This policy uses a few terms consistently. "MiMi", "we" or "us" means the business that publishes the MiMi apps. "Apps" means Stocktake & Inventory Count, Sell by Weight & More for POS, and MiMi Product Rentals. "Merchant" or "you" means the Shopify store owner who installs an App. "End customer" means a shopper who buys from that Merchant's store.
1. Who we are
MiMi builds and operates a small set of applications distributed through the Shopify App Store. This policy explains how we handle personal data in connection with those Apps and with this website.
The data controller for this website, and for our direct relationship with Merchants, is:
- [Registered legal entity name]
- [Registered business address, city, postal code, country]
- Company registration number: [Company registration number]
- Contact: mimiapps11@gmail.com
2. Scope of this policy
This policy applies to:
- Your use of any MiMi App installed on a Shopify store.
- Your use of this website at mimiapps.tech.
- Support conversations you have with us by email or through the Shopify App Store.
It does not apply to Shopify itself, to a Merchant's own storefront, or to any third-party service you connect independently. Shopify's handling of your data is governed by Shopify's Privacy Policy, and a Merchant's own storefront is governed by that Merchant's policy.
3. Controller and processor roles
Our role depends on whose data is involved, and this distinction matters for your rights:
| Data | Our role | What it means |
|---|---|---|
| Merchant account and contact data, website visitors, support emails | Controller | We decide why and how this data is processed. Direct your rights requests to us. |
| Store data processed inside the Apps, including any end-customer data attached to orders or rental bookings | Processor | We process it on the Merchant's instructions, for the purpose of running the App. The Merchant is the controller. End customers should contact the Merchant first. |
4. Information we collect
4.1 Store and installation data
When you install an App, Shopify provides us with information needed to run it. Depending on the App and the permissions you approve, this can include:
- Your shop domain, shop ID, store name, primary email address, country, currency and timezone.
- An OAuth access token that lets the App call the Shopify API on your behalf. We never receive or store your Shopify password.
- Your plan type and the App installation status.
4.2 Operational store data
Each App reads only the store data it needs to perform its function:
- Stocktake & Inventory Count — products, variants, SKUs and barcodes; inventory levels and inventory items; locations; collections and vendors; count sessions, discrepancy records, purchase orders and stock transfers created in the App.
- Sell by Weight & More for POS — products, variants, prices, product tags, unit and measurement configuration, inventory levels, and the order line items produced by measurement-based sales.
- MiMi Product Rentals — products and variants, availability and unit counts, rental bookings with start and return dates, deposits, delivery method eligibility, fulfilment and return records.
4.3 End-customer personal data
Most of what our Apps touch is inventory data, which contains no personal information. However, where a feature depends on an order — most notably rental bookings, which must be tied to the person who booked — the App will process limited end-customer data such as name, email address, order identifier, and the delivery address or method associated with the booking.
We process this data solely to make the feature work for the Merchant. We do not use it for our own marketing, we do not sell it, and we do not use it to build advertising or behavioural profiles.
4.4 Staff and POS user data
Where an App records who performed an action — for example, which staff member submitted an inventory count — we process the staff name or POS user identifier supplied by Shopify. This exists so that Merchants have an audit trail over stock adjustments.
4.5 Website data
When you visit this website we may process your IP address, browser type and version, device type, referring page, pages viewed and approximate location derived from IP. See our Cookie Policy for detail on what is set in your browser and how to control it.
4.6 Support communications
If you email us or contact us through the Shopify App Store, we keep your message, your contact details and our reply, so that we have a record of the issue and can follow up on it.
4.7 Technical logs
Our servers keep application logs recording API requests, errors, timestamps and identifiers such as shop domain. These are used to diagnose faults, investigate abuse and maintain reliability.
5. How we use information
We use the information described above to:
- Provide the App's features — counting stock, calculating measurement-based prices, managing rental availability, and writing approved changes back to Shopify.
- Authenticate your store and maintain your installation and settings.
- Respond to your support requests and investigate reported problems.
- Monitor reliability, detect errors, and prevent fraud, abuse or unauthorised access.
- Send service messages about outages, breaking changes or material updates to these terms.
- Improve the Apps, using aggregated and de-identified usage patterns that do not identify any store or individual.
- Comply with our legal obligations and with Shopify's Partner Program requirements.
We do not sell personal data, share it for cross-context behavioural advertising, or use your store's commercial data to benefit another merchant.
