Optionfier Privacy Policy
Last updated: May 9, 2026
Optionfier ("the App") is operated by Real Studio ("we," "us," or "our"). This privacy policy describes how we collect, use, and protect information when you install and use Optionfier through the Shopify platform.
What Data We Collect
Merchant Data
When you install Optionfier, we access certain information from your Shopify store through Shopify's API, as authorized during the OAuth installation process. This includes:
- Store information (store name, domain, email)
- Product and variant data (titles, prices, inventory levels)
- Order and fulfillment data (for inventory tracking purposes)
We use this data solely to provide the App's functionality — managing custom product options, processing bundles, and tracking inventory.
Customer Data
Optionfier processes the following customer data in the course of providing its functionality:
- Option selections: The choices customers make when configuring products (text inputs, color selections, dates, etc.). These are stored as line item properties or bundle attributes on the Shopify order and are not separately stored by us.
- File uploads: Files that customers upload through file upload option fields are temporarily staged on our servers (see File Uploads below) and then transferred to Shopify's file storage upon checkout.
Optionfier does not collect analytics, tracking data, cookies, or any other information from storefront visitors. The App only processes data when a customer actively interacts with option fields and submits an order.
Admin Analytics
We use PostHog, a product analytics service, within the App's admin interface (the merchant-facing dashboard embedded in the Shopify admin). PostHog collects the following data from merchants using the admin interface:
- Page views and page leave events
- Click and scroll heatmap data
- DOM interactions (clicks, form submissions) via autocapture
- Session recordings — replays of merchant interactions within the admin interface, used to understand usage patterns and diagnose issues. The AI assistant's free-text input is excluded from these recordings.
- Merchant identification by shop domain, for the purpose of associating analytics with a specific store
Additionally, PostHog receives server-side error reports for debugging purposes. These may include contextual properties such as shop domain, webhook identifiers, and error details to help us diagnose and fix issues.
No analytics, tracking, heatmaps, or error reporting of any kind is performed on your storefront or on your customers. PostHog is only active within the merchant admin interface.
PostHog's privacy policy is available at https://posthog.com/privacy.
AI Assistant
The App includes an optional AI assistant that helps merchants configure product options through natural-language conversation within the admin interface. When you use the AI assistant:
- Your messages and the assistant's responses are sent to third-party large language model (LLM) providers for processing. We currently use one or more of: Anthropic (Claude), Google (Gemini via Vertex AI), and OpenAI (GPT). The active provider depends on our configuration; the message content is necessarily transmitted to the provider in order to generate a response. These providers process your messages under their own terms of service and privacy policies and do not retain or train on your messages beyond what is required to return a response.
- Conversation history is stored in our database so you can return to prior chats. Each message — both yours and the assistant's, including any tool calls the assistant makes — is persisted with the associated shop session and group. We do not use the content of these conversations for any purpose other than displaying them back to you and providing the assistant's functionality.
- Telemetry about each AI generation is sent to PostHog, including model identifier, token counts, latency, tool-call names, and (by default) the message content of inputs and outputs. We provide an internal configuration switch (
AI_ASSISTANT_PRIVACY_MODE) that suppresses message content from this telemetry when enabled while preserving the operational metrics. Tool-call arguments may include internal identifiers (group ids, product GIDs, variant GIDs); they do not include customer personal data. - The assistant input field is excluded from PostHog autocapture and any future session-replay surface. Server-side persistence and the LLM provider request are necessary to provide the feature; client-side analytics capture of the same text is not.
Please use the AI assistant only with information you are comfortable transmitting to third-party LLM providers. Avoid pasting customer personal data, payment details, credentials, or other sensitive information into the assistant. Use the standard admin UI for those tasks.
The privacy policies of our current LLM providers are available at:
- Anthropic: https://www.anthropic.com/legal/privacy
- Google Cloud (Vertex AI): https://cloud.google.com/terms/cloud-privacy-notice
- OpenAI: https://openai.com/policies/privacy-policy
File Uploads
When a customer uploads a file through an Optionfier file upload field:
- The file is temporarily staged on our secure servers (S3-compatible storage, US East region) while the customer completes their purchase.
