Zizr Shopify App Privacy Policy
Effective date: 21 May 2026
Last updated: 21 May 2026
Applies to: Merchants installing the Zizr Shopify app and the storefront end-customers ("Shoppers") of those merchants.
Plain-English summary (non-binding):
Zizr helps Shoppers pick the right size and helps stores understand fit and returns. We access order, product, and limited customer data from Shopify to run the app, acting as the merchant's data processor. We also offer Shoppers an optional Zizr ID account, where the Shopper can save preferences and reuse a shared fit history across stores that have installed Zizr. When you uninstall the app, or when we receive Shopify's redaction webhooks, we delete or de-identify your shop-scoped personal data. We may keep aggregated or de-identified analytics to improve our algorithms. In the European Economic Area and the United Kingdom, certain features require consent. In California and other U.S. states, you may opt out of "selling" or "sharing" and targeted advertising.
Notice: This policy is informational and does not constitute legal advice. Merchants remain responsible for their own privacy notices toward Shoppers.
Table of Contents
- Who we are and scope
- Our roles: processor and controller
- Data we collect
- How we use data (purposes and legal bases)
- Automated decisions and profiling
- Data retention
- Data sharing and subprocessors
- International transfers
- Security
- Your privacy rights
- CPRA and U.S. state privacy disclosures
- Cookies and SDKs on storefronts
- Children's data
- Merchant responsibilities
- Shopify-required webhooks
- Changes to this policy
- Contact
1. Who we are and scope
Zizr AS ("Zizr", "we", "us"), organisation number 922 796 556, registered at Dronningens gate 38, 7011 Trondheim, Norway, is a Norwegian company established in the European Economic Area (EEA). We provide a Shopify app that delivers personalised sizing recommendations, FitBack (structured post-purchase fit and return feedback), returns analytics, the optional Zizr ID account, and related infrastructure features such as product data normalisation, Findr, and circularity enablement.
This policy explains how we process merchant store data and Shopper personal data obtained via Shopify APIs and storefront integrations when our app is installed on a merchant's store. It also explains how we process Shopper personal data when a Shopper has voluntarily created a Zizr ID account.
2. Our roles: processor and controller
We act in different capacities depending on the processing activity. The distinction matters for your legal rights and for how requests are handled.
a) Processor for the merchant (default mode). When a Shopper is not logged into a Zizr ID account, we process Shopify-sourced personal data (including orders, products, and limited customer data) on behalf of the merchant to deliver the contracted app features. In this capacity the merchant is the controller and we follow the merchant's documented instructions. We do not combine identifiable Shopper data across merchants in this default mode. The terms of this relationship are set out in our Data Processing Agreement (DPA), available at https://www.zizr.com/legal/dpa.
b) Independent controller for Zizr ID accounts (opt-in mode). Zizr ID is an optional account that a Shopper can voluntarily create directly with Zizr. When the Shopper logs into Zizr ID at any merchant that has installed the Zizr app, Zizr uses the Shopper's cross-store purchase and fit history under that Zizr ID to provide more accurate size recommendations in that store. The data shared into the Zizr ID profile includes the Shopper's email address and Shopify customer identifier (used as the match key across stores), products purchased, prices, dates of purchase, and return status.
For the Zizr ID account and the cross-store use of Zizr ID data, Zizr is the controller with the Shopper's consent and contract as the legal basis under Article 6(1)(a) and 6(1)(b) GDPR. Merchants are not controllers for this cross-store processing. The Zizr ID service is governed by separate Zizr ID Terms of Use and a Zizr ID Privacy Notice that the Shopper accepts when creating the account.
c) Independent controller for limited operational purposes. We also act as an independent controller for the following narrow purposes:
- Security and fraud prevention, including detecting abuse of the service.
- Product analytics and algorithm improvement using pseudonymised or aggregated data with appropriate safeguards.
- Benchmarking and infrastructure research and development using de-identified data that does not reasonably identify a specific person or store.
Summary of cross-merchant data use. In default mode (no Zizr ID), each merchant's Customer Personal Data is kept logically segregated and is used only to serve that merchant. Cross-merchant use of identifiable Shopper data occurs only where the Shopper has actively created a Zizr ID and is logged in at the merchant they are visiting. In that case, the Shopper has consented to this use under the Zizr ID Terms of Use.
3. Data we collect
We request the minimum Shopify scopes necessary for the contracted features. Depending on which features the merchant enables, we may receive and process:
Order and transaction data. Order identifiers, line items, SKU and product identifiers, brand, model, style, price, taxes, discounts, currency, quantity, fulfilment and return status, and timestamps.
Customer data from Shopify (limited). Name, email (or hashed email), phone, shipping and billing addresses (country and region level where required), Shopify customer identifier.
Product and size data. Product titles and descriptions, variant and size attributes, images and URLs, category metadata.
