Privacy Policy — Varto
Varto ← Back to homepage
Legal

Privacy Policy

This policy applies to vartoapps.com and all Shopify applications published under Varto by Bohdan Manko.

Last updated: August 30, 2026

Bohdan Manko, operating as Varto ("we", "us", "our"), is committed to protecting the privacy of merchants who install our Shopify applications and visitors to vartoapps.com. This policy explains what data we collect, why, and how it is handled.

1. Website — vartoapps.com

Data collected

vartoapps.com uses Google Analytics. This service may automatically collect:

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Pages visited, time spent, and referrer URL
  • Device identifiers via cookies

We do not require visitors to create an account or directly provide personal information through vartoapps.com. However, Google Analytics may automatically process technical, device, and usage information as described above.

Cookies and local storage

Google Analytics sets cookies to distinguish visitors and measure traffic. Your theme preference (light/dark) is stored in localStorage on your device only and is never transmitted.

You can control or disable cookies through your browser settings at any time. You may also opt out of Google Analytics using the option described below.

Third-party services

Opt out of Analytics via the Google Analytics Opt-out Add-on.

2. Shopify Applications — Varto

This section applies to all Shopify applications published by Varto and governs the data we access from Shopify merchants and their customers.

2.1 Data we collect from merchants

When a merchant installs one of our apps, we may access the following data through the Shopify Admin API, limited to the scopes required by each specific application:

Data type
Purpose
Shop domain & name
Identify the merchant account; provide app functionality
Shop email & owner name
Communicate about the app; send transactional notices
Store plan & currency
Determine feature availability; billing calculations
Products & collections
App-specific features (only when required by the app)
Orders & transactions
App-specific features (only when required by the app)
Customers
App-specific features (only when required by the app)
Access tokens (OAuth)
Authenticate API calls on behalf of the merchant

Each app's Shopify listing specifies the exact API scopes it requests. We do not request scopes beyond what the app requires to function.

Per-app scopes — Varto Product Reviews

Varto Product Reviews requests access to the following data only:

  • Staff and contributor data — store owner: name, email address, phone number, physical address
  • Store data — products: products and collections, used to target review campaigns

Review submissions collected on the storefront (rating, answers, and any name or email the shopper provides) are stored on our infrastructure on the merchant's behalf.

2.2 Data we collect from end-customers

Some apps may process data about a merchant's customers (such as names, email addresses, or order information) solely to provide the service to the merchant. We act as a data processor on behalf of the merchant, who is the data controller for their customers' information.

We do not use customer data for our own marketing, analytics, or any purpose other than delivering the app's stated functionality.

2.3 How we use merchant data

  • To authenticate and authorise API requests to Shopify
  • To provide, maintain, and improve the application's core functionality
  • To respond to merchant support requests
  • To send critical service notifications (downtime, breaking changes)
  • To comply with legal obligations

We do not sell, rent, or share merchant data with third parties for advertising or marketing purposes.

2.4 Data sharing

We may share data only as necessary to operate our services, including with:

  • Hosting and infrastructure providers — services used to host, store, secure, monitor, and operate the application, subject to appropriate contractual and data-protection safeguards
  • Shopify — as required to operate within the Shopify platform
  • Law enforcement — when required by applicable law or a valid legal request

We do not sell personal information or share it with third parties for their own advertising or marketing purposes. Service providers may process data in countries outside the merchant or customer's country of residence. Where required by applicable law, we use appropriate safeguards for international data transfers.

2.5 Data retention

We retain merchant data for as long as necessary to provide the app and meet applicable legal obligations. After an app is uninstalled, Shopify sends the mandatory shop/redact webhook. After receiving that request, we delete or anonymise applicable merchant data within 30 days, unless longer retention is required by law.

Customer data covered by a Shopify deletion request is deleted or anonymised after we receive the customers/redact webhook, within 30 days of receiving the request, unless retention is required by law.

2.6 Shopify privacy compliance webhooks

Our apps implement Shopify's mandatory privacy compliance webhooks:

Webhook
Action taken
customers/data_request
We compile and provide all data held for the specified customer upon merchant request
customers/redact
We delete or anonymise all data held for the specified customer within 30 days
shop/redact
We delete or anonymise applicable data associated with the merchant's store within 30 days of receiving the webhook, unless retention is required by law

2.7 Security

We implement reasonable technical and organisational measures designed to protect data, including encrypted connections (TLS), access controls, and regular security reviews. Shopify OAuth tokens are stored encrypted. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

3. Your rights

GDPR and UK GDPR (EEA / UK residents)

Subject to applicable law, you may have the right to access, correct, erase, restrict or object to certain processing of, and receive a portable copy of, personal data we hold about you. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a supervisory authority. To exercise your rights, contact us at the address below. We will respond within the period required by applicable law.

California privacy rights (CCPA / CPRA)

Subject to applicable law, California residents may have the right to know and access personal information we collect, request correction or deletion, and opt out of certain sales or sharing of personal information. We do not sell personal information or share it for cross-context behavioural advertising. To make a request, contact us below.

Merchant rights

Merchants may request a copy of data we hold for their store or request deletion of that data by contacting us. Uninstalling an app also initiates Shopify's privacy-deletion process described in section 2.5.

4. Children's privacy

Our services are not directed to anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it promptly.

5. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date above. Where required by applicable law, we will provide additional notice of material changes.

6. Contact

For any privacy-related questions, data requests, or complaints:

Developer
Bohdan Manko (Varto)
Location
Lviv, Ukraine