Privacy Policy

Effective date: July 4, 2026

Welcome to LayerWise ("LayerWise", "we", "our", or "us").

We respect your privacy and are committed to protecting the information entrusted to us by merchants ("Merchants") and their customers ("Customers"). This Privacy Policy explains how we collect, use, process, store, and safeguard information when you install or use our Shopify application and related services.

LayerWise is designed to help beauty, skincare, and wellness brands create personalized product routines, deliver post-purchase product recommendations, and improve customer engagement through Shopify.

By installing or using the App, you acknowledge that you have read and understood this Privacy Policy.

1. Definitions

For purposes of this Privacy Policy:

  • Merchant means the Shopify store owner who installs and uses the App.
  • Customer means an individual who purchases products from a Merchant's Shopify store.
  • Personal Information means information that identifies or can reasonably identify an individual.
  • Merchant Content means any routines, configurations, widgets, assets, campaigns, or other information created by the Merchant using the App.
  • Services means all functionality provided through the App.

2. Data Controller and Data Processor

For Customer Personal Information, the Merchant is the Data Controller, and our App acts as a Data Processor on behalf of the Merchant.

We process Customer information solely to provide the Services requested by the Merchant and in accordance with Shopify's platform requirements.

We do not determine the purposes for which Customer Personal Information is collected by the Merchant.

For Merchant account information, we act as the Data Controller for information necessary to provide and administer our Services.

3. Information We Collect

3.1 Merchant Information

When a Merchant installs the App, we collect limited account information from Shopify, including:

  • Merchant name
  • Merchant email address
  • Shopify store domain
  • Shopify store identifier

This information is used for:

  • Authentication
  • Account administration
  • Customer support
  • Service communications
  • Billing (where applicable)
  • Security monitoring

3.2 Customer Information

To provide matching routines and post-purchase experiences, the App may process Customer information made available through Shopify APIs, including:

  • Customer name
  • Customer email address
  • Order information
  • Order line items

This information is processed solely to:

  • Generate matching routines
  • Display post-purchase recommendation widgets
  • Send Merchant-initiated routine emails
  • Associate purchased products with routines

Customer Personal Information is processed only in transit and is not permanently stored in our application databases.

We do not build customer profiles, sell customer information, or use Customer data for advertising purposes.

3.3 Merchant-Generated Content

During use of the App, Merchants may create and manage:

  • Product routines
  • Routine steps
  • Recommendation rules
  • Product relationships
  • Widget configurations
  • Campaign settings
  • Email templates
  • Metaobjects and related configurations
  • Other App configuration data

This information is stored securely to provide ongoing functionality.

3.4 Uploaded Files

Merchants may upload assets such as:

  • Images
  • Product illustrations
  • Icons
  • Brand assets
  • Other media files

Uploaded files are stored securely using Amazon Web Services (AWS) Simple Storage Service (Amazon S3).

4. Shopify Permissions We Request

Our App requests only the permissions necessary to provide its functionality.

Shopify PermissionPurpose
read_ordersAccess purchased products to generate routines, personalize recommendations, and send post-purchase routine emails. Customer information is processed in transit and is not permanently stored.
write_productsAssociate routines and recommendation data with Shopify products where required.
write_metaobjectsCreate and update Shopify Metaobjects used by the App.
write_metaobject_definitionsCreate and manage Metaobject definitions required by the App.
write_contentCreate and manage App-related content presented to Merchants and Customers.
read_themesDetect theme compatibility and enable App widgets to integrate correctly with Merchant storefronts.

We request only the minimum permissions necessary to deliver the Services.

5. How We Use Information

We use collected information to:

  • Authenticate Merchants
  • Operate the App
  • Generate personalized product routines
  • Display post-purchase recommendation widgets
  • Deliver Merchant-configured routine emails
  • Store Merchant-created routines and configurations
  • Improve App functionality
  • Diagnose technical issues
  • Monitor system performance
  • Prevent abuse and unauthorized access
  • Comply with legal obligations

We do not sell Personal Information.

We do not use Customer Personal Information for behavioral advertising.

6. Data Storage and AWS Infrastructure

Merchant-generated application data is securely stored using infrastructure hosted on Amazon Web Services (AWS).

This includes:

  • Routine data
  • Widget configurations
  • Metaobject configurations
  • Campaign settings
  • Uploaded assets

Uploaded files are stored using Amazon S3.

Customer Personal Information obtained through Shopify for order processing is processed temporarily and is not retained after processing has been completed unless retention is required by applicable law.

7. Security Measures

Protecting data is a core priority.

We implement administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction.

Security measures include:

  • TLS encryption for data transmitted over the Internet
  • Encryption of stored data at rest
  • Secure AWS cloud infrastructure
  • Role-based access controls
  • Principle of least-privilege access
  • Authentication and authorization controls
  • Secure storage of uploaded assets
  • Continuous monitoring of production systems
  • Regular software maintenance and security updates

While no security system can guarantee absolute protection, we continually review and improve our security practices.

8. Data Retention

Merchant-created content is retained while the Merchant continues to use the App.

Upon App uninstallation or account deletion:

  • Merchant-generated application data may be deleted within a reasonable operational period unless retention is required by law.
  • Uploaded assets may be removed from storage during scheduled cleanup processes.
  • Customer Personal Information processed through Shopify is not retained after processing.

Backup copies may temporarily exist for disaster recovery purposes and are securely managed.

9. Third-Party Services

We rely on trusted third-party service providers to operate our Services.

These providers may include:

  • Shopify
  • Amazon Web Services (AWS)
  • Error monitoring and application logging services

These providers process information only as necessary to provide their respective services and are contractually required to maintain appropriate security measures.

10. International Data Transfers

Depending on the Merchant's location and the location of our infrastructure providers, information may be processed in countries other than where it was originally collected.

Where applicable, we implement appropriate safeguards to protect Personal Information during international transfers in accordance with applicable data protection laws.

11. GDPR and Other Privacy Rights

Where applicable under data protection laws, individuals may have the right to:

  • Request access to Personal Information
  • Request correction of inaccurate information
  • Request deletion of Personal Information
  • Request restriction of processing
  • Object to certain processing activities
  • Request data portability
  • Withdraw consent where processing is based on consent

Because Customer information is processed on behalf of Merchants, Customer requests relating to order information should generally be directed to the relevant Merchant.

Merchants may contact us regarding requests related to Merchant account information.

12. California Privacy Rights

If applicable under California law, California residents may have rights regarding access to, deletion of, and correction of Personal Information.

We do not sell Personal Information as defined under applicable California privacy laws.

We do not share Personal Information for cross-context behavioral advertising.

13. Children's Privacy

The App is intended exclusively for businesses and commercial use.

We do not knowingly collect Personal Information directly from children under the age required by applicable law.

If we become aware that such information has been collected inadvertently, we will take appropriate steps to remove it.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our Services, legal requirements, or privacy practices.

When changes are made, we will update the "Effective Date" at the top of this document.

Material changes may also be communicated through the App or other appropriate channels.

Continued use of the App after changes become effective constitutes acceptance of the revised Privacy Policy.

15. Contact Information

If you have any questions regarding this Privacy Policy or our privacy practices, please contact us:

Company: LayerWise

Website: https://getlayerwise.com

Email: support@getlayerwise.com

We will make reasonable efforts to respond to privacy-related inquiries in a timely manner.

LayerWise Support 👋
Leave a message and we'll reply by email
Hi there! Questions about installing LayerWise or building routines? Ask away.
You can also browse our Help center for setup guides.