Legal

Privacy Policy

Last updated: May 11, 2026

01

Introduction

At SampleLoop, your privacy and the privacy of your customers is our priority. This Privacy Policy explains how we collect, use, store, and protect information when you install and use SampleLoop on your Shopify store, and when your prospects submit sample requests through the SampleLoop storefront form. By installing SampleLoop, you agree to the practices described in this policy.

02

Information We Collect

  • Shopify Account Information: Your shop domain, store name, contact email, and the access token Shopify issues when you install the app. We only access scopes you approve during installation.
  • Merchant Configuration: The settings you choose in the SampleLoop admin, such as the products you mark as eligible for sampling, max items per request, auto-approval, and notification preferences.
  • Sample Request Data: Information submitted by prospects through the storefront form: contact name, company, email, phone (optional), shipping address, and the variants they want to sample.
  • Order and Attribution Data: When you approve a request we create draft orders in your Shopify store. We also receive paid-order webhooks during the 180-day attribution window to match orders back to the originating sample.
  • Billing Information: Subscription status is managed by Shopify Billing. We do not collect or store your payment card details.
03

How We Use Your Information

  • To operate the SampleLoop app inside your Shopify admin (accepting requests, creating draft orders, attributing paid orders)
  • To send service updates, security alerts, and account notifications
  • To diagnose technical issues and improve the reliability of the app
  • To verify your subscription status with Shopify Billing
  • To comply with legal obligations and enforce our Terms of Service
04

Legal Basis for Processing

We process personal data under the following legal bases:

  • Contractual Necessity: Processing data is necessary to deliver the SampleLoop service to merchants who install the app.
  • Legitimate Interest: We process limited operational data (such as request logs) to maintain, improve, and secure the service.
  • Consent: Where required by law, we obtain your or your prospects' consent. Prospects consent when submitting a sample request form. You may withdraw consent at any time.
  • Legal Obligation: We may process data to comply with applicable laws, regulations, or legal proceedings.
05

Data Processing and Sub-processors

SampleLoop acts as a bridge between your storefront and your Shopify admin. We do not sell or trade your data or your prospects' data.

We use the following sub-processors to provide the service:

  • Shopify: App hosting, billing, OAuth, and Admin API access (US/global)
  • Vercel: Application hosting and deployment (US)
  • PostgreSQL (Supabase or equivalent): Encrypted database hosting for merchant configuration and sample request records (US)
06

Security Measures

  • All Shopify access tokens are stored encrypted at rest
  • We follow the Principle of Least Privilege, requesting only the minimum Shopify scopes required to run the app
  • All data in transit is protected with TLS 1.2+ encryption
  • We conduct regular reviews of our security practices and access controls
07

Data Retention

  • Merchant account and configuration: Retained for as long as the app is installed on your store. Deleted within 30 days after the app is uninstalled or when Shopify sends an app/uninstalled or shop/redact webhook.
  • Sample request records: Retained for the duration of the 180-day attribution window plus a reasonable archival period, then purged on customer/redact request.
  • Operational logs: Retained for up to 90 days for troubleshooting purposes, then automatically purged.
08

International Data Transfers

SampleLoop is based in the United States, and data is processed and stored on servers located in the United States. If you or your prospects are accessing the service from outside the US (including the European Economic Area or the United Kingdom), data will be transferred to and processed in the US. We rely on standard contractual clauses and other appropriate safeguards to ensure data is protected in accordance with applicable data protection laws.

09

Your Rights

Depending on your location, you or your customers may have the following rights regarding personal data:

  • Access: Request a copy of the personal data we hold.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of personal data. Shopify's customer/redact and shop/redact webhooks are honored automatically.
  • Data Portability: Request a machine-readable copy of data.
  • Restriction: Request that we limit processing of data in certain circumstances.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

California Residents (CCPA): You have the right to know what personal information we collect, to request its deletion, and to opt out of the sale of personal information. SampleLoop does not sell personal information to third parties.

To exercise any of these rights, contact us at michael@michaelmcgarvey.com. We will respond within 30 days.

10

Data Breach Notification

In the event of a data breach that affects personal data, we will notify affected users via email within 72 hours of becoming aware of the breach. We will also notify the relevant supervisory authorities as required by applicable law.

11

Cookies

SampleLoop uses only essential cookies and Shopify session tokens required for the embedded app to function inside the Shopify admin. We do not use cross-site tracking cookies.

12

Children's Privacy

SampleLoop is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at michael@michaelmcgarvey.com.

13

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify merchants via the email address associated with the Shopify store at least 30 days before the changes take effect. Continued use of the service after changes are posted constitutes acceptance of the updated policy.

14

Contact Us

Any questions about your data or our privacy practices? Contact Michael at michael@michaelmcgarvey.com.

© 2026 SampleLoop. All rights reserved.