Legal Privacy Policy

Privacy Policy

v2.0 · Last updated: 21 July 2026

01Who we are

InRoom Wall Art (the "App") is a Shopify application that lets shoppers preview wall art on their own wall — using Apple AR Quick Look and an in-browser 2D collage editor — and lets merchants configure that experience from the Shopify admin.

The data controller responsible for the personal data described here is:

  • Data controller: Ian Otero Casamitjana (individual / sole trader)
  • ID (NIF): 54756076E
  • Address: Sabadell (Barcelona), Spain
  • Contact / data protection: eco9one@gmail.com

We are established in Spain and act as data controller for merchant and app-operation data. Where we process the personal data of a merchant's own customers, we act as a data processor on the merchant's behalf (the merchant is the controller of their customers' data).

02Scope

This policy covers:

  • The InRoom Wall Art Shopify app installed on a merchant's store (the admin experience).
  • The storefront experience the App adds to product pages (Apple AR Quick Look and the 2D collage editor).
  • The marketing website at inroom.es.
  • Support communications with us.

It does not cover the merchant's own storefront, checkout, or privacy practices, nor Shopify's own processing. Each merchant remains responsible for their store's own privacy policy.

03Merchant data we process

When you install and use the App, we process the following data about the merchant and its staff:

CategoryWhat it includes
Store & sessionShopify store domain, Shopify OAuth access and refresh tokens, and — for the signed-in staff user — first name, last name, email, locale and account-owner / collaborator flags. Used to authenticate the App with Shopify.
Product catalogueA synced copy of your products: titles, descriptions, handles, vendor, product type, tags, image URLs, variants and prices. Read from the Shopify Admin API to power the preview. We do not modify your products except where you explicitly ask the App to create or update a product.
App configurationYour appearance settings, collage editor settings, frame definitions and feature toggles.
Billing & usageSubscription plan and status, Shopify charge IDs, and usage-based charges for each product you activate with AR. Payment is handled by Shopify Billing — we never see or store your card details.
SupportEmails and messages you send us, and the contents needed to resolve them.

04Shopper data (your customers)

The App is deliberately built to process as little shopper data as possible.

  • The preview runs on the shopper's device. Apple AR Quick Look and the 2D collage editor run in the shopper's browser/device. Any photo or camera view the shopper uses stays on their device and is not uploaded to, transmitted to, or stored on our servers.
  • Anonymous usage events. The App may record anonymous interaction events (for example: preview opened, item added to cart) tied to a random session identifier plus the product/variant involved and a timestamp. These events do not include names, emails, addresses, or any information that identifies the shopper.
  • No end-customer identity data. We do not collect shopper names, emails, phone numbers, addresses or payment data. That information flows through Shopify and the merchant — never through InRoom Wall Art.

05Purposes & legal basis (GDPR)

PurposeLegal basis (Art. 6 GDPR)
Providing the App to the merchant (authentication, catalogue sync, AR/2D preview, configuration)Contract — Art. 6(1)(b)
Billing, tax and accounting recordsLegal obligation — Art. 6(1)(c)
Anonymous product analytics and improving the AppLegitimate interest — Art. 6(1)(f)
Security, fraud and abuse preventionLegitimate interest — Art. 6(1)(f)
Marketing emails to merchants (if any)Consent — Art. 6(1)(a), withdrawable at any time

06Sub-processors

We rely on the following sub-processors, each bound by a Data Processing Agreement (DPA) and, for transfers outside the EEA, by the EU Standard Contractual Clauses (SCCs):

ProviderPurpose & dataLocation
Shopify Inc.App platform, merchant authentication, product catalogue, billing and GDPR webhooks. DPACanada / EU
Railway Corp.Hosting of the App backend and admin, and the managed PostgreSQL database. DPAUSA (EU region)
Cloudflare, Inc.CDN and DDoS protection at the network edge (marketing site, and optionally in front of the App). DPAUSA (EU edge)

We do not sell personal data. We will update this list before adding a new sub-processor that changes how personal data is handled.

