FrameTap Privacy Policy
Effective Date: August 8, 2026 Last Updated: August 8, 2026
This Privacy Policy describes how FOP Raksha Yaroslav (“FrameTap,” “we,” “us,” or “our”) collects, uses, shares, and protects information in connection with the FrameTap Shopify application, related web dashboards, APIs, and published or previewed mobile shopping experiences (collectively, the “Service”).
By installing or using the Service, you acknowledge this Privacy Policy. If you do not agree, do not install or use the Service. Our Terms of Service govern use of the Service and should be read together with this Policy.
Contact for privacy matters: support@frametap.app General support: support@frametap.app Website: https://frametap.app/ Postal address: Ukraine, Zaporizhzhia, Ladozka 34/11
1. Who We Are and What This Policy Covers
FrameTap is a visual drag-and-drop builder that enables Shopify merchants (“Merchants,” “you”) to design, customize, preview, and publish a mobile shopping app experience for their store. Merchants interact with FrameTap primarily through the Shopify Admin (embedded app) and related APIs. Shoppers who use a Merchant’s mobile experience (“End Customers”) may interact with data pathways operated by FrameTap on the Merchant’s behalf.
This Policy covers:
- Information about Merchants and their staff who install and use FrameTap
- Information obtained from Shopify APIs and webhooks for a Merchant’s store
- Data generated through the visual builder (themes, layouts, settings)
- Information collected from End Customers through mobile apps or previews that use FrameTap infrastructure
- Analytics, logs, cookies, and similar technologies we use
This Policy does not replace:
- Shopify’s own privacy policy and terms
- The Merchant’s privacy notice to their End Customers
- Privacy policies of optional third-party integrations the Merchant chooses to connect (for example, review platforms)
2. Roles and Relationships (Controller vs Processor)
Privacy law often distinguishes who determines the purposes of processing (controller) from who processes data on another’s instructions (processor).
2.1 FrameTap as Controller
We act as an independent controller for:
- Merchant account and authentication data we receive through Shopify installation and sessions (for example, shop domain, staff identity fields Shopify provides, locale, and session credentials)
- Subscription and billing status metadata we need to operate entitlements (billing charges themselves are processed by Shopify; see Section 4)
- Our own product, security, fraud-prevention, and Service-usage analytics that we generate to improve, secure, and bill for FrameTap
- Communications we send as FrameTap (support responses, Service notices)
2.2 FrameTap as Processor
We act as a processor (or service provider) on the Merchant’s behalf for:
- Catalog and store configuration data accessed from Shopify to power search, previews, builder product references, and related features (products, collections, media/files metadata, shop currency, and selected product metafields)
- Builder content the Merchant creates (page structures, design tokens, navigation, icons, search and review display settings) when processed solely to provide the Service
- End Customer data processed through FrameTap-powered mobile experiences (for example, analytics events and push notification device tokens) so that Merchants can operate and measure their mobile app
Where we process as a processor, the Merchant is the controller of that data (including End Customer data for the Merchant’s commerce relationship). Merchants decide what to publish, what notifications to send, and how to present their store. Additional processing terms are set out in the Terms of Service (Processing Annex).
3. Information We Collect from Merchants and Staff Users
Depending on how you install and use the Service, we may process:
3.1 Shopify account and session information
When you install FrameTap or authorize access via Shopify OAuth / session tokens, Shopify may provide us with information such as:
- Shop domain / store identifier
- Access tokens and granted API scopes
- Staff user identifiers and, where Shopify supplies them, name, email, account-owner flag, collaborator status, locale, and email-verification status
We use this to authenticate the embedded app, associate data with the correct store, and provide support.
3.2 Billing and subscription information
Billing is handled through the Shopify App Billing API. We store subscription-related metadata necessary to enforce plans and entitlements (for example: plan identifier, status, Shopify subscription identifier, trial and period dates). Payment card details are processed by Shopify, not by FrameTap.
3.3 Builder interactions and support
We may collect:
- Content and configuration you create or upload in the builder (themes, pages, blocks, navigation, colors, typography, custom icons, search settings, recommendation layouts)
- Feature usage within the dashboard (for example, publish actions, plan changes)
- Communications you send to us (support emails, feedback)
3.4 Technical and log data
Like most online services, we process technical logs such as IP address, browser or client type, timestamps, request URLs, error traces, and security events associated with Merchant sessions and API calls, for security, reliability, and troubleshooting.
