Stesso DIY Hub — Shopify App Privacy Policy

Effective Date: July 29, 2026
Last Updated: July 29, 2026

About this Policy

This Privacy Policy describes how Stesso, Inc. ("Stesso," "we," "us," or "our") collects, uses, and shares information in connection with the Stesso DIY Hub Shopify App (the "App"). It supplements Stesso's general Privacy Policy at https://stesso.com/legal/privacy, which governs use of our broader platform and services. Where this policy and the general policy conflict for App use, this policy controls.

The App is a Shopify-installed merchant tool that adds an AI guide engine to a merchant's storefront. Shoppers can describe a DIY task in plain language; the App returns a step-by-step guide that recommends specific tools, materials, and supplies from the merchant's own Shopify product catalog.

Who We Are

Stesso, Inc. is a Delaware corporation with its principal place of business in the United States.

  • General contact: support@stesso.com
  • Privacy contact: privacy@stesso.com
  • Shopify App support: support@stesso.com

Roles Under Data Protection Law

For the App:

  • We act as a data processor for personal data that a merchant directs us to process on their behalf (for example, the merchant's store metadata, product catalog, theme settings, and any merchant-side configuration of the App). The merchant is the data controller for that data.
  • We act as a data controller for technical, operational, and aggregate usage data we collect to run, secure, and improve the App (for example, anonymous shopper session identifiers, error logs, performance metrics).

Information We Collect from Merchants

When a merchant installs and uses the App, we receive and process information from the merchant's Shopify store through the Shopify API, including:

  • Store identity and configuration: Shop domain, shop ID, store name, currency, locale, country, and storefront URL.
  • Product catalog: Product titles, descriptions, handles, images, prices, inventory status, variants, tags, vendor, product type, and collection membership. The App reads catalog data so it can recommend products that the merchant actually sells.
  • Theme and storefront context: Active theme ID, the page on which the App block is embedded, and merchant-configured settings for the App (tone, scope, branding, enabled features).
  • App authentication data: OAuth access tokens issued by Shopify, scoped to the permissions the merchant grants at install. We store these tokens securely and use them only to call the Shopify API on the merchant's behalf.
  • Account and contact information of the installing user: Name and email address of the Shopify account user who installs or administers the App, as provided by Shopify.

We do not access order data, payment information, or fulfillment data through the App. Our Shopify scopes are read_products, read_themes, read_inventory and write_files — the last so the App can upload the guide images it generates. Where a shopper signs in to save a guide, the App records the identifiers described in the next section.

Information We Collect from Shoppers

When a shopper interacts with the App on a merchant's storefront, we collect and process:

  • Inputs to the guide engine: The DIY task or question typed into the App widget (for example, "hang a shelf in drywall"), and any follow-up clarifying selections the shopper makes.
  • Generated guide content: The step-by-step guide returned by the App, including referenced products and the products the shopper interacts with.
  • Anonymous session identifier: A randomly generated ID held for the duration of a single visit, so a shopper can resume a guide without starting over.
  • Anonymous visitor identifier: A randomly generated ID stored in the browser's local storage that persists across visits, so repeat use of the App is recognised as the same browser. Neither identifier contains personal information, and neither is linked to a Shopify customer account unless the shopper signs in to save a guide. Clearing site data for the store removes both.
  • Technical telemetry: Device type, browser type and version, operating system, viewport size, IP address (used transiently for delivery and abuse prevention), language preference, and referring URL.
  • Interaction events: Widget views, guide generations, step views, product clicks, errors, and basic timing metrics.

The App does not ask shoppers to log in, and the App does not require or collect a shopper's name, email address, phone number, mailing address, or payment information. Shoppers are not required to identify themselves to use the App.

If a merchant has separately configured Shopify Customer accounts or other identification mechanisms on their store, those are governed by the merchant's own privacy policy.

