Skip to content
WS Themes
WS Cookie Consent

Privacy policy

How WS Themes processes information when merchants use WS Cookie Consent and visitors interact with the consent interface.

Effective: August 4, 2026 · support@wsthemes.com

1. Scope and roles

This policy applies to the Shopify app, embedded merchant interface, theme app extension, app-proxy endpoints, support services, and related product website. WS Themes may act as an independent controller for account, security, billing, and support information, or as a processor/service provider for data handled on a merchant's behalf.

2. Information we may process

Merchant and shop information

  • Shop domain, Shopify identifiers, installation state, scopes, app configuration, plan state, and technical sessions.
  • Banner content, categories, cookie declarations, policy URLs, integration settings, scan requests, and merchant configuration.
  • Support correspondence and contact details supplied for assistance.

Storefront consent information

  • A random browser token submitted for server-side hashing; the raw token is not intended to remain in the consent record.
  • A pseudonymous hash, random consent ID, selected categories, action, policy version, timestamps, source, language, and broad region.
  • The consent proof is designed not to contain a visitor name, email, Shopify customer ID, or IP address.

Technical information

  • Errors, security events, request metadata, and performance diagnostics needed to operate the service.
  • Public storefront response cookies and script URLs found during merchant-initiated scans.

3. Purposes

Information is used to provide and secure the app, authenticate merchants, save configuration, display consent controls, synchronize privacy signals, record choices, run scans, provide support, maintain reliability, comply with obligations, and improve the product.

4. Legal bases

Where applicable, processing may rely on contract, legitimate interests, legal obligations, or consent. Merchants remain responsible for determining lawful bases and notices for their storefront technologies.

5. Service providers

Information may be processed by infrastructure, database, monitoring, email, and support providers, as well as Shopify where needed for app functionality.

6. Retention

Merchant configuration is generally retained while installed and for a limited operational period afterward. Consent records follow merchant retention settings, subject to backups, security, disputes, and legal requirements.

7. Uninstallation and deletion

The production app must verify and process Shopify's mandatory privacy webhooks, including shop redaction, to remove or anonymize shop-associated data. Merchants can also use the documented deletion request process.

8. International transfers

Information may be processed outside the merchant's or visitor's country. Appropriate safeguards should be used where required.

9. Security

Controls are designed to include signed request verification, authenticated APIs, shop-level boundaries, pseudonymous identifiers, encrypted transport, restricted URLs, scanner protections, access controls, backups, monitoring, and incident response. No system can be guaranteed completely secure.

10. Rights

Depending on location, individuals may have rights to access, correct, delete, restrict, object, or receive information. Storefront visitors should normally contact the merchant operating the store. Merchants may contact WS Themes for assistance.

11. Changes

This policy may be updated for product, provider, legal, or operational changes. The effective date will be revised when updated.

12. Contact

Contact support@wsthemes.com. Before launch, add the legal entity name, registered address, privacy contact, and any required representative or DPO information.