4. Shopify Store and API Data We Access
FrameTap integrates with Shopify using OAuth and the Admin APIs under permissions you grant during installation (and any later scope updates). As of the current product implementation, those permissions relate primarily to products, collections, files, and themes-related scopes declared for the app.
4.1 Categories of Shopify data we may access
| Category | Examples of data used | Typical purpose |
|---|---|---|
| Products | Titles, handles, descriptions, status, vendor, type, tags, images/media URLs, options/variants, prices, SKUs, inventory availability signals, collection membership | Catalog sync for mobile search, previews, builder product links, recommendations UI |
| Collections | Title, handle, description, image, product membership | Mobile browsing and search filters |
| Files / media | URLs, alt text, mime type, size; ability to create/upload files via Shopify Files | Merchants upload and display media in the builder; assets remain on Shopify-hosted files where applicable |
| Shop | Currency code (and similar minimal shop settings we require) | Correct pricing display and catalog indexing |
| Product metafields | Selected namespaces used for display or review integrations | Optional reviews badges/summaries and similar product presentation |
| Billing objects | App subscription status via Shopify Billing | Plan enforcement |
4.2 What we generally do not access via Shopify Admin API today
As of the current Service implementation, FrameTap does not request Shopify scopes to read or write Admin order lists or Admin customer profiles. End-customer commerce events that appear in FrameTap analytics are primarily sourced from the mobile experience (see Section 6), not from bulk Shopify Customer/Order Admin exports.
4.3 Webhooks
We receive Shopify webhooks for events such as product and collection changes (to keep catalog search indices current), billing subscription updates, and app uninstall. Upon uninstall, we erase shop data we store for that installation (see Section 11).
We also subscribe to Shopify’s mandatory privacy compliance webhooks:
customers/data_request— acknowledge and locate any End Customer–related data FrameTap stores (primarily mobile analytics) so it can be provided to the Merchantcustomers/redact— delete End Customer–related analytics we can match to the requestshop/redact— erase remaining shop data after uninstall (Shopify typically sends this about 48 hours after uninstall)
Merchants and End Customers (via their Merchant) may also submit requests to support@frametap.app, and we will assist as described in Section 13.
5. Data Generated Through the Visual Builder
When Merchants use the drag-and-drop builder, we store Builder Content, which may include:
- Theme and page structure (layout trees, blocks, components)
- Navigation headers/footers and link configurations (including references to Shopify product or collection IDs)
- Text and color collections (design tokens / theme variables)
- Saved components and custom SVG icons
- Search/filter configuration and related settings
- Theme status (draft vs published) and related metadata
Builder Content may reference Shopify assets (for example, product IDs or Shopify CDN file URLs) and may temporarily include product preview payloads in the editor. Full product catalogs are primarily sourced live from Shopify APIs and/or search indices rather than as a permanent replacement for the Merchant’s Shopify admin catalog.
FrameTap may provide installable starter themes and template assets authored by FrameTap. Those packages may include template media hosted on FrameTap infrastructure (for example, Cloudinary) and are separate from a Merchant’s own store catalog. This Policy version does not cover a third-party creator marketplace with separate email/password accounts; Merchant access is through Shopify OAuth.
6. Mobile App Data and End-Customer Information
FrameTap-powered mobile shopping experiences may send data to FrameTap’s systems so Merchants can operate search, personalize presentation, send push notifications, and view analytics.
6.1 Analytics and usage events
Mobile clients may transmit first-party analytics events to FrameTap endpoints. Depending on configuration and app version, events may include:
- Pseudonymous or device-local identifiers (for example, anonymous user IDs and session IDs stored on device)
- Device category (for example, iOS, Android, or web)
- App install / open signals and screen views
- Product interaction signals (product identifiers, names, prices as displayed)
- Search queries and suggestion/result interaction events
- Cart and checkout funnel events (for example, add-to-cart, checkout started)
- Purchase completion signals when the checkout flow notifies the app (for example, order identifier, order totals, and line-item summaries)
These events are used to power Merchant-facing analytics dashboards and related Service features. Where we process them solely to provide Merchants with insights about their own app, we do so as a processor. Aggregated or product-improvement uses of Service data may also be processed under our controller role within the limits of applicable law and the Terms.
