Wotaso Ring Sizer Privacy Notice
This notice describes how the app operator handles shop and storefront sizing data for Wotaso Ring Sizer.
App operator: Wotaso GmbH
Address: Bostonring 5, 71686 Remseck am Neckar, Germany
Represented by: Lucas Damian Orzan, Managing Director
Privacy contact: contact@wotaso.com
Contact / imprint: https://wotaso.com/imprint
Public privacy URL: https://app.ringsizerpro.com/legal/privacy
Roles
The merchant using the app remains responsible for the storefront deployment and for choosing a valid legal basis for end-customer processing in the merchant's shop. The app operator processes shop, product, and sizing event data to provide the sizing service, quota enforcement, billing support, security monitoring, and aggregated service analytics.
Data categories processed by the app
- Shop account data such as the shop domain, subscription state, app settings, and product matching configuration.
- Product context required for size matching, such as product title, type, options, variant availability, and selected size option.
- Sizing output data such as measurement mode, calculated diameter/circumference, recommended size, and matched product size. Detailed events are persisted only when the merchant enables analytics and Shopify Customer Privacy reports that analytics processing is allowed.
- Anonymous funnel events such as measurement viewed, calibration viewed, result viewed, and purchase requested, also only when Shopify reports analytics processing is allowed.
- Pseudonymized abuse-prevention counters keyed by an HMAC-SHA-256 value derived from request scope and either shop domain or client IP address. The HMAC uses a server-held secret; the app does not persist the raw IP address in this rate-limit table.
The sizing flow does not request or use camera access. It uses an on-screen overlay calibrated with a physical credit card, collects no images, and does not persist customer account identifiers.
Purposes
- Deliver the sizing flow inside the merchant storefront.
- Map a measured size to the nearest available product variant.
- Cap analytics recording during the free launch and support future billing operations only after the documented approval gates.
- Generate merchant-facing and operator-facing aggregated performance analytics.
- Protect the service against abuse and support incident response.
Roles and legal bases
- For merchant account administration, installation, support, security, and service operation, the app operator acts as controller. Processing is based on performance of the merchant contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c)), and the operator's legitimate interests in providing and securing the service (Article 6(1)(f)).
- For optional storefront measurement analytics enabled by a merchant, the merchant determines purpose and legal basis and the app operator processes the data on the merchant's documented instructions. Shopify Customer Privacy consent state is enforced as an additional technical gate; it does not replace the merchant's legal assessment.
- Security logs and pseudonymous rate-limit counters are processed under the operator's legitimate interest in preventing abuse, protecting availability, and investigating incidents. They are not used for advertising profiles.
Retention
When Shopify Customer Privacy reports analytics processing is allowed, detailed measurement events and anonymous funnel events are retained for 90 days by default and are then purged automatically. If processing is not allowed or cannot be determined, sizing still works but no measurement or funnel event is persisted. Merchants can disable sizing analytics entirely in the app settings.
Abuse-prevention counters use one-minute enforcement windows. Expired hashed keys are removed by request-time cleanup after they have been expired for one day; raw IP addresses are not stored in the rate-limit table.
Shop data and application sessions are deleted after the verified Shopify shop-redact request. On uninstall, the stored access token is cleared and Shopify SDK sessions are deleted. If encrypted backups are enabled, deleted records can remain in rotation until the configured backup retention expires and are not restored except for disaster recovery.
Recipients, hosting, and transfers
- Shopify supplies installation, authentication, product, theme-extension, consent, and compliance-webhook services.
- Hetzner Online GmbH hosts the current application and PostgreSQL service in Germany.
- Public authorities or professional advisers receive data only where legally required or necessary to establish, exercise, or defend legal claims.
The primary application/database workload is hosted in Germany. Shopify may process data in other countries under the merchant's Shopify agreement and Shopify's applicable transfer safeguards. No experimental AI provider receives storefront sizing data in the free launch.
Customer rights and merchant transparency
Merchants should link their own storefront privacy policy in the sizing modal so shoppers understand the merchant-facing use of the feature. The app supports this directly through the merchant settings. Shopify privacy compliance webhooks for customer data requests, customer redact, and shop redact are implemented server-side.
Depending on the applicable GDPR conditions, data subjects may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Requests can be sent to contact@wotaso.com. Shoppers should normally contact the merchant first because the app does not persist customer identifiers and cannot independently identify an individual measurement event.
Data subjects may lodge a complaint with a supervisory authority, in particular the supervisory authority of their habitual residence or workplace. The operator's lead local contact is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg: baden-wuerttemberg.datenschutz.de.
Required and optional data
Shop installation and product context are required to provide the Shopify app. Optional measurement analytics can be disabled; sizing remains available without persisting measurement or funnel events. No automated decision with legal or similarly significant effect is performed.
Subprocessors
The app relies on Shopify platform services and the operator's hosting/database stack. The experimental AI category scan is disabled in the release candidate and is not used for storefront sizing.
Current subprocessor list: https://app.ringsizerpro.com/legal/subprocessors
AI transparency notice: https://app.ringsizerpro.com/legal/ai-transparency
Updates
This notice is effective from 10 August 2026. Material changes to purposes, recipients, retention, or international transfers require a new published version and merchant notice where required.