GlidePod Privacy Policy

Effective and last updated: July 2, 2026

This policy explains how GlidePod (the developer identified in the GlidePod Shopify App Store listing, referred to as “GlidePod”, “we”, “us”, or “our”) processes personal data when Shopify merchants install or use the app and when buyers use the storefront product designer.

1. Our role

For buyer and order data processed to provide services to a merchant, the merchant generally determines why and how the data is used and GlidePod acts as its service provider or processor. The merchant's own privacy policy also applies. We act as a controller for data used to administer merchant accounts, provide support, secure the service, bill merchants, and meet our legal obligations.

2. Data we process

3. Storefront cookie

GlidePod sets a first-party cookie named pod_session_uuid. It contains a random identifier, expires after 30 days, and is used to reconnect a buyer with saved or in-progress designs. It is not used for advertising or cross-site behavioral tracking. Merchants are responsible for presenting any cookie notice or obtaining consent required by the laws that apply to their storefront.

4. How we use data

We do not use personal data for automated decisions that produce legal or similarly significant effects.

5. Legal bases and merchant instructions

Where applicable, we rely on performance of our contract, legitimate interests in operating and securing the service, consent, and compliance with legal obligations. When we process buyer data for a merchant, we do so on the merchant's documented instructions. Merchants are responsible for having an appropriate legal basis and providing required notices for their use of the app.

6. Service providers and disclosures

We do not sell personal data or use it for cross-context behavioral advertising. We disclose data only as needed to:

7. Public design links

Saved designs can be accessed through an unguessable public link used for cart, order, customer email, and fulfillment workflows. Anyone who receives that link can view the associated artwork and design choices. Merchants and buyers should treat design links as confidential and avoid uploading sensitive personal data. Full customer contact and shipping details are not shown through a public design link and require an authenticated app administrator.

8. Retention and deletion

9. Security and international transfers

We use administrative, technical, and organizational safeguards designed to protect data, including HTTPS in transit, access controls, authenticated Shopify webhooks, and restricted administrative access. No system is completely secure. Data may be processed outside the merchant's or buyer's country; where required, the parties responsible for the transfer must use an approved transfer mechanism.

10. Privacy rights

Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, and to withdraw consent. Buyers should normally contact the Shopify merchant first. Merchants and buyers may also contact us below. We authenticate and process Shopify's mandatory customers/data_request, customers/redact, and shop/redact requests. Individuals may also complain to their local data protection authority.

11. Children

GlidePod is not directed to children and we do not knowingly collect children's personal data outside a merchant-directed transaction.

12. Changes and contact

We may update this policy and will publish the revised date on this page. For privacy questions or requests, email [email protected]. Merchant support and the developer's business contact details are also available through the GlidePod Shopify App Store listing.