6.2 Checkout and payment data
Checkout and payment are designed to run through Shopify mechanisms (for example, cart permalinks and Shopify Checkout Sheet Kit). Payment card numbers, full shipping addresses, and similar checkout identity details are processed by Shopify (and the Merchant’s payment settings), not intended to be collected as frame-level stored PCI data by FrameTap.
6.3 Data stored only on device
Certain preferences may remain on the End Customer’s device (for example, recent searches, local analytics identifiers, or theme identifiers in mobile storage) and are not fully under FrameTap’s control once stored on device.
6.4 Merchant responsibility for End Customer notices
Merchants are responsible for providing End Customers with a privacy notice that accurately describes mobile analytics, push notifications, cookies/trackers (if any), and sales/sharing (if applicable), and for obtaining any required consents in their jurisdictions. FrameTap provides infrastructure; Merchants control storefront content, offers, and notification content.
7. Analytics, Logs, Cookies, and Similar Technologies
7.1 Merchant dashboard (Shopify embedded app)
The Service runs primarily as a Shopify embedded application. Authentication and session management rely on Shopify’s platform and FrameTap session storage. The browser environment may use:
- Cookies or similar storage set by Shopify’s ecosystem for embedded app authentication
- First-party browser storage used by the builder for temporary editor state (for example, clipboard contents in
sessionStorage)
7.2 Mobile identifiers
Mobile experiences may store anonymous session/user identifiers and similar values in on-device storage (for example, AsyncStorage) to support analytics continuity and app behavior.
7.3 Marketing pixels and advertising cookies
As of the current Service implementation, FrameTap does not integrate third-party marketing analytics or advertising pixels (for example, Google Analytics, Meta Pixel, or Segment) into the Service. If that changes, we will update this Section and implement any required consent mechanisms.
7.4 Server logs and security monitoring
We retain application and infrastructure logs for security, debugging, and operational integrity. Log retention is described in Section 11.
7.5 Fonts and static asset delivery
The builder may load font catalogs or assets via third-party infrastructure (for example, Google Fonts API). Requests to those services may technically expose IP address and request metadata to the provider under their policies.
8. Push Notifications
On eligible plans, Merchants may send push notifications to End Customers who use the mobile experience.
8.1 Device tokens
When an End Customer opts in (or as permitted by platform rules and the Merchant’s configuration), the mobile client may register a push token (for example, an Expo push token) with FrameTap, associated with the Merchant’s shop and device type.
8.2 Notification content and delivery
Merchants compose notification content. FrameTap stores notification records as needed to deliver, rate-limit by plan, and report delivery/open metrics. Delivery may use Expo Push (or successor mobile push infrastructure).
8.3 Merchant and platform obligations
Merchants must comply with applicable marketing, spam, and electronic communications laws, Apple/Google platform rules, and must honor End Customer opt-out/unsubscribe expectations. FrameTap may suspend push features for abuse.
9. How We Use Information and Legal Bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on one or more of the following bases:
| Purpose | Examples | Typical basis (controller activities) |
|---|---|---|
| Provide and secure the Service | Authentication, builder storage, API operations, troubleshooting | Performance of a contract; legitimate interests (security) |
| Billing and entitlements | Plan status, trial eligibility, feature gates | Contract; legal obligations (tax/accounting where applicable) |
| Improve the Service | Aggregated usage patterns, reliability metrics | Legitimate interests; consent where required |
| Communications | Service announcements, support replies | Contract; legitimate interests; consent for marketing if applicable |
| Legal compliance | Respond to lawful requests, enforce Terms | Legal obligation; legitimate interests |
When we act as a processor, we process Personal Data on the Merchant’s documented instructions (including the Merchant’s configuration of the app, publish actions, and notification sends), the Terms, and applicable law.
We do not sell Personal Data for money. Whether certain analytics or service-improvement practices constitute a “sale” or “share” under California law is addressed in Section 13.
10. Sharing, Third Parties, and Subprocessors
We share information only as needed to operate FrameTap, comply with law, or with appropriate authorization.
