CAROUSELY

Privacy policy

Effective date: September 19, 2026

This policy explains how the Carouselly team handles information when merchants install and use our Shopify product carousel app, visit our hosted pages, or contact us. For privacy questions, contact lanina.ansari@gmail.com.

Information we process

We store Shopify installation and authentication information needed to operate the app: your shop domain, session identifiers and state, access and refresh tokens, granted permissions, and token expiry information. If Shopify supplies staff information in an online authentication session, that session may also include a staff user ID, name, email, language, and account ownership or collaborator status. Authentication credentials are stored on the server.

Our hosting providers process technical request and diagnostic information, which may include IP addresses, browser information, request URLs, timestamps, response status, and error details. If you email us, we receive your email address and the information you choose to include. Please do not send passwords or access tokens in support messages.

Products and shoppers

Carouselly displays the collection selected by a merchant using Shopify's theme system. Product titles, images, prices, translations, and links are supplied by Shopify. Carousel settings are saved in the Shopify theme; we do not copy your product catalog into our external database.

The app does not request access to customer records, orders, addresses, or payment information. It does not add shopper analytics or advertising trackers. Product and cart actions are handled by Shopify. Shopify and the merchant's store may use their own cookies and collect information under their respective privacy policies.

How information is used

We use installation and authentication information to provide the app, maintain authorized access, and process uninstall and deletion events. Technical information helps us operate, secure, and troubleshoot the service. Support information is used to respond to your requests. We do not sell personal information or use it for targeted advertising.

Service providers and processing locations

We use Shopify to integrate with your store and Google Firebase and Google Cloud to host the app and store authentication sessions. Support email is handled through Gmail. These providers process information as needed to provide their services. We may also disclose information where required by law or necessary to protect the service and its users.

The app server runs in the United States, and the session database is located in Singapore. Firebase Hosting uses distributed delivery infrastructure. Information may therefore be processed outside your country. See the Shopify privacy policy and Google privacy policy for their practices.

Retention and deletion

Authentication sessions are retained while needed for the installation. The app deletes the shop's session records when it receives a valid Shopify uninstall or shop deletion webhook. Shopify delivery timing can affect when that deletion occurs. The session database currently has no scheduled backups or point-in-time recovery enabled.

Ordinary cloud operational logs are retained for 30 days; required cloud audit logs are retained for 400 days. Log retention is separate from session deletion. Support correspondence is retained as needed to resolve requests and meet applicable obligations; you can contact us to request its deletion.

Shopify privacy webhooks may contain customer identifiers. The app verifies and acknowledges these requests without saving their payloads. Because Carouselly does not maintain customer records, there are no corresponding customer records in our app database to export or delete.

Your requests and choices

You can uninstall Carouselly through Shopify. To request access, correction, or deletion of information we hold about you, or to raise a privacy concern, email lanina.ansari@gmail.com with your shop domain and request. We may need to verify your identity or authority over the store before responding. Rights and exceptions depend on applicable law. Shoppers should contact the relevant merchant for requests about orders or customer accounts held by that store.

Security and policy updates

We use HTTPS, server-side credential storage, and access restrictions to protect app information. No system can guarantee absolute security. We may update this policy as the app or our practices change and will publish the updated policy with a revised effective date on this page.