01Who we are
InRoom Wall Art (the "App") is a Shopify application that lets shoppers preview wall art on their own wall — using Apple AR Quick Look and an in-browser 2D collage editor — and lets merchants configure that experience from the Shopify admin.
The data controller responsible for the personal data described here is:
- Data controller: Ian Otero Casamitjana (individual / sole trader)
- ID (NIF): 54756076E
- Address: Sabadell (Barcelona), Spain
- Contact / data protection: eco9one@gmail.com
We are established in Spain and act as data controller for merchant and app-operation data. Where we process the personal data of a merchant's own customers, we act as a data processor on the merchant's behalf (the merchant is the controller of their customers' data).
02Scope
This policy covers:
- The InRoom Wall Art Shopify app installed on a merchant's store (the admin experience).
- The storefront experience the App adds to product pages (Apple AR Quick Look and the 2D collage editor).
- The marketing website at
inroom.es. - Support communications with us.
It does not cover the merchant's own storefront, checkout, or privacy practices, nor Shopify's own processing. Each merchant remains responsible for their store's own privacy policy.
03Merchant data we process
When you install and use the App, we process the following data about the merchant and its staff:
| Category | What it includes |
|---|---|
| Store & session | Shopify store domain, Shopify OAuth access and refresh tokens, and — for the signed-in staff user — first name, last name, email, locale and account-owner / collaborator flags. Used to authenticate the App with Shopify. |
| Product catalogue | A synced copy of your products: titles, descriptions, handles, vendor, product type, tags, image URLs, variants and prices. Read from the Shopify Admin API to power the preview. We do not modify your products except where you explicitly ask the App to create or update a product. |
| App configuration | Your appearance settings, collage editor settings, frame definitions and feature toggles. |
| Billing & usage | Subscription plan and status, Shopify charge IDs, and usage-based charges for each product you activate with AR. Payment is handled by Shopify Billing — we never see or store your card details. |
| Support | Emails and messages you send us, and the contents needed to resolve them. |
04Shopper data (your customers)
The App is deliberately built to process as little shopper data as possible.
- The preview runs on the shopper's device. Apple AR Quick Look and the 2D collage editor run in the shopper's browser/device. Any photo or camera view the shopper uses stays on their device and is not uploaded to, transmitted to, or stored on our servers.
- Anonymous usage events. The App may record anonymous interaction events (for example: preview opened, item added to cart) tied to a random session identifier plus the product/variant involved and a timestamp. These events do not include names, emails, addresses, or any information that identifies the shopper.
- No end-customer identity data. We do not collect shopper names, emails, phone numbers, addresses or payment data. That information flows through Shopify and the merchant — never through InRoom Wall Art.
05Purposes & legal basis (GDPR)
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the App to the merchant (authentication, catalogue sync, AR/2D preview, configuration) | Contract — Art. 6(1)(b) |
| Billing, tax and accounting records | Legal obligation — Art. 6(1)(c) |
| Anonymous product analytics and improving the App | Legitimate interest — Art. 6(1)(f) |
| Security, fraud and abuse prevention | Legitimate interest — Art. 6(1)(f) |
| Marketing emails to merchants (if any) | Consent — Art. 6(1)(a), withdrawable at any time |
06Sub-processors
We rely on the following sub-processors, each bound by a Data Processing Agreement (DPA) and, for transfers outside the EEA, by the EU Standard Contractual Clauses (SCCs):
| Provider | Purpose & data | Location |
|---|---|---|
| Shopify Inc. | App platform, merchant authentication, product catalogue, billing and GDPR webhooks. DPA | Canada / EU |
| Railway Corp. | Hosting of the App backend and admin, and the managed PostgreSQL database. DPA | USA (EU region) |
| Cloudflare, Inc. | CDN and DDoS protection at the network edge (marketing site, and optionally in front of the App). DPA | USA (EU edge) |
We do not sell personal data. We will update this list before adding a new sub-processor that changes how personal data is handled.
07International transfers
Some sub-processors (Railway Corp. and Cloudflare) are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR — primarily the EU Standard Contractual Clauses (SCCs) and equivalent mechanisms in each provider's DPA.
08Data retention
- Store data (session, catalogue copy, configuration). Kept while the App is installed. When you uninstall, Shopify sends a
shop/redactrequest (about 48 hours later) and we then delete the store's data from our database. - Billing records. Retained as required by tax and accounting law, even after uninstall.
- Anonymous analytics events. Retained in aggregate; not tied to any identifiable person.
- Support emails. Kept up to 24 months after the last contact.
09Security
We apply appropriate technical and organisational measures, including: HTTPS/TLS in transit, access controls on the database and infrastructure consoles, HMAC verification of all Shopify webhooks, and idempotency controls to avoid duplicate processing. No system is perfectly secure; if a personal-data breach is likely to create a risk to your rights, we will notify the competent supervisory authority within 72 hours and affected merchants without undue delay, as required by GDPR.
10Your rights
If you are in the EEA, the UK or Switzerland you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing is based on consent.
To exercise any right, contact us at eco9one@gmail.com. You also have the right to lodge a complaint with your supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD).
If your request concerns data we process on behalf of a merchant (as processor), we will refer you to, or coordinate with, that merchant as the controller.
11Cookies & local storage
The marketing site uses only strictly-necessary cookies. This legal page stores your language choice in the browser's local storage (inroom-legal-lang). The storefront experience may use a random, non-identifying session value in the device's local storage to make the preview work — it contains no personal data. We do not use advertising or cross-site tracking cookies.
12Children
The App is intended for merchants and adult shoppers. We do not knowingly collect personal data from children under the age of digital consent in their country. If you believe a child has provided us personal data, contact eco9one@gmail.com and we will delete it.
13Shopify GDPR webhooks
As required by the Shopify App Store, the App implements the mandatory compliance webhooks and verifies their HMAC signature:
customers/data_request— we acknowledge the request. Because the App does not store identifiable end-customer data, there is normally no such data to return.customers/redact— we acknowledge the request; there is normally no identifiable end-customer data to delete.shop/redact— when a merchant uninstalls, we delete that store's records from our database (sessions, catalogue copy, billing, usage, analytics and configuration).
14Changes to this policy
We may update this policy. We will change the "Last updated" date above and, for material changes, notify merchants in-app or by email before the change takes effect.
15Contact
For any privacy question or request: eco9one@gmail.com. Registered controller: Ian Otero Casamitjana, Sabadell (Barcelona), Spain.