Shopify
Shopify is a web application that allows you to create your own online store.
Score
Citation
We use cookies to serve targeted ads from Google, Facebook, Bing, SourceKnowledge, and other third-party vendors. We also use cookies, and other information from your browser and/or device to provide you with personalized advertising, ad delivery, and reporting across multiple sessions and devices.
Notes
The service does offer opting-out option.
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Citation
Shopify understands that you have rights over your personal information, and takes reasonable steps to allow you to access, correct, amend, delete, port, or limit the use of your personal information.
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
Shopify works with a variety of third parties and service providers to help provide you with our Services and we may share personal information with them to support these efforts.
Score
Citation
..to conform to legal requirements, or to respond to lawful court orders, subpoenas, warrants, or other requests by public authorities (including to meet national security or law enforcement requirements).
Score
Citation
We follow industry standards on information security management to safeguard sensitive information, such as financial information, intellectual property, employee details and any other personal information entrusted to us. Our information security systems apply to people, processes and information technology systems on a risk management basis.
We perform annual audits to ensure our handling of your credit card information aligns with industry guidelines. We are certified as a PCI DSS Level 1 compliant service provider, which is the highest level of compliance available, and our platform is audited annually by a third-party qualified security assessor."
Score
Notes
The last modified date is available in the bottom of the policy.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
Nothing is mentioned about data breaches in the privacy policy.
Score
Citation
If we make material changes to this Privacy Policy, we will give you notice of such changes by posting the revised policy on this Website, and where appropriate, by other means.
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Citation
We collect your name, company name, website, twitter or other social media handles, phone number(s), address, business type, email address, PayPal Account, and GST/HST number.
We collect data about the Shopify websites that you visit. We also collect data about how and when you access your account and the Shopify platform, including information about the device and browser you use, your network connection, your IP address, and information about how you browse through the Shopify interface.
Score
Citation
We collect your name, company name, address, email address, phone number(s) and payment details (for example, your credit card information).
We use this information to provide you with our Services; for example, to confirm your identity, contact you, provide you with advertising and marketing, and invoice you. We also use this information to make sure that we comply with legal requirements.
Notes
It's generally clear why the service collects the data that it does.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Citation
Opting out: You can opt out of targeted ads served via specific third party vendors by visiting the Digital Advertising Alliance’s Opt-Out page or the Network Advertising Initiative’s Opt-Out page.
Notes
Despite you can opt-out of targeted ads, there is still quite a big amount of data that is going to be used for non-critical purposes.
Score
Notes
The policy lists the data types only generally though uses a lot of "including" and "for example" statements.
Last Updated
June 24, 2020
Sources
Contributors