Effective Date: May 29, 2018
Last Updated: July 15, 2026
This Privacy Policy describes how MakeProSimp (“MakeProSimp”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects information when merchants install and use the ToastiBar application on the Shopify platform (“App”). This Privacy Policy applies only to the ToastiBar Shopify application and does not apply to other MakeProSimp products, applications, or websites.
1. Scope
This policy applies exclusively to merchants using ToastiBar through Shopify and to information processed through Shopify-authorized APIs.
2. Definitions
Merchant – the Shopify merchant who installs and uses the App.
Store – the Shopify store associated with the Merchant.
Customer Data – information relating to the Merchant’s customers processed through Shopify APIs.
Personal Data – information relating to an identified or identifiable natural person.
Processing – collecting, storing, using, transmitting, deleting, or otherwise handling information.
Shopify – Shopify Inc. and its affiliated services.
Services – the ToastiBar application and related support services provided by MakeProSimp.
Applicable Law – privacy, consumer protection, and data protection laws applicable to the Merchant or MakeProSimp.
3. Information We Collect
Merchant account information; Shopify store information; app configuration; usage logs; diagnostics; support communications; billing references from Shopify; limited customer, order, and product information only when required by enabled features and granted permissions.
We do not intentionally collect more information than is reasonably necessary to provide the functionality requested by the Merchant.
4. Shopify Permissions
The App only accesses Shopify data for which permission has been granted by the Merchant during installation or subsequently approved by the Merchant through Shopify’s authorization process.
Merchants may revoke these permissions at any time by uninstalling the App or through Shopify, where applicable.
5. How We Use Information
Provide, maintain, improve, secure, troubleshoot, analyze performance, respond to support requests, comply with legal obligations, and prevent abuse or fraud.
6. Legal Basis (GDPR/UK GDPR)
Processing is based on contract performance, legitimate interests, legal obligations, and consent where legally required.
7. Sharing Information
We may share data with cloud hosting providers, analytics providers, customer support platforms, and professional advisers under confidentiality obligations. We never sell merchant or customer personal data.
All service providers process information only on our behalf and are contractually required to protect such information.
8. International Transfers
Where data is transferred internationally, appropriate safeguards such as contractual protections or other lawful mechanisms are implemented where required.
9. Data Retention
Information is retained only as long as necessary for business, contractual, legal, security, and dispute-resolution purposes. Following app uninstallation, unnecessary data is deleted or anonymized within a reasonable period unless retention is legally required.
Certain information may be retained for longer where necessary to comply with legal obligations, resolve disputes, enforce agreements, or protect our legal rights.
10. Security
Industry-standard administrative, technical, and organizational safeguards, including encryption in transit, access controls, monitoring, backups, least-privilege access, and secure development practices.
Although we implement reasonable safeguards, no method of electronic transmission or storage is completely secure, and absolute security cannot be guaranteed.
11. Merchant Responsibilities
Merchants are responsible for determining their own legal obligations as data controllers (or equivalent under applicable law), including providing privacy notices, obtaining required consents, and responding to customer privacy requests where applicable.
12. Customer Data
We process Customer Data solely to provide the Services requested by the Merchant and do not use such data for our own advertising or marketing purposes.
13. Cookies and Analytics
The ToastiBar Shopify App does not place or use cookies on merchants’ storefronts for its core functionality. Our website (www.makeprosimp.com) may use cookies and similar technologies for analytics, security, and website performance.
14. Your Rights
Depending on jurisdiction, users may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent where applicable.
15. California Privacy Notice
Residents of California may have additional rights under the CCPA/CPRA. We do not sell or share personal information as defined by applicable law.
16. Children’s Privacy
The App is intended for businesses and is not directed toward children under the age of 13, or such higher minimum age as required by applicable law in your jurisdiction, and we do not knowingly collect their personal information.
17. Third-Party Services
The App interacts with Shopify and may rely on infrastructure providers, monitoring services, email providers, and support platforms necessary to operate the service.
18. Compliance with Shopify
The App is designed to operate in accordance with Shopify’s API License and Terms of Use. Where Shopify requires MakeProSimp to process, retain, or delete information in a particular manner, we will comply with such requirements.
19. Changes to this Policy
We may update this Privacy Policy periodically. Material changes will be reflected by updating the Last Updated date.
20. Contact Information
MakeProSimp
Email: [email protected]
Website: https://www.makeprosimp.com
Privacy requests may also be submitted using the contact details available on our website.
Appendix A – Detailed Data Categories
ToastiBar only accesses the minimum Shopify data necessary for enabled features. Access depends upon the permissions approved by the Merchant and the features enabled within the App. Not every installation will require access to every data category. Data is processed solely to deliver merchant-requested functionality, improve reliability, investigate support issues, maintain security, and comply with legal obligations. We regularly review permissions to minimize data collection and follow the principle of least privilege.
Appendix B – Contact Requests
Privacy requests may be submitted to [email protected]. We will respond within the period required by applicable law after verifying the request, where necessary.
We may request information reasonably necessary to verify the identity of the requesting party before processing privacy requests.