Behavioural and feature signals (FitBack and usage). Size recommendations shown and selected, add-to-bag interactions, return reason codes, fit feedback, widget and app interactions, timestamps, and device and browser metadata. IP addresses are processed transiently to deliver the widget and for security purposes. IP addresses included in traffic logs are retained for up to 30 days for security purposes and then deleted.
Merchant and store data. Store name, domain, contact details, app configuration, subscription and billing status.
Zizr ID account data (only if the Shopper has created an account). Account credentials (managed by our identity provider), declared fit preferences (such as preferred sizes per brand or category), and a cross-store history derived from the Shopper's purchases at merchants where they have logged in with their Zizr ID. The cross-store history includes the Shopper's email and Shopify customer identifier (used as match keys across stores), products purchased, prices, dates of purchase, and return status. Cross-store data is collected and combined only after the Shopper has actively created the Zizr ID account and is logged in.
Sensitive categories. We do not seek special categories of data as defined under GDPR Article 9 (such as health data, religious beliefs, or biometric data used for unique identification). If such data are inadvertently provided (for example in free-text notes), we will delete or minimise it.
4. How we use data (purposes and legal bases)
Legal bases below apply primarily to the EEA and the United Kingdom under the GDPR and UK GDPR. Other regions follow equivalent grounds under local law.
| Purpose | Examples | Legal basis |
|---|---|---|
| Core app delivery (Processor for merchant) | Generating size recommendations, showing product and size alternatives, returns analytics | Performance of contract between the merchant and the Shopper; legitimate interests of merchant and Shoppers in accurate sizing |
| Zizr ID account (Controller) | Creating and operating the Zizr ID account, saving fit preferences, providing cross-store size recommendations to logged-in Zizr ID holders | Contract with the Shopper (Article 6(1)(b) GDPR) for the account itself; consent (Article 6(1)(a) GDPR) for cross-store data combination |
| Support and operations | Troubleshooting, billing, service communications | Performance of contract; legitimate interests |
| Security and abuse prevention | Detect, investigate, and prevent fraud, abuse, or misuse | Legitimate interests; legal obligation where applicable |
| Product improvement (de-identified or aggregated) | Train and evaluate models, create category and SKU fit profiles, improve catalogue standardisation | Legitimate interests, with pseudonymisation, aggregation, and safeguards |
| Benchmarking and infrastructure research (de-identified) | Size and fit insights by category or brand, without identifying individuals or stores | Legitimate interests, with de-identification |
| Marketing modules (optional, merchant-enabled) | Size-aware segments, lifecycle messaging, ad integrations when the merchant enables them | Consent where required in the EEA and the UK; opt-out rights under U.S. state laws |
For optional marketing features, merchants must ensure valid consent in the EEA and the UK and must honour opt-out choices in U.S. states. Zizr provides settings to respect these signals.
5. Automated decisions and profiling
We use automated processing and profiling to:
- Generate personalised size recommendations and product relevance scores, at the SKU level where supported.
- Build cross-store fit profiles for Shoppers who have voluntarily created a Zizr ID account. These profiles are linked to the Shopper's Zizr ID and may be used across merchants where the Shopper has logged in. The Shopper consents to this cross-store use when accepting the Zizr ID Terms of Use.
These processes do not constitute automated decision-making within the meaning of Article 22 GDPR and do not produce legal or similarly significant effects. Size recommendations are advisory only, and the Shopper always retains full discretion to select a different size. Zizr ID profiles do not influence pricing, access to services, or any other decision with legal or significant personal effect.
Where required, you may object to profiling or request human review by contacting us at privacy@zizr.com, or by deleting your Zizr ID account at any time.
6. Data retention
We retain personal data only as long as necessary for the purposes above, then delete or irreversibly de-identify it.
While installed. We keep shop-scoped personal data for the duration of the merchant's subscription.
Uninstall or shop redaction. When we receive Shopify's shop/redact webhook after app uninstall, we delete or anonymise shop-scoped personal data within 30 days.
Customer redaction. When we receive customers/redact, we delete the relevant Shopper's merchant-scoped personal data within 30 days. Note that this webhook does not automatically delete the Shopper's Zizr ID account itself, since that is a separate Shopper-to-Zizr relationship. To delete a Zizr ID account, the Shopper contacts Zizr directly at privacy@zizr.com or deletes the account in Zizr ID self-service.
Zizr ID account. Zizr ID account data is retained for as long as the Shopper maintains the account. The Shopper may delete their Zizr ID at any time, in which case we delete or anonymise the account data within 30 days, subject to statutory retention obligations.
Event and log data. Security logs and operational telemetry: typically 90 to 180 days, unless needed to investigate incidents.
Model artefacts and analytics. We may retain aggregated or de-identified outputs (from which re-identification is not reasonably possible) for longer, to ensure model stability, benchmarking, and auditability.
