Privacy Policy — SizeEcho
Last updated: 25 September 2026
Publish at: https://app.sizeecho.com/privacy (also intended at https://sizeecho.com/privacy when the marketing site is live)
This policy explains what SizeEcho collects and why, in plain language for merchants and, where relevant, their customers.
Who we are
SizeEcho (“we”, “us”) is a Shopify embedded app for apparel merchants. It helps you collect post-fulfillment fit check-ins by sending one event to Klaviyo after a wait you choose; your Klaviyo Flow emails the buyer.
Operator
SizeEcho is operated by Thomas Johansson, a sole proprietorship in Sweden.
- Marketing site: https://sizeecho.com
- App host: https://app.sizeecho.com
- Privacy / support contact: support@sizeecho.com
- Postal address available on request via the same email.
SizeEcho is available to merchants who install the app from the Shopify App Store (or via a Partner install).
Roles under data protection law
- You (the merchant) are typically the controller for personal data about your buyers that SizeEcho processes to run fit check-ins (for example customer email and fit answers tied to an order). You decide why buyers are contacted and how results are used in your store.
- SizeEcho is typically the processor for that buyer-related processing: we process it on your behalf to provide the app features described here. Where GDPR applies, merchants may need a written data processing arrangement under Article 28; contact support@sizeecho.com if you need one.
- SizeEcho is the controller for data we process for our own operations as the app operator — for example messages you send to support, our records of your Shopify Billing subscription identifiers, and technical session data needed to keep the embedded app signed in.
Shopify and Klaviyo remain separate controllers/processors under your agreements with them.
Data we collect
We collect only what is needed to run fit check-ins and the product.
From Shopify (merchant / shop)
- Shop domain and identifiers needed to run the embedded app
- Order and fulfillment metadata needed to schedule check-ins (for example order id, order name, fulfillment timing, line-item titles, variants, SKUs, product/variant ids, quantities)
- Staff session fields Shopify provides for embedded Admin access (for example name and email associated with the logged-in staff session), plus OAuth tokens needed to call Shopify APIs for your shop
- Shopify Billing subscription identifiers for your SizeEcho plan
Related to check-in delivery
- Customer email from the order, used so the check-in can be delivered via Klaviyo (SizeEcho does not replace your email provider; Klaviyo sends the message through your Flow)
- A signed check-in link token. It stops working 90 days after the check-in was scheduled. The database row is not deleted only because the link expired.
- Delivery status fields used to know whether a Klaviyo event was accepted (these may include order identifiers or the check-in URL in status detail text)
Fit answers
- Overall fit summary: too small, true to size, too big, or mixed
- Per line-item answers, including optional reason codes such as Tight, Loose, Short, Long, Narrow, and Wide
- Product/size/order context needed to show results in Overview, Products, and Sizes
Merchant configuration we store
- App settings (for example whether SizeEcho is enabled, check-in delay days, onboarding flags)
- Your Klaviyo private API key when you connect Klaviyo in the app (stored so SizeEcho can create the Fit Check-In event in your Klaviyo account)
Written back to Shopify (in your shop)
When a buyer answers, SizeEcho may also write:
- Order tags related to fit
- A product metafield with aggregated size-fit counts and recent reason/order context
That data then lives in your Shopify store. Removing or anonymizing it in SizeEcho’s database does not automatically erase those Shopify tags or metafields; you control them in Shopify. A product metafield can still show the latest order name until a later check-in replaces it.
We do not store
- Payment card numbers or card credentials. Billing is handled through Shopify Billing.
- Buyer name, phone number, or postal address
- Buyer IP addresses as a stored field in SizeEcho’s database
- SizeEcho-authored analytics cookies in the app code described here
Embedded Shopify authentication uses session records in our database (see above), not a separate marketing cookie system of our own.
Klaviyo event we create
SizeEcho sends a Klaviyo event named “SizeEcho Fit Check-In” (via Klaviyo’s Events API) with properties such as check-in URL, order id/name, shop, and line-item context, and identifies the profile by email (or by order id when email is unavailable). Your Flow then emails the buyer. That is part of the check-in product — not a separate SizeEcho marketing list.
Why we collect it (purposes and legal bases)
| Purpose | Data used | Typical legal basis |
|---|---|---|
| Schedule and trigger post-fulfillment check-ins | Shop domain, order/fulfillment metadata | Merchant: your relationship with buyers / your chosen basis. SizeEcho: processing necessary to perform the contract with you to provide the app. |
| Deliver the check-in through your Klaviyo Flow | Customer email, Klaviyo connection / API key | Same as above |
| Show fit results in the app | Fit answers, reason codes, product/size/order context | Same as above |
| Keep the embedded app signed in and able to call Shopify | Session / OAuth tokens, staff session fields | Necessary to perform the contract with you |
| Bill and enforce plan limits | Shopify Billing subscription ids, completed-response usage | Necessary to perform the contract with you; legitimate interests in preventing abuse |
| Provide support when you contact us | Whatever you send to support@sizeecho.com, plus shop context as needed | Legitimate interests / steps prior to or under contract |
| Comply with Shopify mandatory privacy webhooks and law | Data needed to respond to access or deletion requests | Legal obligation / Shopify platform requirements |
We use this data to operate SizeEcho for your shop — not to sell customer lists.
Where data is hosted and who processes it
| Provider | Role | Location notes |
|---|---|---|
| Hostinger | Hosts the SizeEcho application and its PostgreSQL database on a VPS | Server region used in production: Germany (Düsseldorf area) |
| Shopify | App platform, authorized Admin API access, webhooks, Shopify Billing | Processed under Shopify’s terms; may involve processing outside the EEA under Shopify’s mechanisms |
| Klaviyo | Receives the SizeEcho event; your Flow sends the email | Processed under your Klaviyo agreement; may involve processing outside the EEA under Klaviyo’s mechanisms |
| Let’s Encrypt | TLS certificates for app.sizeecho.com via our reverse proxy | Certificate issuance for the public hostname |
If personal data is transferred outside the EEA/UK, we rely on the safeguards offered by those providers (for example Standard Contractual Clauses) as described in their documentation.
