Privacy Policy

Size Chart and Guide by Jotly

Last Updated: December 7, 2025

1. Introduction and Scope

This Privacy Policy explains how Jotly operates the Size Chart and Guide by Jotly application (hereinafter referred to as "the Application" or "the App") and how data is handled when the App is installed on a Shopify store.

Jotly, referred to as "we", "us", or "our", provides the App to Shopify merchants, referred to as "you", "the Merchant", or "Store Owner". The App is designed to display size charts and size guides on product pages within your Shopify store. The App does not collect personally identifiable information from your store's customers or visitors, though it does use limited pseudonymous analytics as described in Section 3.

This policy is intended to provide clear transparency and to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA and CPRA), and other relevant global privacy frameworks.

By installing or using the App, you acknowledge and agree to the data practices described in this policy. For the purposes of data protection laws, the Merchant acts as the Data Controller for their store operations, and Jotly acts as a Data Processor only with respect to limited Merchant account data as described herein.

2. Categories of Users and Data Processing

The Application interacts with two distinct categories of users. This section clarifies how data is handled for each category.

2.1 Merchants (Store Owners)

Merchants are Shopify store owners who install and configure the Application through the Shopify App Store. Merchants access the Application's administrative dashboard to create, edit, and manage size charts and size guides for their products. Limited merchant account information is collected and processed as described in Section 4 of this policy.

2.2 End Customers (Store Visitors)

End Customers are individuals who visit and browse products on Shopify stores where the Application is installed. When an End Customer views a product page, the Application renders size chart content configured by the Merchant.

No personally identifiable information is collected, stored, or transmitted from End Customers. The Application does collect limited pseudonymous analytics data (such as a randomly generated device identifier and aggregate chart interaction events) for the purpose of usage metrics. This data cannot be used to identify a natural person. Full details are provided in Section 3.

3. End Customer Data Practices

Protecting End Customer privacy is a fundamental principle of the Application's design. The Application is built in a manner that strictly avoids collecting any personally identifiable information from End Customers, in accordance with data minimization principles under Article 5 of the GDPR.

We explicitly confirm the following with respect to End Customers who browse products on stores where the Application is installed:

No personal data of store visitors or customers is collected. The Application does not collect, receive, access, store, transmit, infer, or otherwise process any personally identifiable information from End Customers. This includes, but is not limited to: names, email addresses, telephone numbers, postal addresses, account identifiers, order information, or payment details.

No IP address collection or logging. The Application does not log, store, or analyze the IP addresses of End Customers.

Pseudonymous analytics identifier. The Application sets a browser cookie named _jotly_user_id containing a randomly generated identifier (UUID). This identifier is created locally in the browser and is not linked to any personal information. It cannot be used on its own to identify a natural person. It exists solely to deduplicate chart interaction events for aggregate analytics purposes. No name, email address, or other personal data is associated with this identifier at any point.

Local browser storage. The Application uses the browser's localStorage to record which size chart was last viewed for a given product. This data is stored locally on the visitor's device and is used purely for in-session functional purposes. It is not transmitted to our servers independently and does not contain personally identifiable information.

Aggregate chart analytics. When an End Customer interacts with a size chart (for example, by opening or viewing it), the Application sends an anonymized event to our analytics service. This event includes: the randomly generated user identifier described above, device category (desktop or mobile), the store domain, the chart identifier, page type, page handle, page title, product identifier, and the URL path. None of this information can be used to identify a specific natural person. No names, email addresses, account credentials, or any other personal data are included. This data is used solely for aggregate performance monitoring and to provide Merchants with usage metrics for their size charts.

No profiling or automated decision making. The Application does not perform user profiling or make automated decisions within the meaning of Articles 4(4) and 22 of the GDPR. Analytics data is used only in aggregate and is not used to build individual behavioral profiles.

Merchant-controlled third-party analytics. If a Merchant has enabled optional Google Analytics or Meta (Facebook) Pixel integrations within the Application's settings, the Application may pass chart interaction events to those platforms on behalf of the Merchant. These integrations are disabled by default and are governed by the Merchant's own privacy practices and the respective platform's terms. Jotly does not control or receive the data processed by these third-party platforms.

Because no personally identifiable information is collected from End Customers, installing this App does not add any privacy compliance obligations to your store. You do not need to update your privacy policy, obtain additional consent, or respond to customer data requests on our behalf.

4. Data Collected From Merchants

In addition to the pseudonymous analytics described in Section 3, the Application collects limited data from Merchants (Store Owners) who install and use the Application. This section describes that data, its purpose, and its lawful basis.

4.1 Merchant Account Information

Through Shopify's APIs, we access and store the following merchant-related information:

  • Store identifiers: This includes the store name, primary domain, and myshopify.com domain. These identifiers are necessary to correctly associate size charts with the correct store and to deliver the Application's functionality.
  • Contact details: We collect the store owner's name and the primary email address associated with the Shopify account. This is used for account-related communication, customer support, and important service notifications.
  • Locale and configuration data: Store language and currency settings are accessed to ensure size charts render correctly and consistently with the store's configuration.

