Varia privacy policy
Last updated 8 September 2026
Varia adds custom options to Shopify product pages and charges for them at checkout. This policy describes what the app stores, what it deliberately does not, and how to have it removed.
What Varia stores
- The myshopify.com domain of the store that installed the app, and the access token Shopify issues for it.
- The option sets a merchant configures: field names, help text, choices, prices, and which products they apply to.
- Identifiers for the helper product and checkout function Varia creates in the store.
What Varia does not store
- Varia does not store personal information about a store's customers. No names, no email addresses, no order history.
- Answers a buyer gives to an option, such as engraving text or an uploaded file, are attached to the Shopify order by Shopify. They are never copied into Varia's database.
- Prices are calculated inside a Shopify Function running on Shopify's own infrastructure. Varia does not receive cart or checkout contents on its servers.
Why Varia needs the permissions it asks for
- Products: to create and maintain one hidden helper product per store. Option charges are attached to it at checkout, which is what avoids creating a duplicate product for every priced option.
- Cart transforms: to register the checkout function that applies those charges.
- Publications: to publish the helper product to the Online Store, without which the charge is silently rejected at checkout.
Sharing
- Varia does not sell data and does not share it with third parties for advertising.
- Data is stored with our hosting and database providers (Vercel and Neon) solely to operate the app.
Deletion
- When a store uninstalls Varia, its session is deleted immediately.
- Shopify sends a shop/redact request 48 hours after uninstall. On receiving it, Varia deletes that store's option sets, settings and any remaining session records.
- Requests about customer data (customers/data_request, customers/redact) are answered honestly: Varia holds no customer data to return or erase.
Contact
- Questions about this policy, or a request relating to your data, can be sent to ravlinapp@gmail.com.