Statutory retention obligations. Notwithstanding the above, we may retain certain transaction and billing records for longer periods where required by applicable law. Norwegian accounting legislation (bokføringsloven) requires retention of accounting records for a minimum of five years. During this period, such records are stored securely and are not used for any purpose other than compliance with the relevant legal obligation.
Default retention targets (illustrative):
| Dataset | Typical retention |
|---|---|
| Identifiable order and return records (per shop) | Lifetime of installation, plus up to 30 days after shop/redact |
| Per-Shopper data (Shopify customer-scoped) | Until deleted via customers/redact or per merchant request |
| Raw event logs | 90 to 180 days |
| Zizr ID account and cross-store profile | Lifetime of Shopper account, plus up to 30 days after deletion |
| De-identified model features and aggregates | As needed for statistical purposes (no re-identification) |
| Accounting and billing records | Minimum five years (Norwegian bokføringsloven) |
7. Data sharing and subprocessors
We share personal data only with:
Subprocessors and service providers. Cloud hosting, databases, analytics, logging and monitoring, support tools, email providers, and similar vendors. These vendors act under contract and follow security requirements that are substantially equivalent to those in our DPA.
The merchant (controller). Reports, dashboards, and data needed to operate the app.
Authorities. Where legally required.
We do not sell personal information. If an optional marketing integration could be considered "sharing" for cross-context behavioural advertising under CPRA or similar U.S. state laws, we provide the required opt-out mechanisms and honour Global Privacy Control (GPC) signals.
Current subprocessors
| Provider | Location of processing | Purpose |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd) | France (France Central) | Cloud infrastructure, data storage, Azure OpenAI Service for large language model processing |
| Cloudflare, Inc. | Frankfurt, Germany (network) | Network delivery, DDoS protection, web application firewall |
| Datadog, Inc. | Frankfurt, Germany | Application logging, monitoring, error tracking |
| ClickHouse, Inc. (planned) | Frankfurt, Germany | Analytics database |
| Postmark (ActiveCampaign LLC) | United States, with EU SCCs | Transactional email delivery |
| HubSpot, Inc. | United States, with EU SCCs | Customer support, CRM, merchant communications |
| Google LLC (Google Cloud, Vertex AI / Gemini) | United States, with EU SCCs | Large language model processing for product data parsing |
OpenAI inference performed via Azure OpenAI Service is processed within our Microsoft Azure tenant and does not constitute a separate transfer to OpenAI Inc.
This subprocessor list is updated periodically. Material additions or replacements will be communicated to merchants via in-app notice or email to merchant admins with a minimum of 15 days' notice, during which a merchant may object on reasonable data protection grounds in accordance with our DPA.
Business transfers
If Zizr AS is involved in a merger, acquisition, asset sale, or similar corporate transaction, personal data may be transferred to the acquiring entity as part of that transaction. We will provide notice via in-app notification or email to merchant admins if personal data becomes subject to a materially different privacy policy as a result.
8. International transfers
Our primary infrastructure is hosted within the European Economic Area. Our cloud, network, logging, and analytics subprocessors process personal data inside the EEA.
For the subprocessors that process personal data outside the EEA (Postmark, HubSpot, Google), we rely on the European Commission's Standard Contractual Clauses (Module 2 or Module 3 as applicable), supplemented by:
- Encryption in transit and at rest.
- Pseudonymisation of identifiers where feasible.
- Transfer impact assessments documented in our internal records.
- Contractual obligations on subprocessors that are substantially equivalent to those we owe to merchants.
For transfers to the United Kingdom, we use the UK International Data Transfer Addendum or the UK IDTA where applicable. Further details are available in our DPA.
9. Security
We implement administrative, technical, and organisational safeguards, including:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Network segregation and least-privilege access.
- Pseudonymisation, such as hashing of identifiers, where feasible.
- Vulnerability management, logging, and monitoring.
- Employee confidentiality obligations and recurring data protection and security training.
- Vendor due diligence and contractual controls on all subprocessors.
No method is one hundred percent secure. We maintain and improve controls consistent with industry practices and the requirements of Shopify's protected customer data programme.
Personal data breach notification
In the event of a personal data breach affecting personal data we process on behalf of a merchant, we will notify the affected merchant without undue delay, and in any case within 72 hours after becoming aware of the breach, and provide the information reasonably necessary for the merchant to comply with their own notification obligations under applicable law (for example GDPR Articles 33 and 34). We will assist the merchant in mitigating the impact of the breach and in fulfilling any obligations to notify supervisory authorities or affected individuals. Our Incident Response Procedure (Annex to the DPA) sets out the timelines and content of breach notifications.