6. Legal bases (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
| Purpose | Legal basis |
|---|---|
| Delivering the App you installed | Performance of a contract (Art. 6(1)(b)) |
| Support, security, fraud prevention, product improvement | Legitimate interests (Art. 6(1)(f)) |
| Non-essential cookies and analytics | Consent (Art. 6(1)(a)) |
| Retaining records for tax, accounting or legal claims | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Processing end-customer data inside an App | On the Merchant's documented instructions, as processor (Art. 28) |
7. Sharing and sub-processors
We share personal data only where it is necessary to run the service. We do not sell it and we do not rent it. The categories of recipient are:
| Recipient | Purpose | Location |
|---|---|---|
| Shopify Inc. | The platform the Apps run on; source and destination of store data | Canada / United States |
| [Hosting provider, e.g. AWS / Google Cloud / Hetzner] | Application hosting, databases, backups | [Region] |
| [Error and performance monitoring provider] | Diagnosing crashes and faults | [Region] |
| [Email / support provider] | Sending service email and handling support tickets | [Region] |
| Professional advisers and authorities | Legal, accounting, or where disclosure is legally required | As applicable |
Every sub-processor is bound by a written agreement requiring confidentiality and appropriate security, and permitting them to process data only on our instructions. We will keep this list current; if we add a sub-processor that materially changes how your data is handled, we will update this page.
8. International transfers
We and our sub-processors may process data in countries other than yours, including the United States. Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or UK, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by additional safeguards where appropriate. You may request a copy of the relevant safeguards by emailing us.
9. Retention and deletion
We keep personal data only as long as we need it for the purpose it was collected, and then delete or anonymise it.
- While installed — we retain your store's App data for as long as the App remains installed, so that your history, settings and count records stay available to you.
- On uninstall — Shopify sends an
app/uninstalledwebhook immediately, and ashop/redactwebhook 48 hours later. We delete the store's data on receipt of the redaction request, within the period Shopify requires. - Customer data requests — on a
customers/data_requestwebhook we supply the Merchant with the personal data we hold for that customer. On acustomers/redactwebhook we erase it. - Logs — technical logs are retained for a limited operational period, typically no more than 90 days, and then rotated out.
- Support and billing records — kept for as long as needed to handle disputes and to meet tax, accounting and legal retention obligations.
- Backups — deleted data can persist briefly in encrypted backups and is removed as those backups expire on their normal cycle.
You do not have to wait for the automatic schedule. Email us and we will delete your store's data on request.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit using TLS, encryption at rest for stored data, least-privilege access controls, OAuth tokens instead of stored credentials, and restricted internal access on a need-to-know basis. Our Security page sets out our practices in more detail.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and, where required, the relevant supervisory authority, without undue delay and in accordance with applicable law.
11. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase your data where we no longer have grounds to keep it.
- Restrict processing in certain circumstances.
- Object to processing carried out on the basis of legitimate interests.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, where processing is based on consent. This does not affect processing already carried out.
- Complain to your local data protection authority. In the EEA this is your national supervisory authority; in the UK it is the Information Commissioner's Office.
To exercise any of these rights, email mimiapps11@gmail.com. We will respond within one month, and will tell you if we need longer because the request is complex. We may ask you to verify your identity before we act, to make sure we are not disclosing your data to somebody else.
If you are an end customer of a store using our Apps, please contact that Merchant first — they are the controller of your data. If they ask us to act, we will.
12. California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what personal information we collect and why, to request deletion, to request correction, and to be free from discrimination for exercising those rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We have not done so in the preceding twelve months. Where we handle personal information on behalf of a Merchant, we act as a service provider and are contractually restricted from using it for any purpose other than providing the service.
To make a request, email mimiapps11@gmail.com. You may use an authorised agent, in which case we will require proof of their authority.
13. Merchant responsibilities
If you are a Merchant using our Apps, you are the controller of your store's data, and you are responsible for:
- Having a lawful basis for the personal data you process about your own customers and staff.
- Maintaining your own privacy notice that accurately describes the apps and processors you use.
- Responding to your customers' data rights requests, and asking us for assistance where you need it.
- Configuring the App appropriately and controlling which of your staff have access to it.
We will assist you with these obligations to the extent required under Article 28 of the GDPR. If you need a signed Data Processing Agreement, email us and we will provide one.
14. Children's data
Our Apps and this website are business tools intended for merchants, and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the Apps change or as the law does. When we make a material change, we will update the effective date at the top of this page and, where the change significantly affects your rights, notify Merchants by email or through the App. Continuing to use the Apps after a change takes effect means you accept the updated policy.
16. How to contact us
For any privacy question, a data rights request, a signed DPA, or a complaint:
- Email: mimiapps11@gmail.com
- Postal: [Registered legal entity name], [Registered business address, city, postal code, country]
- Data protection contact: [Name or role, and EU/UK representative if you have appointed one]
We read everything that arrives, and we would much rather answer a question early than have you guess.