10.1 Categories of recipients
| Recipient | Role | Data typically involved |
|---|---|---|
| Shopify Inc. and affiliates | Commerce platform, OAuth, Admin API, Files hosting, Billing, Checkout | Shop, products/collections/files as authorized; billing; checkout |
| Algolia (or successor search infrastructure) | Product/collection search indices for mobile storefront search | Catalog records (titles, handles, images, prices, tags, collection links, derived search terms) |
| Expo / Expo Push (or successor) | Mobile runtime tooling and push delivery | Device push tokens; push payload metadata as required for delivery |
| Cloudinary | Hosting of FrameTap’s own static / theme-library media | FrameTap template and marketing assets only. Merchant-uploaded media is stored in Shopify Files, not Cloudinary |
| Google Fonts API | Font catalog for builder design features | Technical request metadata |
| Optional review providers (Merchant-configured), e.g. Judge.me, Yotpo, Okendo, Loox | Product rating summaries for display | Merchant API credentials (stored encrypted); product rating/count summaries |
| Render | Application hosting and managed PostgreSQL database | Merchant Service data, Builder Content, analytics events, push tokens, and related operational data. Database is hosted in Frankfurt, Germany (EU) |
| Professional advisors / authorities | Legal, accounting, regulators, courts | As legally required |
FrameTap does not currently use a third-party transactional email provider. Privacy and support correspondence are handled at support@frametap.app.
10.2 Merchant-directed disclosures
Data may leave FrameTap systems when Merchants:
- Publish content visible to End Customers
- Connect optional third-party tools
- Export or copy configurations outside FrameTap
10.3 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, or asset sale, Personal Data may be transferred subject to appropriate confidentiality and continuity of protective commitments.
10.4 Subprocessor list updates
When we add or replace a material subprocessor that processes Personal Data for the Service, we will:
- Update the subprocessor list in this Privacy Policy at https://frametap.app/privacy, and
- Update the “Last Updated” date (and, where practical, note the change in the Shopify app).
If you object to a material new subprocessor, you may terminate the Service as described in the Terms. Continuing to use the Service after the updated Policy’s effective date constitutes acceptance of the updated subprocessor list where permitted by law.
11. Storage, Security, Retention, and Deletion
11.1 Security measures
We implement technical and organizational measures appropriate to the nature of the Service, which may include:
- Encryption in transit (TLS) for Service endpoints
- Access controls and authenticated APIs for Merchant admin functions
- Encryption of sensitive third-party credentials (for example, review-platform secrets) at rest
- Least-privilege operational practices
No method of transmission or storage is completely secure. Merchants must protect their Shopify accounts and staff access.
11.2 Location of processing
FrameTap is operated by FOP Raksha Yaroslav under the laws of Ukraine. The application is hosted on Render. Primary application data is stored in Render Managed PostgreSQL in Frankfurt, Germany (EU). Personal Data may also be processed in other countries where our providers operate (for example, Shopify, Algolia, Expo, and Cloudinary infrastructure), including the United States and other regions (see Section 14).
11.3 Retention principles
We retain information only as long as needed for the purposes described in this Policy, including:
| Data type | Intended retention |
|---|---|
| Shopify sessions / access tokens | While the app remains installed and sessions are active; deleted on uninstall / shop/redact |
| Catalog search indices (Algolia) and related search settings | While installed; re-synced on catalog changes; deleted on uninstall / shop/redact |
| Subscription entitlement records we store | Deleted on uninstall / shop/redact; Shopify may retain billing history under Shopify’s policies |
| Builder themes and related content | Retained while you use the Service; deleted on uninstall / shop/redact |
| Analytics events | Retained to power Merchant analytics dashboards; deleted on uninstall / shop/redact. Individual End Customer–related events may also be deleted on customers/redact when we can match them |
| Push tokens and notification logs | Retained to deliver and measure push; deleted on uninstall / shop/redact |
| Review-integration settings / credentials | Retained while configured; deleted on uninstall / shop/redact |
| Security / application logs | Retained for a limited operational period (typically up to 90 days) unless needed longer for security investigations |
| Backups | Residual copies may remain in encrypted backups for a limited period until overwritten |
11.4 Deletion and Merchant requests
- Uninstall / shop redact: When a Merchant uninstalls the app, we erase shop data we store for that installation — including sessions, subscription entitlement records, catalog search indices, Builder themes, analytics events, push tokens, notification history, and review-integration settings. Shopify also sends a
shop/redactwebhook (typically about 48 hours later); we run the same erasure if any residual data remains. - Merchant data requests / cancellation: Contact support@frametap.app with your shop domain and request type. We will delete or return applicable data within a commercially reasonable period (and within applicable legal timelines), subject to legal holds and residual backup cycles.