10. Your privacy rights
Depending on your location and your relationship with Zizr, you may have the right to access, correct, delete, object to or restrict processing, port your data, withdraw consent, and not be subject to certain automated decisions. How you exercise these rights depends on your relationship with Zizr.
If you are a Shopper without a Zizr ID. The merchant is the controller of your personal data. Direct rights requests to the merchant, who can forward them to us via Shopify's privacy webhooks (customers/data_request and customers/redact). We will respond within the timelines required by applicable law, and in any case within 30 days of receiving the validated request from the merchant.
If you are a Shopper with a Zizr ID account. You may submit rights requests directly to Zizr at privacy@zizr.com. Zizr is the controller of your Zizr ID account data and will respond within the timelines required by applicable law.
If you are a merchant operating a Shopify store using Zizr. You may submit rights requests directly to Zizr at privacy@zizr.com.
Direct requests to Zizr. Where Zizr acts as an independent controller (for example for security, algorithm improvement, or Zizr ID accounts), you may contact us directly at privacy@zizr.com.
If you are in the EEA, the UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority. In Norway, the supervisory authority is Datatilsynet (datatilsynet.no). If you are in another country, you may contact your local authority.
11. CPRA and U.S. state privacy disclosures
For residents of California and other U.S. states with comprehensive privacy laws (including but not limited to Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana):
- We process the categories of personal information described in section 3 for the purposes in section 4.
- We do not sell personal information for money.
- If an optional feature constitutes "sharing" for cross-context behavioural advertising under CPRA or similar concepts under other state laws, you may opt out by emailing privacy@zizr.com with the subject line "Privacy Opt-Out", or via the data sharing opt-out page on the merchant's storefront where available. We honour Global Privacy Control (GPC) signals.
- You may request access, deletion, correction, and to limit the use and disclosure of sensitive personal information (if any). See section 10 for how to submit requests.
- We do not knowingly collect or process personal information of consumers under 16 without the legally required consent.
12. Cookies and SDKs on storefronts
If the merchant enables Zizr widgets or SDKs on the storefront, we may use the following categories of cookies, local storage, and similar technologies on the Shopper's device:
Strictly necessary. Required for the widget to function, including session management, fit profile persistence within the same merchant context, and preference storage. These do not require consent under EEA and UK rules.
Analytics (optional). Used to measure widget performance and improve recommendations, only if the merchant enables this feature and consent has been obtained where required.
Marketing (optional). Used for audience segmentation and personalised messaging, only if the merchant enables marketing features and consent has been obtained where required.
Specific details about cookie names, providers, and durations are made available to merchants and Shoppers through the merchant's cookie banner or consent management platform.
In the EEA and the UK, merchants must present a compliant consent mechanism before any non-essential cookies fire. We provide configuration options to respect consent frameworks and regional requirements, and we integrate with Shopify's Customer Privacy API where supported.
13. Children's data
Our services are not directed to children under 13, or the applicable local age threshold where higher (for example 16 in some EEA member states). We process purchaser or guardian data. If we learn that we have inadvertently collected children's personal data, we will delete it.
14. Merchant responsibilities
As a merchant installing Zizr, you remain responsible for the following:
- Providing a clear storefront privacy notice that explains the use of Zizr and the data shared with us.
- Obtaining and managing consents and opt-outs where required by applicable law, including EEA and UK cookie consent and U.S. state-level opt-outs.
- Configuring Zizr features in line with your legal basis. For example, only enabling optional marketing modules where you have valid consent or opt-out controls.
- Notifying us of data subject requests or legal holds where relevant.
- Reviewing and accepting our Data Processing Agreement as part of installing the app.
15. Shopify-required webhooks
We subscribe to and honour the following Shopify privacy webhooks:
customers/data_requestto provide Shopper data to the merchant within 30 days.customers/redactto delete a single Shopper's personal data within 30 days.shop/redactto delete shop-scoped personal data within 30 days after uninstall.
We operate to these timelines or faster where required by law. We also periodically delete test stores and development data.
16. Changes to this policy
We may update this policy to reflect operational, legal, or regulatory changes. We will post updates here with a revised "Last updated" date. Material changes will be communicated via in-app notice or email to merchant admins at least 15 days before they take effect.
17. Contact
Zizr AS
Dronningens gate 38
7011 Trondheim
Norway
Organisation number: 922 796 556
General contact: contact@zizr.com
Privacy contact: privacy@zizr.com
Privacy Lead: Petter Hellevik, CEO
Data Protection Officer. Zizr has not formally appointed a Data Protection Officer under Article 37 GDPR, as our current core activities do not require one. Petter Hellevik serves as our internal Privacy Lead and is the primary contact for privacy and data protection matters.
Supervisory authority. If you are in the EEA, the UK, or Switzerland, you may complain to your local data protection authority. In Norway, the supervisory authority is Datatilsynet (datatilsynet.no).