI extraction. Infrastructure providers may store data continuously for the applicable period in Section 4; AI providers receive the submitted material at the time of the request and retain it, if at all, under the applicable provider configuration and terms. Where required, we rely on contractual safeguards, adequacy decisions, or another lawful transfer mechanism. A merchant can avoid the optional AI transfer by not using Smart Chart. The App cannot provide hosting, account, support, or storefront functions without the infrastructure transfers needed to operate those functions.

7. Security

We use technical and organizational safeguards appropriate to the nature of the information, including HTTPS encryption in transit, provider-managed encryption at rest, HMAC verification of Shopify webhooks, signed and short-lived storefront credentials, store and origin isolation, role-restricted service access, private object storage, rate limiting, data minimization, dependency review, and deletion workflows. No system is completely secure, and we cannot guarantee absolute security.

8. Children

The App is a business service for Shopify merchants and is not directed to children. The fit finder does not knowingly request information from children under 13. Merchants are responsible for configuring their storefront and obtaining parental or guardian authorization where a higher local age threshold or the nature of their products requires it. A parent or guardian may contact the merchant or us to request deletion.

9. Changes to This Policy

We may update this Policy to reflect product, legal, or operational changes. We will post the revised date and provide reasonable advance notice through the App or email when a change materially affects rights or our use of personal data.

10. Contact

For privacy questions or requests concerning PopSmart Size Chart Fit Finder, contact team@popsmart.ai.

  • Business Operator: 매드맨스튜디오 (MadmanStudio)
  • Representative and Privacy Officer: 가영근
  • Business Registration No.: 167-79-00541
  • Address: 서울특별시 구로구 가마산로25길 9, 202-S13호 (구로동, 네오팰리스), Republic of Korea
  • Email: team@popsmart.ai
PopSmart PopSmart · © 2026 PopSmart. All rights reserved.
Privacy PolicyTerms of Service · Contact Us
매드맨스튜디오 (MadmanStudio) · 대표: 가영근 · 사업자등록번호: 167-79-00541 · 서울특별시 구로구 가마산로25길 9, 202-S13호 (구로동, 네오팰리스) · team@popsmart.ai

POPSMART EARLY ACCESS

Get early access

Join the PopSmart launch list. We will send a confirmation email, then product access and release notes.