Skip to content
Varn by Enstacked
  • How it works
  • Features
  • Pricing
  • Docs
Contact support

Privacy policy

For the Shopify app Varn - Variants & Swatches, published by Enstacked Technologies. Last updated 18 August 2026.

In short

Varn turns product options into swatches. To do that it reads and writes product, theme and file data on the store that installs it, and it saves your swatch settings on your own store as metafields. Varn does not collect names, email addresses, payment details or any other personal information about your shoppers, and it never sells data.

What Varn accesses through the Shopify APIs

When you install Varn, Shopify asks you to approve a fixed set of permissions. Varn requests only what its features need:

  • Products (read and write) — titles, handles, options, option values, variants and product images, so swatches can be built and shown, and so an image can be attached to a variant when you explicitly ask for it.
  • Themes (read) — to check whether the Varn app embed is switched on in a theme. Varn never edits theme code.
  • Files (read and write) — to upload the swatch images you choose, into your own Shopify Files library.
  • Metaobjects (write) — used for app-owned configuration storage.

Varn does not request access to orders, to customers, or to Shopify’s protected customer data.

What Varn stores, and where

  • Your swatch settings stay on your store. Colors, images, styles, groups and backups are written to metafields on your own Shopify store, not to our database. They are still there if you uninstall and reinstall.
  • Uploaded swatch images stay on your store. They go into your own Shopify Files library and are served from your store’s CDN.
  • An installation session. We store your myshopify domain, the access token Shopify issues at install, and the permission scopes you approved, so the app can call the Shopify API on your behalf.
  • Anonymous swatch interaction events on the Advance and Premium plans, described next.

Swatch analytics, and what it does not collect

On the Advance and Premium plans, Varn counts how shoppers interact with swatches so you can see which colors get attention. Each recorded event contains four things and nothing else: whether it was a swatch click or an add to cart, the product handle, the option value that was clicked (for example “Ruby Red”), whether that option was sold out at the time, and the timestamp.

Events carry no shopper identifier of any kind: no name, email, IP address, cookie, device ID, session ID or order. They cannot be traced back to an individual shopper, and they are never combined with another source to try to identify one. On the Free and Grow plans no events are recorded at all, and the tracking code is not sent to your storefront.

The storefront script briefly holds not-yet-sent events in the browser’s sessionStorage, so a dropped network request does not lose a count. That data clears when the tab closes, and it is not a tracking cookie.

How long data is kept

  • Swatch interaction events: 90 days. Older events are deleted automatically.
  • Installation session: until you uninstall. Shopify revokes the access token on uninstall and we delete the stored session.
  • Your settings: for as long as you keep them. They live on your own store, so they are yours to edit or delete at any time from inside the app, and they go with the rest of your app data when Shopify asks us to erase your store.

Deletion and data requests

Varn implements Shopify’s mandatory privacy webhooks. When Shopify sends a customer data request or a customer erasure request, we confirm that we hold no personal data for that customer, because the app never stores any. When Shopify sends a shop erasure request, which follows an uninstall, we delete that store’s stored events and its session.

You can also write to support@enstacked.com to access, correct, export or delete anything we hold about your store, and we will respond within 30 days. Depending on where you live you may also have the right to object to processing, to restrict it, or to complain to your local data protection authority.

Who else sees the data

We do not sell, rent or trade any data, and we do not share it for advertising. The third parties involved are the infrastructure providers that host the app server and its database on our behalf, and the AI vision provider described below, all under contract and only to run the service. There are no advertising networks, no analytics pixels and no data brokers in Varn.

We may disclose data where we are legally required to, or to protect our rights or the safety of others.

Artificial intelligence and machine learning

Most of Varn’s AI setup runs entirely inside the app: it matches your option names against a built-in color dictionary, reads photo file names and alt text, and can read the dominant color out of the image pixels. None of that leaves the app.

One pass does call an outside service. When a photo cannot be placed any other way, Varn sends it to an AI vision provider (currently OpenAI) to find out which color it shows. What is sent is the photo’s public Shopify CDN URL, the option value names you chose and the product title, and nothing else. No shopper data, customer data or order data is ever sent. It only runs when you press one of the AI setup buttons, and each photo the model reads spends one of your plan’s monthly AI usage credits.

We do not use merchant data or customer data, including in aggregated or derived form, to train or develop artificial intelligence or machine learning models, and we do not permit our AI provider to use what we send for training.

Security

All traffic to and from the app runs over TLS. Every request from the Shopify admin is verified with Shopify’s session tokens, every webhook is verified with its HMAC signature, and every storefront request is verified before anything is recorded. Access tokens are stored server-side and are never exposed to the browser.

International transfers

The app is operated from, and its data stored in, the regions used by our hosting provider. Where data is transferred outside your own region, we rely on the safeguards that provider offers. Write to support@enstacked.com if you need the current hosting region in writing.

Children

Varn is a business tool for Shopify merchants. It is not directed at children and we do not knowingly collect data from them.

Changes to this policy

If this policy changes we update the date at the top of this page, and material changes are also announced to merchants who have the app installed.

Contact

Enstacked Technologies
support@enstacked.com

Back to Varn

Enstacked Technologies Powered by Enstacked Technologies

2026 Enstacked Technologies. Varn is not affiliated with or endorsed by Shopify Inc.