The short version
Varn shows color and image swatches on your storefront. To do that, it needs to read your products, their options, and their images from Shopify, and it needs to store the swatch settings you configure. It also counts anonymous swatch clicks and add-to-carts so you can see which colors sell.
Varn has no access to your customers’ personal data. It does not identify, profile, or track individual shoppers and sets no cookies on your storefront.
Who controls the data?
For merchant account data and for anything you submit on varn.enstacked.com, Enstacked is the data controller.
For store and product data that Varn reads from your Shopify store, you are the data controller, and Enstacked is your data processor. We act on your instructions. Installing Varn is the instruction to process this data for the purposes described below.
Contact for any privacy questions, including deletion requests:
- Email: support@enstacked.com
- Postal address: Enstacked Technologies, B-207, Shilp Aaron, Opposite Armieda Complex, Sindhu Bhavan Road, Ahmedabad 380059, Gujarat, India
What does Varn collect?
Store and account data that Varn reads from Shopify
When you install Varn, Shopify grants it access to a defined set of scopes. Varn reads:
- Store profile: shop domain, shop ID, store name, primary contact email, store country, currency, time zone, and Shopify plan. Used to create your Varn account, apply the right billing plan, and contact you about the app.
- Products and variants: product IDs and titles, variant IDs, option names and option values, variant availability, product and variant images including their URLs and alt text, product category or taxonomy, and product data relevant to the agent-readiness score. Used to detect which of your options are color options, to build swatches, to map images to colors, and to score how well an AI shopping agent can read your product.
- Theme information: which theme is published, and whether the Varn app embed is enabled in it. Used to confirm setup worked and to tell you when the embed is off.
- Installation session: your myshopify domain, access token, and the scopes you approved. Used to authenticate every request the app makes to your store, and revoked automatically on uninstall.
Varn stores data against your shop. It does not keep a record of which individual staff member installed or configured the app.
Data Varn writes back to your store
- Swatch configuration metafields on your products, holding the colors, styles, and gallery order you set.
- Product images you upload from inside Varn, which are attached to the product through Shopify’s Files API at full quality.
- Image alt text, when you run the one-click agent-readiness fix. Varn only writes fields you asked it to fix.
- Structured product data rendered on the storefront page so search engines and AI shopping agents can read it.
Varn never writes to your theme’s code files.
Data you enter into Varn
Swatch colors, custom option names, gallery order, style settings, plan preferences, and support messages you send us. Used to run the app and to answer your questions.
Storefront usage data (Advance and Premium plans only)
When your plan includes swatch analytics, Varn counts, per product and per color:
- swatch clicks
- add-to-carts that follow a swatch click
- clicks on a color that was sold out at the time
This is counter data, not visitor data. Each stored event records the shop, the product, the variant option value, and a timestamp. Varn does not record or store an IP address, a device identifier, a customer ID, an email address, a name, or a page URL that could identify a shopper. Two shoppers clicking the same color are indistinguishable in the stored data.
Which stores this applies to. Swatch analytics is included on the Advance and Premium plans; it is not part of Starter or Grow. Every paid plan, Grow, Advance, and Premium, offers a 7 day free trial. During a trial of Advance or Premium, swatch analytics is active for those 7 days, the same as on a paid subscription; a Grow trial does not include it. Starter needs no trial, has no time limit, and Varn collects no storefront usage data from Starter stores at any time.
App admin usage data
Basic diagnostics from the Varn admin interface inside your Shopify dashboard: pages opened, actions taken such as running AI setup or auto-detect, errors and stack traces, and browser and version information. Used to fix bugs and to see which features merchants actually use. Tied to your store, not to a named person.
Server access logs
Like any web service, the servers and content delivery network that run Varn write standard access logs. These can contain an IP address, a user agent, and a timestamp for each request, including requests made by your storefront. They exist to keep the service running and secure and are not used for analytics.
Cookies and browser storage
Two different surfaces, two different answers:
- Your storefront: Varn sets no cookies. It uses sessionStorage, which the browser clears when the tab is closed.
- The Varn admin inside your Shopify dashboard: a session cookie is required to keep you signed in. Live chat on the Support page, run by Crisp, may set its own cookies when you open it.
Why do we collect it, and the legal basis?