07International transfers

Some sub-processors (Railway Corp. and Cloudflare) are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR — primarily the EU Standard Contractual Clauses (SCCs) and equivalent mechanisms in each provider's DPA.

08Data retention

  • Store data (session, catalogue copy, configuration). Kept while the App is installed. When you uninstall, Shopify sends a shop/redact request (about 48 hours later) and we then delete the store's data from our database.
  • Billing records. Retained as required by tax and accounting law, even after uninstall.
  • Anonymous analytics events. Retained in aggregate; not tied to any identifiable person.
  • Support emails. Kept up to 24 months after the last contact.

09Security

We apply appropriate technical and organisational measures, including: HTTPS/TLS in transit, access controls on the database and infrastructure consoles, HMAC verification of all Shopify webhooks, and idempotency controls to avoid duplicate processing. No system is perfectly secure; if a personal-data breach is likely to create a risk to your rights, we will notify the competent supervisory authority within 72 hours and affected merchants without undue delay, as required by GDPR.

10Your rights

If you are in the EEA, the UK or Switzerland you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing is based on consent.

To exercise any right, contact us at eco9one@gmail.com. You also have the right to lodge a complaint with your supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD).

If your request concerns data we process on behalf of a merchant (as processor), we will refer you to, or coordinate with, that merchant as the controller.

11Cookies & local storage

The marketing site uses only strictly-necessary cookies. This legal page stores your language choice in the browser's local storage (inroom-legal-lang). The storefront experience may use a random, non-identifying session value in the device's local storage to make the preview work — it contains no personal data. We do not use advertising or cross-site tracking cookies.

12Children

The App is intended for merchants and adult shoppers. We do not knowingly collect personal data from children under the age of digital consent in their country. If you believe a child has provided us personal data, contact eco9one@gmail.com and we will delete it.

13Shopify GDPR webhooks

As required by the Shopify App Store, the App implements the mandatory compliance webhooks and verifies their HMAC signature:

  • customers/data_request — we acknowledge the request. Because the App does not store identifiable end-customer data, there is normally no such data to return.
  • customers/redact — we acknowledge the request; there is normally no identifiable end-customer data to delete.
  • shop/redact — when a merchant uninstalls, we delete that store's records from our database (sessions, catalogue copy, billing, usage, analytics and configuration).

14Changes to this policy

We may update this policy. We will change the "Last updated" date above and, for material changes, notify merchants in-app or by email before the change takes effect.

15Contact

For any privacy question or request: eco9one@gmail.com. Registered controller: Ian Otero Casamitjana, Sabadell (Barcelona), Spain.

Legal Política de Privacidad

Política de Privacidad

v2.0 · Última actualización: 21 de julio de 2026

01Quiénes somos

InRoom Wall Art (la "App") es una aplicación de Shopify que permite al comprador previsualizar cuadros y láminas sobre su propia pared —mediante Apple AR Quick Look y un editor de collage 2D en el navegador— y permite al merchant configurar esa experiencia desde el admin de Shopify.

El responsable del tratamiento de los datos personales descritos aquí es:

  • Responsable: Ian Otero Casamitjana (persona física)
  • NIF (DNI): 54756076E
  • Domicilio: Sabadell (Barcelona), España
  • Contacto / protección de datos: eco9one@gmail.com

Estamos establecidos en España y actuamos como responsable respecto de los datos del merchant y de la operación de la App. Cuando tratamos datos personales de los clientes del merchant, actuamos como encargado del tratamiento por cuenta del merchant (que es el responsable de los datos de sus clientes).

02Ámbito

Esta política cubre:

  • La app InRoom Wall Art instalada en la tienda del merchant (el admin).
  • La experiencia que la App añade a las páginas de producto del storefront (Apple AR Quick Look y el editor de collage 2D).
  • El sitio web inroom.es.
  • Las comunicaciones de soporte con nosotros.

