Switch2Phone Privacy Policy
Last updated: 10 August 2026
Switch2Phone is a Shopify app that shows a QR code on product pages for shoppers browsing on a computer. Scanning it opens the same product on their phone, with the same option already selected.
Switch2Phone does not collect any information that identifies a shopper. No names, email addresses, IP addresses, device identifiers, or browsing profiles are recorded. The app does not set cookies on your storefront and does not track shoppers across sites.
Who this applies to
This policy covers merchants who install Switch2Phone on their Shopify store, and shoppers who visit a store where the app is active.
If you are a shopper, the merchant whose store you visited is the controller of any personal data collected on that store. Their own privacy policy applies to your visit. Switch2Phone acts as a processor for the merchant.
What we collect
From merchants
When you install the app, Shopify provides us with:
- your store's domain (for example
your-shop.myshopify.com) - an access token that lets the app read your product catalogue
- basic account details for the staff member who installs the app, where Shopify supplies them
The app requests a single permission, read_products, which
it uses to show product names on your dashboard and to preview the QR
code against one of your own products. Product data is not copied into
our database beyond the numeric product and variant identifiers
described below.
From shoppers
If you leave analytics switched on, the app records two kinds of event. Each record contains only:
- the store domain
- whether the event was a QR code being shown, or a QR code being scanned
- the numeric product identifier
- the numeric variant identifier, where one applies
- a random token generated for that single page view, used only to match a scan back to the QR code that produced it
- the date and time
The random token is not linked to a person, an account, a session, or a device. It is discarded from the shopper's address bar immediately after the scan is recorded, and it cannot be used to recognise the same shopper again.
What we deliberately do not collect
- names, email addresses, phone numbers, or postal addresses
- IP addresses or approximate location
- browser or device fingerprints, or user agent strings
- cart contents, order history, or payment information
- any identifier that persists between visits
How the QR code works
The QR code is generated inside the shopper's own browser. Displaying it involves no request to Switch2Phone's servers, no third-party service, and no external image. The code points directly at the merchant's own storefront, never at us.
The only message sent to us is a small analytics record, described above, and only when analytics are switched on.
Why we collect it
- To run the app. The store domain and access token are needed to authenticate with Shopify and show you your own data.
- To show merchants whether the feature works. The event records power the dashboard: how often the QR code was shown, how often it was scanned, and which products were scanned most.
We do not sell data, share it for advertising, or use it to build profiles. We do not use it to train machine learning models.
Turning collection off
Merchants can switch off analytics at any time on the app's Settings page. This is enforced on our servers, so events are discarded on arrival rather than relying on the storefront to stop sending them.
The same page has a button that permanently deletes every record stored for your store.
Where data is stored, and who else sees it
Data is stored in a managed database hosted by Render, our infrastructure provider. They process data on our behalf and have no independent right to use it.
Like any service on the internet, our hosting provider keeps short-lived technical request logs, which can include IP addresses. These are used for security and troubleshooting only, are not loaded into the app's database, and are not linked to the analytics records described above.
We do not use third-party analytics, advertising, or tracking services in this app.
How long we keep it
- Analytics records are kept until you delete them, or until you uninstall the app.
- Store credentials are deleted as soon as the app is uninstalled.
- Everything else is removed when Shopify sends its store data erasure request, which arrives about 48 hours after uninstall.
Uninstalling the app removes all of your store's data from our systems. There is nothing left to retain.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete personal data we hold about you, to object to or restrict how it is used, and to complain to a data protection authority.
Because the app stores no shopper identifiers, we normally cannot connect a request from a shopper to any record we hold — there is no field in our data that identifies a person. Merchants can delete all of their store's records at any time from the app's Settings page, or by uninstalling.
To exercise any right, contact us using the details below.
Security
Traffic to and from the app is encrypted in transit. Requests from your storefront and from Shopify are cryptographically verified before they are accepted, so records cannot be forged by a third party. Access to the production database is restricted.
Children
The app is a tool for merchants and is not directed at children. It does not knowingly collect information from anyone, of any age.
Changes to this policy
If the app's handling of data changes, this page will be updated and the date at the top revised. Significant changes will be communicated to merchants through the app.
Contact
Questions about this policy, or about data held by Switch2Phone, can be sent to info@tamerio.com.