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Run the app and display swatches | Store, product, variant, and image data | Performance of a contract |
| Bill you for a paid plan | Store profile, plan, Shopify billing records | Performance of a contract |
| Provide support | Account data, support messages, diagnostics | Performance of a contract |
| Fix bugs and keep the app secure | Diagnostics, error logs, access logs | Legitimate interests |
| Swatch analytics | Anonymous counter data | Not personal data, so no legal basis is required |
| Understand how merchants use the app | Admin usage data, tied to your store | Legitimate interests |
| Send you a marketing email | Your email address | Consent, which you can withdraw at any time |
How the AI setup works, and what it does not do
Varn’s one-click setup fills in colors for you in two distinct ways. Auto-detect reads your product option names against a built-in color dictionary; it is unlimited, free, and available on every plan, with no credits involved, and it never leaves Shopify or touches a third party. AI setup reads the color out of your product photos when a name alone can’t identify it, and it does this by sending the photo to OpenAI’s API for identification.
It is available on every plan, metered by a monthly AI usage credit allowance that scales with your plan (250 to 25,000 credits a month, Starter through Premium); each credit corresponds to one photo sent to OpenAI.
OpenAI is a third-party AI vendor, and product photos are sent to it. When you run AI setup, the product photo is transmitted to OpenAI’s API for color identification, together with the option value names and the product title. OpenAI returns the identified color to Varn, which stores it as part of your swatch configuration. No shopper, customer, or order data is ever sent, and nothing we send is used to train a model.
How long do we keep it?
| Data | Retention |
|---|---|
| Swatch analytics counter data | 90 days from the event, then deleted automatically |
| Store, product and configuration data | For as long as Varn is installed |
| Store, product and configuration data after uninstall | Deleted when Shopify sends the shop/redact request, which arrives 48 hours after uninstall |
| Config backups you created | Deleted with your store data after uninstall |
| Support email correspondence | Kept while your store has Varn installed, deleted with your store data after uninstall |
| Marketing email address | Until you unsubscribe |
| Billing records | As long as Indian tax and accounting law requires |
Uninstalling Varn removes it from your storefront immediately and stops all collection at once. Varn never writes to your theme’s code files, so uninstalling leaves your theme exactly as it was. Stored data is erased on shop/redact, 48 hours later.
Where is data stored and transferred?
Varn’s data is stored in the United States. Enstacked is registered in India, and our team accesses that data from India to run the service and answer support requests.
If you are in the European Economic Area, the United Kingdom, or Switzerland, your data is therefore processed outside your region. We rely on the European Commission’s Standard Contractual Clauses for those transfers, together with the UK Addendum where the UK GDPR applies. This includes the transfer of product photos to OpenAI when you run AI setup.
Security
- All data is transmitted over TLS.
- Data is encrypted at rest by our infrastructure providers.
- Access to production data is limited to the people who need it to run the service, and is authenticated.
- Varn authenticates every request using Shopify’s session tokens and verifies webhook signatures.
- Varn does not store payment card details at any point. All billing runs through Shopify’s Billing API.
No system is perfectly secure. If a breach affects your data, we will notify you and, where required, the relevant supervisory authority, without undue delay and within 72 hours of becoming aware of it.
Your rights, and how to use them
Depending on where you are, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent.
To request deletion, export, or access: email support@enstacked.com from the email address on your Shopify store, and say which store it concerns. We respond within 5 business days and complete the request within 30 days.
To stop all processing: uninstall Varn from your Shopify admin. Collection stops immediately, and your stored data is erased when Shopify’s shop/redact request arrives 48 hours later. If you want it erased sooner, email us, and we will do it on request.
If you are in the EEA or UK, you may also complain to your local data protection authority. If you are in California, you may exercise CCPA and CPRA rights, including the right to know and the right to delete. We do not sell or share personal information as those terms are defined under the CCPA. If you are in Nevada, we do not sell personal information as defined by Nevada law, and you may write to us to confirm that.
Children
Varn is a business tool built for merchants, not a consumer product, and it is not directed at children.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will email the store contact and update the date at the top. Continuing to use Varn after a change means you accept the updated policy.
Contact
Enstacked Technologies Pvt Ltd
B-207, Shilp Aaron, Opposite Armieda Complex, Sindhu Bhavan Road, Ahmedabad 380059, Gujarat, India
support@enstacked.com