Wotaso Ring Sizer Privacy Notice
This notice describes how the app operator handles shop and storefront sizing data for Wotaso Ring Sizer.
App operator: Wotaso GmbH
Contact / imprint: https://wotaso.com/imprint
Public privacy URL: https://app.ringsizerpro.com/legal/privacy
Roles
The merchant using the app remains responsible for the storefront deployment and for choosing a valid legal basis for end-customer processing in the merchant's shop. The app operator processes shop, product, and sizing event data to provide the sizing service, quota enforcement, billing support, security monitoring, and aggregated service analytics.
Data categories processed by the app
- Shop account data such as the shop domain, subscription state, app settings, and product matching configuration.
- Product context required for size matching, such as product title, type, options, variant availability, and selected size option.
- Sizing output data such as measurement mode, calculated diameter/circumference, recommended size, and matched product size. Detailed events are persisted only when the merchant enables analytics and Shopify Customer Privacy reports that analytics processing is allowed.
- Anonymous funnel events such as measurement viewed, calibration viewed, result viewed, and purchase requested, also only when Shopify reports analytics processing is allowed.
- Pseudonymized abuse-prevention counters keyed by an HMAC-SHA-256 value derived from request scope and either shop domain or client IP address. The HMAC uses a server-held secret; the app does not persist the raw IP address in this rate-limit table.
The sizing flow does not request or use camera access. It uses an on-screen overlay calibrated with a physical credit card, collects no images, and does not persist customer account identifiers.
Purposes
- Deliver the sizing flow inside the merchant storefront.
- Map a measured size to the nearest available product variant.
- Cap analytics recording during the free launch and support future billing operations only after the documented approval gates.
- Generate merchant-facing and operator-facing aggregated performance analytics.
- Protect the service against abuse and support incident response.
Retention
When Shopify Customer Privacy reports analytics processing is allowed, detailed measurement events and anonymous funnel events are retained for 90 days by default and are then purged automatically. If processing is not allowed or cannot be determined, sizing still works but no measurement or funnel event is persisted. Merchants can disable sizing analytics entirely in the app settings.
Abuse-prevention counters use one-minute enforcement windows. Expired hashed keys are removed by request-time cleanup after they have been expired for one day; raw IP addresses are not stored in the rate-limit table.
Customer rights and merchant transparency
Merchants should link their own storefront privacy policy in the sizing modal so shoppers understand the merchant-facing use of the feature. The app supports this directly through the merchant settings. Shopify privacy compliance webhooks for customer data requests, customer redact, and shop redact are implemented server-side.
Subprocessors
The app relies on Shopify platform services and the operator's hosting/database stack. The experimental AI category scan is disabled in the release candidate and is not used for storefront sizing.