No cubre el storefront, el checkout ni las prácticas de privacidad propias del merchant, ni el tratamiento que realiza Shopify. Cada merchant sigue siendo responsable de su propia política de privacidad.

03Datos del merchant que tratamos

Al instalar y usar la App, tratamos los siguientes datos del merchant y su personal:

CategoríaQué incluye
Tienda y sesiónDominio de la tienda Shopify, tokens OAuth de acceso y de refresco y —del usuario que inicia sesión— nombre, apellidos, email, idioma y marcas de propietario/colaborador. Se usan para autenticar la App con Shopify.
Catálogo de productosUna copia sincronizada de tus productos: títulos, descripciones, handles, proveedor, tipo, etiquetas, URLs de imágenes, variantes y precios. Se lee de la Admin API de Shopify para hacer funcionar la previsualización. No modificamos tus productos salvo cuando pides expresamente a la App crear o actualizar uno.
Configuración de la AppAjustes de apariencia, del editor de collage, definiciones de marcos y activadores de funciones.
Facturación y usoPlan y estado de suscripción, IDs de cargo de Shopify y cargos por uso por cada producto que actives con AR. El pago lo gestiona Shopify Billing — nunca vemos ni guardamos los datos de tu tarjeta.
SoporteLos emails y mensajes que nos envías y el contenido necesario para resolverlos.

04Datos del cliente final (tus compradores)

La App está diseñada a propósito para tratar el mínimo de datos del comprador posible.

  • La previsualización se ejecuta en el dispositivo del comprador. Apple AR Quick Look y el editor de collage 2D funcionan en el navegador/dispositivo del comprador. Cualquier foto o vista de cámara que use el comprador permanece en su dispositivo y no se sube, transmite ni almacena en nuestros servidores.
  • Eventos de uso anónimos. La App puede registrar eventos de interacción anónimos (por ejemplo: previsualización abierta, añadido al carrito) asociados a un identificador de sesión aleatorio, al producto/variante implicado y a una marca de tiempo. Estos eventos no incluyen nombres, emails, direcciones ni ningún dato que identifique al comprador.
  • Sin datos de identidad del cliente final. No recogemos nombres, emails, teléfonos, direcciones ni datos de pago del comprador. Esa información circula por Shopify y el merchant — nunca por InRoom Wall Art.

05Fines y base legal (RGPD)

FinBase legal (Art. 6 RGPD)
Prestar la App al merchant (autenticación, sync de catálogo, previsualización AR/2D, configuración)Contrato — Art. 6(1)(b)
Facturación, obligaciones fiscales y contablesObligación legal — Art. 6(1)(c)
Analítica de producto anónima y mejora de la AppInterés legítimo — Art. 6(1)(f)
Seguridad, prevención de fraude y abusoInterés legítimo — Art. 6(1)(f)
Emails de marketing al merchant (si los hubiera)Consentimiento — Art. 6(1)(a), revocable en cualquier momento

06Subencargados del tratamiento

Nos apoyamos en los siguientes subencargados, cada uno vinculado por un Acuerdo de Encargo (DPA) y, para transferencias fuera del EEE, por las Cláusulas Contractuales Tipo (SCC) de la UE:

ProveedorFinalidad y datosUbicación
Shopify Inc.Plataforma de la app, autenticación del merchant, catálogo, facturación y webhooks RGPD. DPACanadá / UE
Railway Corp.Hosting del backend y admin de la App y base de datos PostgreSQL gestionada. DPAEE. UU. (región UE)
Cloudflare, Inc.CDN y protección DDoS en el edge de red (sitio de marketing y, opcionalmente, delante de la App). DPAEE. UU. (edge UE)

No vendemos datos personales. Actualizaremos esta lista antes de incorporar un nuevo subencargado que cambie el tratamiento de datos personales.