- Upon successful checkout, the file is transferred to Shopify's file storage and permanently deleted from our servers.
- Files associated with abandoned carts or incomplete checkouts are automatically deleted from our servers after 7 days.
- Once transferred to Shopify, files are retained in your Shopify account until you manually delete them.
At no point do we access, view, analyze, or share the contents of uploaded files. They are treated as opaque data passed through to your Shopify orders.
How We Store Data
- Application database: Our database is hosted in the US East region. It stores your App configuration — option groups, option sets, settings, product connections, and AI assistant conversation history. It does not store customer personal information.
- Temporary file storage: Customer file uploads are temporarily stored on S3-compatible storage in the US East region as described above.
- Shopify: Order data, line item properties, bundle attributes, and permanent file storage are managed by Shopify under Shopify's own privacy policy and data processing terms.
Data Sharing
We do not sell, rent, or share your data or your customers' data with third parties, except:
- Shopify: Data is exchanged with Shopify through their API as required for the App to function.
- S3-compatible storage: Customer file uploads are temporarily staged on S3-compatible storage as described above.
- PostHog: Admin usage analytics, AI assistant telemetry, and server-side error reports are processed by PostHog as described above.
- LLM providers (Anthropic, Google Cloud / Vertex AI, OpenAI): When you use the AI assistant, your messages are sent to one or more of these providers for processing as described in the AI Assistant section above.
We do not use your data for advertising, marketing to your customers, or any purpose unrelated to providing the App's functionality.
Data Retention
- App configuration data (option groups, settings) is retained for as long as the App is installed. When you uninstall the App, Shopify sends a data erasure request after 48 hours, at which point all your configuration data is deleted from our systems immediately.
- Temporary file uploads are deleted from our servers within 7 days if not completed through checkout, or immediately upon successful transfer to Shopify.
- AI assistant conversation history is retained for as long as the App is installed. It is deleted alongside your other configuration data when you uninstall the App (see GDPR Compliance below).
- Admin analytics data (including AI assistant telemetry) is retained by PostHog according to their data retention policies.
- Error tracking data sent to PostHog is retained according to PostHog's data retention policies.
- LLM provider data: The retention of message data sent to Anthropic, Google Cloud (Vertex AI), and OpenAI is governed by each provider's own data retention policies.
GDPR Compliance
Optionfier supports Shopify's mandatory GDPR webhooks:
- Customer data request: When a customer requests their data, we respond with any data we hold associated with that customer. Because we do not store customer personal information in our database (option selections are stored on the Shopify order), our response will typically indicate that no additional data is held.
- Customer data erasure: When a customer requests erasure of their data, we delete any data associated with that customer from our systems.
- Shop data erasure: When a merchant uninstalls the App, Shopify sends a shop data erasure webhook after 48 hours. Upon receiving this webhook, we immediately and permanently delete all store configuration data, option groups, inventory adjustments, file upload records, sessions, settings, AI assistant conversation history, and any associated data from our systems in a single operation.
Your Rights
If you are a merchant, you can:
- Access your App configuration data at any time through the Optionfier admin interface.
- Export your configuration by contacting us.
- Request deletion of all your data by uninstalling the App or contacting us directly.
If you are a customer of a merchant using Optionfier, your data rights are governed by the merchant's own privacy policy and Shopify's privacy policy. Any data access or deletion requests should be directed to the merchant whose store you purchased from.
Security
We implement appropriate technical and organizational measures to protect data, including:
- All data transmitted between your browser, our servers, and Shopify is encrypted using TLS/HTTPS.
- Database access is restricted and authenticated.
- File uploads are stored in encrypted S3 buckets with restricted access.
- We regularly review and update our security practices.
Changes to This Policy
We may update this privacy policy from time to time. We will notify merchants of material changes through the App's admin interface or via email. The "Last updated" date at the top of this policy reflects the most recent revision.
Contact Us
If you have questions about this privacy policy or how Optionfier handles data, contact us at:
Real Studio Email: support@optionfier.com Location: Hallandale Beach, FL