We do not currently operate a separate SizeEcho backup product. Database files live on the same Hostinger VPS volume as the running Postgres service. If we add encrypted backups later, we will update this policy with retention for those backups.
Retention
What SizeEcho does today:
- Check-in links stop working 90 days after the check-in was scheduled. The database row is not deleted only because the link expired.
- While SizeEcho is installed, we keep fit-check records (including fit answers and related order/product context) so Overview analytics work.
- On customers/data_request, we store a JSON export for that shop until the customer’s erasure or the shop’s deletion. A logged-in admin of that shop can read it in Settings → Customer data requests. It is not placed on a public URL.
- On customers/redact, we irreversibly anonymize matching fit-check rows and delete any stored export that contains that customer. We clear email, email source, order name, fit note, Klaviyo delivery detail, and the per-order tag result. We replace the Shopify order id and the check-in token so the old link no longer works. We keep product title, variant, SKU, product id, fit (too small, true to size, or too big), and reason codes (tight, loose, short, long, narrow, wide) so anonymous size statistics can remain. A repeat request does not restore those identifiers.
- On app uninstall, and when Shopify sends shop/redact (about 48 hours after uninstall), we delete that shop’s fit-check records, shop settings (including a saved Klaviyo key), customer-data export files, and Shopify session rows (access tokens and staff name or email on those sessions). A repeat deletes nothing further.
- Shopify tags and metafields written into your shop are retained according to Shopify and your own store practices. SizeEcho does not automatically purge them on customer redact or shop redact.
- Klaviyo retains event and profile data under your Klaviyo account settings. SizeEcho does not delete those Klaviyo records when Shopify sends customers/redact.
- Support email: we intend to keep support correspondence up to two years after a ticket is closed, unless a longer legal hold applies.
There is no separate automatic monthly purge job beyond the rules above. If you need confirmation that a deletion request was completed, email support@sizeecho.com.
Shopify mandatory privacy webhooks
Apps distributed through the Shopify App Store must respond to Shopify’s privacy webhooks. SizeEcho implements HMAC-verified endpoints for:
- customers/data_request — When a customer asks the store for their data, we look up SizeEcho check-ins for the shop named on the signed webhook, using the customer email and the order ids in the payload. We store a JSON export of what we hold for those check-ins: order id and order name, email, fit answers, reason codes, and the check-in URL. We do not add a phone number, because we do not store one. If nothing matches, the export says there are no check-ins. Shopify does not accept the file in the webhook response. The merchant copies it in Settings → Customer data requests and gives it to the customer. The same Shopify request id updates the same file. The file is not written to application logs.
- customers/redact — We anonymize matching fit-check rows and delete the stored export for that customer, as described under Retention. We match email and order ids. We do not store Shopify’s customer id, so a request that contains only a customer id, and no email or order id, cannot be matched to a check-in.
- shop/redact — We delete that shop’s fit-check records, shop settings, customer-data export files, and session rows.
An invalid Shopify HMAC signature is rejected. No export, anonymization, or deletion runs for that request. A privacy policy does not replace these technical requirements.
Your rights (and buyers’ rights)
Merchants
You can view fit answers in the app (Overview, Products, Sizes), disconnect Klaviyo, change plan via Shopify Billing, or uninstall the app.
Depending on applicable law (including GDPR), you may also have rights to access, rectify, erase, restrict, or port personal data SizeEcho holds as controller about you, and to object to certain processing. To exercise those rights, email support@sizeecho.com.
If GDPR applies and you are in the EU/EEA, you may lodge a complaint with your local supervisory authority. In Sweden that is the Swedish Authority for Privacy Protection (IMY) — https://www.imy.se/
Buyers (your customers)
Fit check-in emails are sent by your Klaviyo Flow. Buyers’ rights (access, deletion, marketing opt-out, etc.) are primarily handled under your store policies and your Shopify/Klaviyo setup.
If a buyer contacts SizeEcho directly about fit-answer data we store for your shop, we will work with you as the merchant (controller), or point the buyer to you.
Children
SizeEcho is a B2B Shopify app for merchants. It is not directed at children.
Contact
Questions about this policy or privacy requests:
Email: support@sizeecho.com
Postal address available on request via the same email.
We aim to respond within a reasonable time. For security issues, use the same address and mark the subject clearly (for example, “Security”).
Changes
We may update this policy when the product or the law changes. The Last updated date at the top will change when we do. For material changes, we will provide notice in a reasonable way (for example in the app or by email to the merchant contact we have), where feasible. This privacy notice is information about processing; it is not a substitute for your Terms of Service.
Summary (not a substitute for the sections above)
SizeEcho is operated by Thomas Johansson, a sole proprietorship in Sweden. We store shop identifiers, order and fulfillment metadata for check-ins, customer email for Klaviyo delivery, fit answers and reason codes, merchant Klaviyo API keys you connect, Shopify session and billing identifiers, and support messages you send us. A customer access request is shown to that shop’s admin in Settings. Customer erasure anonymizes identifiers on matching fit checks and keeps product and size answers. Shop erasure and uninstall also delete session rows and customer-data exports. App and database hosting is on Hostinger in Germany. We do not store card data, and we do not publish a street address. Processors and platforms include Shopify, Klaviyo, and Hostinger. Contact: support@sizeecho.com. Postal address available on request via the same email.