07Transferencias internacionales

Algunos subencargados (Railway Corp. y Cloudflare) están establecidos en EE. UU. Cuando se transfieren datos personales fuera del Espacio Económico Europeo, aplicamos garantías adecuadas conforme al Capítulo V del RGPD — principalmente las Cláusulas Contractuales Tipo (SCC) y mecanismos equivalentes en el DPA de cada proveedor.

08Conservación de datos

  • Datos de la tienda (sesión, copia del catálogo, configuración). Se conservan mientras la App está instalada. Al desinstalar, Shopify envía una solicitud shop/redact (unas 48 horas después) y entonces borramos los datos de esa tienda de nuestra base de datos.
  • Registros de facturación. Se conservan según exige la normativa fiscal y contable, incluso tras la desinstalación.
  • Eventos de analítica anónimos. Se conservan de forma agregada; no vinculados a ninguna persona identificable.
  • Emails de soporte. Hasta 24 meses tras el último contacto.

09Seguridad

Aplicamos medidas técnicas y organizativas adecuadas, incluyendo: HTTPS/TLS en tránsito, controles de acceso a la base de datos y a las consolas de infraestructura, verificación HMAC de todos los webhooks de Shopify y controles de idempotencia para evitar procesamientos duplicados. Ningún sistema es totalmente seguro; si una brecha de datos personales entraña un riesgo para tus derechos, lo notificaremos a la autoridad de control competente en un plazo de 72 horas y a los merchants afectados sin dilación indebida, según el RGPD.

10Tus derechos

Si te encuentras en el EEE, Reino Unido o Suiza, tienes derecho a acceder, rectificar, suprimir, limitar, portar y oponerte al tratamiento de tus datos personales, y a retirar el consentimiento cuando el tratamiento se base en él.

Para ejercer cualquier derecho, escríbenos a eco9one@gmail.com. También puedes presentar una reclamación ante tu autoridad de control — en España, la Agencia Española de Protección de Datos (AEPD).

Si tu solicitud se refiere a datos que tratamos por cuenta de un merchant (como encargados), te remitiremos a dicho merchant o coordinaremos con él como responsable.

11Cookies y almacenamiento local

El sitio de marketing usa solo cookies estrictamente necesarias. Esta página legal guarda tu elección de idioma en el almacenamiento local del navegador (inroom-legal-lang). La experiencia de storefront puede usar un valor de sesión aleatorio y no identificativo en el almacenamiento local del dispositivo para que la previsualización funcione — no contiene datos personales. No usamos cookies publicitarias ni de seguimiento entre sitios.

12Menores

La App está dirigida a merchants y a compradores adultos. No recogemos conscientemente datos personales de menores de la edad de consentimiento digital de su país. Si crees que un menor nos ha facilitado datos personales, escribe a eco9one@gmail.com y los eliminaremos.

13Webhooks RGPD de Shopify

Según exige la Shopify App Store, la App implementa los webhooks obligatorios de cumplimiento y verifica su firma HMAC:

  • customers/data_request — acusamos recibo de la solicitud. Como la App no almacena datos identificables del cliente final, normalmente no hay datos que devolver.
  • customers/redact — acusamos recibo; normalmente no hay datos identificables del cliente final que borrar.
  • shop/redact — cuando un merchant desinstala, borramos los registros de esa tienda de nuestra base de datos (sesiones, copia del catálogo, facturación, uso, analítica y configuración).

14Cambios en esta política

Podemos actualizar esta política. Cambiaremos la fecha de "Última actualización" de arriba y, para cambios sustanciales, avisaremos a los merchants en la app o por email antes de que el cambio surta efecto.

15Contacto

Para cualquier cuestión o solicitud de privacidad: eco9one@gmail.com. Responsable inscrito: Ian Otero Casamitjana, Sabadell (Barcelona), España.