Privacy notice
Effective 7 October 2026. BespokePilot is operated by Studio8022. Operator details are on our business details page.
What we process
We store the merchant’s Shopify domain, installation and authentication records, subscription entitlement, settings and verified notification address. Shopify authentication may include staff name, email, identifier and locale. For product enquiries we store the customer’s name, email, product and variant, requested quantity, message, custom answers and the form shown when submitted. We also store merchant replies, private notes, follow-up dates and linked Shopify draft and order identifiers, invoice status and payment outcome. We do not collect payment-card details.
How information is used
The merchant decides which details to request and uses them to answer enquiries and prepare quotes. We process these details to supply that workflow, send requested messages, keep records consistent, secure the app and provide support. A customer reply to an app email goes to the merchant’s verified mailbox. BespokePilot does not import incoming emails.
Storefront and service providers
The storefront form sends the product identifier to load the applicable form and sends entered details when the visitor submits. No advertising trackers or cross-site profiling are included. Shopify provides authentication, platform billing, storefront asset delivery, draft orders and invoice emails. Our infrastructure and email providers are described in the Studio8022 provider information. We do not sell personal data.
Security records
Test and production data use separate databases and runtimes. Restricted access records contain pseudonymous actor and shop references, time, resource, action and outcome, without enquiry text, email addresses or authentication tokens. These security records are retained for up to 90 days and checked for integrity.
Retention and deletion
Merchants can export and delete enquiries. Spam is removed 30 days after being marked closed; other closed enquiries after one year. All enquiries are removed after two years, including associated app replies and notes. Records are processed in periodic batches. Uninstalling stops new collection and queued email and revokes saved sessions. Shopify’s shop deletion notification removes remaining app records when the shop has no active installation. Webhook receipts are kept up to 30 days. Restricted records needed for legal or security obligations may be retained where required.
Your rights and responsibilities
Customers should contact the merchant first about an enquiry. Merchants and staff may contact support for access, correction, export or deletion. We verify requests to protect the account. Depending on your location, you may have rights to object, restrict processing or complain to a supervisory authority. Merchants must provide appropriate notices and must not request payment-card data or sensitive personal information in custom fields. Deleting an app enquiry does not delete the merchant’s Shopify draft, order or mailbox copy.
Contact support@studio8022.com.