Privacy Policy

1. Introduction

This Privacy Policy explains how Hipwerk GmbH ("we", "us", or "our") collects, uses, and protects your information when you use Varient, a Shopify app offering AI-powered conversion rate optimization tools. Varient operates as a Shopify app and accesses certain data through Shopify's APIs to provide optimization services for e-commerce stores.

2. Data Minimization

We are committed to processing only the minimum personal data required to provide our services. We limit our data collection and processing to what is necessary for:

  • Analyzing product information to provide optimization recommendations
  • Operating and maintaining the app functionality
  • Communicating with merchants about their account and service updates

3. Information We Collect

When using Varient, we collect information through two primary sources:

3.1 Information Collected Through Shopify APIs

We access the following data through Shopify's APIs when you install and use our app:

  • Shop information (shop name, domain, email, currency, timezone)
  • Product information (titles, descriptions, images, pricing, inventory status)
  • Product metadata (SEO fields, visibility settings, product variants)
  • Installation and authentication tokens required for app functionality

3.2 Information We Collect Independently

We may also collect account registration details, support communications, usage analytics, and technical information necessary for app functionality.

4. How We Use Your Information

We use your information strictly for the following purposes:

  • Deliver the core optimization services offered through the app
  • Generate AI-powered suggestions and insights based on your product data
  • Process and analyze product images, titles, and descriptions for optimization recommendations
  • Maintain and improve the platform functionality and user experience
  • Communicate with you regarding your account, service updates, or support requests
  • Ensure security and detect and prevent abuse of the platform
  • Comply with legal obligations and respond to lawful requests

Important: We do not use your data for marketing purposes without explicit consent, nor do we sell your personal information to third parties.

5. Information Sharing and Third-Party Services

We may share your information in the following circumstances:

5.1 Third-Party Service Providers

We work with trusted third-party service providers to deliver our services, including:

  • Cloud hosting and infrastructure providers for data storage and processing
  • AI/ML services for product analysis and optimization recommendations
  • Analytics providers for privacy-friendly usage tracking
  • Authentication and security services
  • Customer support and communication tools

All third-party providers are required to maintain appropriate data protection standards and use your information only for the specific services they provide to us.

5.2 Legal Requirements

We may disclose your information when required by law, to protect rights and safety, prevent fraud, or in connection with business transfers.

5.3 No Sale of Personal Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

6. Data Retention

We retain data only for as long as necessary to provide our services or comply with legal obligations. When you uninstall the app or request data deletion, we will remove your information in accordance with applicable laws and our operational requirements.

7. Customer Consent and Data Processing

We respect customer consent decisions and process data in accordance with applicable privacy laws:

  • We only process customer data when necessary for providing our optimization services
  • We respect any consent preferences communicated through Shopify's systems
  • Customers can withdraw consent or request data deletion through their merchant's account
  • We do not use customer data for marketing or advertising purposes

8. Data Security

We implement appropriate technical and organizational security measures to protect your data against unauthorized access, alteration, or destruction. However, no method of transmission over the internet or electronic storage is completely secure.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request access to your personal information we hold
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal information
  • Restriction: Request restriction of processing under certain circumstances
  • Portability: Request transfer of your data to another service provider
  • Objection: Object to processing of your personal information

To exercise your rights, please contact us at [email protected]. We will respond to your request in accordance with applicable laws.

10. Children's Privacy

Our service is not intended for use by individuals under the age of 16. We do not knowingly collect data from children. If we learn that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the date and may notify users of significant changes. We encourage you to review this policy periodically.

12. Contact Information

For any questions about this Privacy Policy, our data practices, or to exercise your privacy rights, please contact us:

  • Email: [email protected]
  • Company: Hipwerk GmbH (CHE-219.373.846)
  • Location: Zürich, Switzerland

Last Updated: July 31, 2025