- End Customer requests: End Customers should contact the Merchant first for store-related requests. Where FrameTap acts as processor, we handle Shopify
customers/data_requestandcustomers/redactwebhooks and will assist Merchants responding to GDPR/CCPA requests that concern data in our systems.
12. Shopify-Specific Privacy and Data Requirements
FrameTap is a Shopify app and is designed to operate within Shopify’s Partner Program, App Store, and API requirements, including:
- Use of declared OAuth scopes for disclosed purposes
- Secure handling of API credentials and session tokens
- Handling Shopify mandatory privacy compliance webhooks (
customers/data_request,customers/redact,shop/redact) and support requests at support@frametap.app - Billing through Shopify where applicable
- Clear privacy policy URL for the public app listing (https://frametap.app/privacy)
Merchants remain responsible for configuring their stores consistently with Shopify’s policies and for deciding what customer data their own mobile app experience should collect beyond FrameTap defaults.
If Shopify’s requirements change, we may update the Service and this Policy accordingly.
13. Your Privacy Rights and How to Submit Requests
13.1 European Economic Area, UK, and similar jurisdictions (GDPR / UK GDPR)
Where applicable, data subjects may have rights to:
- Access Personal Data
- Rectification
- Erasure
- Restriction of processing
- Portability
- Object to processing based on legitimate interests
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
For Merchant staff data for which FrameTap is controller: contact support@frametap.app with the shop domain and request type.
For End Customer data for which the Merchant is controller: contact the Merchant’s store. Merchants may forward processor assistance requests to support@frametap.app.
We may need to verify identity and request additional details before acting. We will respond within applicable statutory timelines.
13.2 California (CCPA/CPRA) and certain U.S. state laws
California residents may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information, and to non-discrimination for exercising rights.
- We collect categories of personal information described in Sections 3–8 (identifiers, commercial information, internet/activity data, professional information for Merchants, inferences limited to Service analytics).
- We disclose personal information to service providers/subprocessors for business purposes listed above.
- Sale / share: We do not sell personal information for monetary consideration. We do not engage in cross-context behavioral advertising with third-party ad networks on FrameTap surfaces. If that changes, we will provide a “Do Not Sell or Share” mechanism where required.
- Authorized agents may submit requests where the law allows, subject to verification.
Submit CCPA-style requests to support@frametap.app.
13.3 Other regions
Global Merchants may request access or deletion of Merchant account data subject to local law and the Terms. We will honor rights to the extent required.
14. International Data Transfers
FrameTap is based in Ukraine and works with global infrastructure providers. Personal Data may be transferred to and processed in countries other than the country where Merchants or End Customers are located, including countries that may not provide the same level of data protection as the EEA/UK.
Where required by GDPR/UK GDPR, we will use appropriate transfer mechanisms, which may include:
- Standard Contractual Clauses (SCCs) or UK equivalent addenda with subprocessors
- Adequacy decisions where available
- Supplementary measures as appropriate
Merchants that independently configure third-party tools (review platforms, analytics scripts they inject, etc.) are responsible for their own transfer compliance for those tools.
15. Children’s Privacy
FrameTap is a business Service directed to Shopify Merchants and professionals. We do not knowingly collect Personal Data from children under 16 (or under 13 where U.S. COPPA applies to consumer-facing collection) for the purpose of offering FrameTap accounts.
Mobile shopping apps built with FrameTap may sell products of any age rating chosen by Merchants. Merchants must ensure their own apps, marketing, and product catalogs comply with children’s privacy and advertising rules. FrameTap does not knowingly target FrameTap accounts at children.
If you believe a child has provided Personal Data to us in a way that violates this Policy, contact support@frametap.app and we will take appropriate steps.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date will change when we do. Material changes will be communicated by reasonable means (for example, notice in the Shopify app, email where available, or an updated listing on https://frametap.app/). Continued use of the Service after the effective date of changes constitutes acceptance where permitted by law. If changes require consent, we will seek it when legally required.
17. Contact Information
Controller / operator FOP Raksha Yaroslav Trading name / product: FrameTap
Email (privacy): support@frametap.app Email (support): support@frametap.app Website: https://frametap.app/ Address: Ukraine, Zaporizhzhia, Ladozka 34/11
For Shopify-related billing questions, also refer to Shopify’s merchant support and your Shopify Admin billing pages.