Privacy policy
Draft for review. This is starting text written for pimbo and hasn't been checked by a lawyer. Review it before launch; highlighted items need a decision.
Who we are
pimbo is provided by pimbo (add registered company name, number and address). We decide how account information for merchants and their teammates is used, which makes us its controller. For the customer information we sync from your Shopify store, you're the controller and we process it on your behalf.
What we collect
- Account details: the name and email address of the store owner and each invited teammate, and a password stored only as a secure hash. If you sign in with Google, we receive your name and email address from Google.
- Store data from Shopify: products, variants, collections and inventory, plus orders and customers. Orders and customer records include names, email addresses, phone numbers, billing and shipping addresses, order notes, marketing consent and order history.
- Security records: when something is changed in pimbo, we record what changed, who changed it, and the IP address and browser details used, so changes can be traced.
- Messages: anything you send us through the contact page or by email.
How we use it
- to run pimbo: syncing your store and showing your data to you and your team;
- to send the emails the service needs, such as team invitations and password resets;
- to keep accounts and data secure, and investigate misuse;
- to answer your questions and fix problems;
- to meet our legal obligations.
We don't sell personal information, and we don't use it for advertising.
Our legal bases
Under UK data protection law we rely on: providing the service you signed up for (contract); keeping the service secure and improving it (legitimate interests); and complying with the law (legal obligation).
Who we share it with
We share information only with the services that help us run pimbo:
- Shopify, where your store and its data live;
- our hosting provider, where pimbo and its database run (name the provider and region);
- Sentry, which receives error reports when something breaks; these can include an IP address;
- our email provider, which delivers invitations and password resets (name the provider);
- Google, if you choose to sign in with Google, and because our pages load fonts from Google Fonts, which receives your IP address.
Some of these providers process data outside the UK. Where they do, we rely on UK adequacy regulations or the UK's approved contract terms to protect it.
How long we keep it
- Account details: for as long as the account is active, then deleted.
- Store data: while pimbo is installed. When a store uninstalls pimbo, Shopify asks us to delete its data, usually 48 hours later, and we do.
- Individual shoppers' data: deleted when a store's customer asks Shopify to erase it and Shopify passes that request on.
- Security records: kept for (set a retention period), then deleted.
Keeping it secure
Data travels over encrypted connections, access tokens for your Shopify store are encrypted at rest, and passwords are stored only as hashes. Access to the service is limited to your store's team, who each sign in separately.
Your rights
You can ask to see, correct or delete your personal information, to restrict or object to how we use it, or to receive a copy to take elsewhere. Contact us using the details below. If you're unhappy with our answer, you can complain to the Information Commissioner's Office at ico.org.uk.
If you shop with a store that uses pimbo
The store decides how your information is used, so contact the store first. We act on the data requests Shopify passes to us on the store's behalf.
Changes to this policy
We'll update this policy when how we handle information changes, and change the date at the top when we do.
Contact
Privacy questions and requests: the contact page.