How We Use Information

We use information collected through the App to:

  • Provide and operate the App, including generating guides from the merchant's catalog and rendering the widget on the storefront.
  • Match recommended tools, materials, and supplies to products the merchant actually sells, with stock and price awareness.
  • Maintain, secure, and improve the App's reliability and performance, including diagnosing errors and detecting abuse.
  • Improve the underlying AI models that power the guide engine. We may use de-identified and aggregated inputs and outputs (for example, the kinds of DIY tasks shoppers ask about) to evaluate and improve quality. We do not use a single merchant's catalog or branded content to train models served to other merchants.
  • Communicate with the merchant about the App, including support, updates, and material changes to this policy.
  • Comply with legal obligations and enforce our terms.

How We Share Information

We do not sell merchant or shopper information. We share information only as follows:

  • Service providers (sub-processors): Cloud hosting, database, observability/error monitoring, analytics, and AI model providers we use to operate the App. These providers are contractually obligated to process data only on our instructions and to maintain appropriate safeguards. A current list of sub-processors is available on request at privacy@stesso.com.
  • Shopify: We exchange data with Shopify as required to run a Shopify App (for example, OAuth authentication and API calls to read merchant data per the scopes granted at install).
  • Legal and safety: When required by law, legal process, or to protect the rights, property, or safety of Stesso, our users, or others.
  • Business transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

AI Processing

The App relies on third-party large language model providers to generate guides. When the App calls a model provider, we send the shopper's task description, relevant product titles and descriptions from the merchant's catalog, and prompt context. Inputs and outputs to model providers are processed under the contractual terms we have with each provider, including restrictions on retention and use of data for general model training. We do not send Shopify OAuth tokens, customer data, order data, or payment data to model providers.

Data Retention

  • OAuth tokens and store metadata: Retained for as long as the App is installed, then deleted within 30 days of uninstall.
  • Product catalog snapshots/embeddings: Refreshed from Shopify on an ongoing basis while the App is installed; deleted within 30 days of uninstall.
  • Shopper inputs and generated guides: Retained for up to 90 days for service quality and abuse prevention, then de-identified or deleted. Aggregate and de-identified data may be retained longer.
  • Error logs and telemetry: Retained for up to 90 days for operational purposes.

A merchant may request earlier deletion by emailing privacy@stesso.com.

Merchant Uninstall

When a merchant uninstalls the App, Shopify revokes our access tokens. We will delete the merchant's OAuth tokens, store metadata, and catalog-derived data within 30 days of uninstall, except where we are required to retain data to comply with a legal obligation or resolve disputes.

GDPR Mandatory Webhooks

In addition to merchant-initiated uninstall handling, the App responds to Shopify's mandatory compliance webhooks:

  • customers/data_request: We return the record we hold for that shopper — their Shopify customer identifier, the name and email address Shopify supplied, and the list of guides they have saved. Requests are fulfilled within the period applicable law allows; write to privacy@stesso.com to follow one up.
  • customers/redact: We delete that shopper's record outright — identifier, name, email address and saved-guide list — across every store of yours where they used the App. Nothing is retained in anonymised form.
  • shop/redact: We delete the merchant's OAuth tokens, store metadata, and catalog-derived data on receipt of this webhook (sent 48 hours after uninstall).

Your Rights

Depending on your location, you may have the right to access, correct, delete, or restrict the processing of personal data we hold about you, and to object to processing or request portability. To exercise any of these rights, contact privacy@stesso.com. We will respond within the timeframes required by applicable law. Where Stesso acts as a processor on behalf of a merchant, we will direct rights requests to the merchant.

International Data Transfers

The App is operated from the United States. By installing or using the App, you understand that information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

Security

We use industry-standard administrative, technical, and physical safeguards to protect information processed by the App, including transport encryption (TLS), encryption at rest for stored credentials, scoped API tokens, access controls, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

Children

The App is not directed to children under 13 (or the equivalent minimum age in the relevant jurisdiction), and we do not knowingly collect personal data from children. Merchants are responsible for ensuring that their storefront complies with applicable rules for minors.

Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date above and, where appropriate, notify merchants through the App or by email. Continued use of the App after an update constitutes acceptance of the revised policy.

Contact

Questions about this policy, or requests to exercise privacy rights, may be sent to:

Stesso, Inc.
Email: privacy@stesso.com
Shopify App support: support@stesso.com