Last updated: August 7, 2026
This policy explains what data the Shopify app Wink: Video on Hover ("the App") processes, why, and for how long. It is written to meet Regulation (EU) 2016/679 (GDPR) and the French Loi Informatique et Libertés.
Bandia, société par actions simplifiée à associé unique (SASU), registered in France under SIREN 105 011 043,
registered office: 3 passage Bullourde, 75011 Paris, France.
Contact for any privacy question or request: simon@bandia.fr.
The App is not required to appoint a Data Protection Officer (GDPR Art. 37) and has not done so. Requests are handled directly at the address above.
The App is installed by merchants on their own Shopify store. Its only users are the merchant and their staff.
The App does not collect any data about store visitors or buyers. It does not request the read_customers or read_orders permissions, so Shopify never transmits customer or order data to it. The storefront script sets no cookies, sends no analytics, and makes no request to any third party: it reads the configuration rendered by the theme app embed block and plays videos served by Shopify's own CDN.
| Data | Purpose | Legal basis | Where it is stored |
|---|---|---|---|
Shop domain (e.g. example.myshopify.com) and Shopify offline access token |
Authenticate the App against the merchant's store — without it the App cannot run | Performance of the contract (Art. 6(1)(b)) | Our PostgreSQL database, hosted on Fly.io (Paris region, EU) |
| Product data read from the store: titles, handles, images, video media | List the merchant's products in the App and identify which already have a video | Performance of the contract (Art. 6(1)(b)) | Not stored by us — read on demand from Shopify and displayed |
App settings and per-product on/off state (wink metafields) |
Remember the merchant's configuration | Performance of the contract (Art. 6(1)(b)) | Inside the merchant's own Shopify store, as app-owned metafields |
| Videos uploaded through the App | Play them on hover on the storefront | Performance of the contract (Art. 6(1)(b)) | The merchant's Shopify product media, served by Shopify's CDN — we keep no copy |
| Technical server logs (IP address, timestamp, requested URL) | Security, error diagnosis, service availability | Legitimate interest (Art. 6(1)(f)) | Fly.io infrastructure |
Personal data in the strict sense is therefore limited to what identifies the merchant's store and account, plus technical logs. The App performs no profiling and no automated decision-making.
app/uninstalled webhook, and again by the shop/redact webhook that Shopify sends 48 hours after uninstall as a backstop.wink metafields: removed by Shopify when the App is uninstalled, since they are app-owned. The uninstall webhook also deletes the settings metafield while the access token is still valid.Data is never sold, rented, or used for advertising. It is shared only with the technical providers strictly required to run the service:
| Provider | Role | Location |
|---|---|---|
| Shopify International Ltd. | Platform hosting the store, the videos, and the metafields | Ireland (EU) / Canada, with Standard Contractual Clauses |
| Fly.io, Inc. | Application and database hosting | Paris region (EU) for this app |
No data is transferred outside the European Union by the App itself. Transfers performed by Shopify are governed by Shopify's own privacy policy and its Standard Contractual Clauses.
Under GDPR Articles 15 to 22, you have the right to access, rectify, erase, restrict, and port your data, and to object to its processing. To exercise any of these, write to simon@bandia.fr. We reply within one month.
Uninstalling the App from your Shopify admin triggers erasure automatically, as described in section 4.
If you consider that your rights are not respected, you may lodge a complaint with the French supervisory authority, the CNIL — www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — or with the authority of your country of residence.
The App sets no advertising or analytics cookies. Inside the Shopify admin, the session cookies strictly necessary for authentication are set by Shopify. On the storefront, the App's script uses only the browser's sessionStorage to cache video URLs for the duration of the visit; this holds no personal data and is cleared when the tab is closed.
All traffic is served over HTTPS. Access tokens are stored in a database that is not publicly reachable. Every webhook received from Shopify is verified by HMAC signature and rejected with HTTP 401 if the signature is invalid.
This policy may be updated as the App evolves. The date at the top always reflects the version in force. Any substantial change is communicated to merchants who have installed the App.
Bandia — simon@bandia.fr