4.2 Technical and Usage Information

To ensure reliability and improve the Application experience, we collect limited technical data related only to Merchant usage of the administrative dashboard:

  • Aggregated usage metrics: We may record anonymized, aggregated counts of how often size charts are loaded across all stores. This data is statistical in nature, not tied to any individual End Customer or browsing session, and is used only for merchant dashboards and internal performance monitoring.
  • Admin interaction logs: We keep basic records of Merchant actions within the Application's administrative dashboard, such as when a size chart was created, edited, or updated. These logs exist solely to support functionality, troubleshooting, and customer support.

5. Legal Basis for Processing Merchant Data

Under the GDPR and applicable data protection laws, we process Merchant data based on the following lawful grounds:

Contractual necessity (Article 6(1)(b) GDPR): Processing is required to provide the services you requested when installing and using the Application, including size chart rendering, dashboard access, and customer support.

Legitimate interests (Article 6(1)(f) GDPR): We process limited data to ensure platform security, prevent abuse, maintain system stability, and improve Application performance and usability. We have assessed that these interests are proportionate and do not override your rights or freedoms as a Merchant.

6. Shopify Privacy Compliance

Jotly is fully compliant with Shopify's mandatory privacy requirements for apps. For more information, see Shopify's official documentation: https://shopify.dev/docs/apps/build/compliance/privacy-law-compliance.

After 48 hours of uninstalling the Application, we permanently delete all data associated with your store, including all size charts, size guides, configurations, and any other content created through the Application. If you reinstall the Application within 48 hours of uninstalling, your data will remain intact and no deletion will occur. Once the 48-hour window has passed, the deletion is permanent and the data cannot be recovered.

7. Data Security Measures

We implement appropriate technical and organizational safeguards to protect the limited Merchant data we store, in accordance with Article 32 of the GDPR.

  • Secure data transmission: All data exchanged between Shopify, merchant stores, and our servers is encrypted in transit using TLS 1.2 or higher protocols.
  • Encryption at rest: Stored Merchant configuration data is protected at rest using encryption supported by our hosting infrastructure.
  • Access controls: Access to production systems and databases is restricted to authorized personnel only, protected by multi-factor authentication, and subject to the principle of least privilege. Access logs are maintained and reviewed regularly.
  • Infrastructure security: Our infrastructure is hosted on reputable cloud platforms that maintain their own security certifications, with regular security updates applied to our systems.

8. Data Retention and Deletion Upon Uninstallation

Active installations: Merchant data is retained only while the Application remains installed and active on the store. This retention is necessary to provide the contracted services.

Permanent deletion upon uninstallation: When the Application is uninstalled from your Shopify store, all data associated with your store will be permanently and irreversibly deleted within 48 hours. This includes, without limitation: all size charts, size guides, chart configurations, product assignments, display settings, store identifiers, contact information, usage history, and any other data created or stored through your use of the Application. Jotly is fully compliant with Shopify's mandatory privacy requirements for app data deletion. For more information, see: https://shopify.dev/docs/apps/build/compliance/privacy-law-compliance.

Data deleted upon uninstallation cannot be recovered. Once deletion is triggered, there is no mechanism to restore your size charts or any other data. If you reinstall the Application, you will need to recreate all your size charts and configurations from scratch. Jotly accepts no responsibility or liability for any loss of data, loss of business, or any other damages arising from your decision to uninstall the Application.

We strongly recommend that you export or record any size chart content you wish to preserve before uninstalling the Application.

Exceptions: Certain minimal data may be retained beyond uninstallation where strictly required by law, such as for accounting records, tax compliance, dispute resolution, or to comply with legal obligations. Any such retention is limited to the minimum necessary and in accordance with applicable retention schedules.

9. International Data Transfers

Merchant data may be processed on servers located outside your country of residence, including in the United States. Where such transfers occur from the European Economic Area, United Kingdom, or Switzerland to countries not recognized as providing an adequate level of data protection, we implement appropriate safeguards including:

  • Reliance on adequacy decisions where applicable (e.g., EU-US Data Privacy Framework)
  • Where required, reliance on Standard Contractual Clauses approved by the European Commission as provided by our infrastructure partners

10. Merchant Rights

As a Merchant, you have the following rights regarding the data we hold about your store, subject to applicable laws and verification of your identity:

  • Right to access (Article 15 GDPR): You may request confirmation of what Merchant data we hold and receive a copy of that data in a commonly used electronic format.
  • Right to rectification (Article 16 GDPR): You may request correction of inaccurate or outdated store or contact information.
  • Right to erasure (Article 17 GDPR): You may request deletion of your Merchant data by uninstalling the Application or by contacting us directly. Note that some data may be retained where we have a legal obligation to do so.
  • Right to data portability (Article 20 GDPR): You may request your data in a structured, machine-readable format.
  • Right to object (Article 21 GDPR): You may object to processing based on legitimate interests, and we will honor that request.

To exercise any of these rights, please contact us using the details provided in Section 11.

11. Contact Information

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how data is handled, you can contact us at:

Email: [email protected]

We aim to respond to all inquiries within 2–3 business days.