Pick A Hat, Pick A Patch ® - Privacy Policy
Pick A Hat, Pick A Patch ("the App") is a Shopify application provided by InTandem Promotions, Inc. ("we", "us"), Kennesaw, Georgia, USA. This policy describes what information the App accesses when a merchant installs it and how that information is used.
Effective date: September 21, 2026
What the App does
The App lets a merchant's customers choose a patch, preview it on a hat product, and add the configured product to the cart. Merchants manage the patch library and per-product settings inside their Shopify admin.
Information the App accesses
When a merchant installs the App, Shopify grants it access to the following store data, which the App uses only to perform its function:
- Products and product variants, including images and metafields, to show the hat the customer is customizing and to read the merchant's per-product settings.
- Metaobjects and metaobject definitions, to store and read the merchant's patch library.
- Files, to save the rendered preview image ("mockup") for each customized item into the merchant's own Shopify Files.
The App stores one record per installed store: a Shopify-issued access token, the store's domain, and the granted permission scopes. This is required for the App to communicate with Shopify on the merchant's behalf.
Customer information
The App does not collect, store, or transmit personal information about the merchant's customers. It does not access customer accounts, orders, addresses, payment information, or browsing behavior.
When a customer completes a design, the App writes the following to the cart line item in Shopify: the chosen patch name and code, a placement description, and links to the patch artwork and the rendered preview. These become part of the merchant's order in Shopify and are subject to the merchant's own privacy policy. The rendered preview is stored in the merchant's Shopify Files and is not retained by us.
Data we retain
- Per-store access token, domain, and scopes: retained while the App is installed. Removed when the merchant uninstalls the App, and again upon receipt of Shopify's
shop/redactrequest. - Server logs containing store domains and request metadata: retained for up to 30 days for operational troubleshooting.
We do not retain product data, images, or cart contents outside of Shopify.
Shopify privacy requests
The App responds to Shopify's mandatory privacy webhooks:
-
customers/data_requestandcustomers/redact: acknowledged. The App holds no customer data, so there is nothing to provide or erase. -
shop/redact: any remaining store record is deleted.
Sharing
We do not sell or share store or customer data with third parties. The App is hosted on Vercel (application) and Supabase (database), which process data on our behalf under their respective terms.
Security
Requests between the storefront and the App are signed by Shopify and verified before any action is taken. Upload requests use short-lived, store-scoped tokens.
Changes
We may update this policy as the App changes. The effective date above reflects the current version.
Contact
InTandem Promotions, Inc. services@intandempromotions.com https://intandempromotions.com