Privacy Policy

Effective Date: February 4, 2026

This Privacy Policy describes how Fits In The Box ("we", "us", or "our") collects, uses, and shares information when you install and use our Shopify application.

Information We Collect

Information from Shopify APIs

When you install our app, we access the following data through Shopify's APIs:

  • Product Information: Product titles, descriptions, dimensions, weight, variants, and inventory data to calculate optimal box sizes
  • Shop Information: Your store name and domain to identify your account

Information from Merchants

We collect information you provide directly:

  • Box Configurations: Dimensions, costs, and names of shipping boxes you configure
  • App Settings: Your preferences for packing rules and display options

Information from Customers

Our embedded shipping estimate widget may collect the following from your customers:

  • Shipping Destination: Country, province/state, and postal code entered to calculate shipping estimates

We do NOT collect customer names, email addresses, payment information, or any other personal identifiable information directly from customers.

How We Use Information

We use the collected information solely to:

  • Calculate optimal box sizes for orders
  • Display shipping estimates to customers
  • Suggest products that fit in remaining box space
  • Provide and improve our services

We do NOT use your data for marketing, advertising, or any purpose other than providing the core functionality of our app.

Data Sharing

We do not sell, rent, or share your data with third parties except:

  • When required by law or legal process
  • To protect our rights or the rights of others
  • With service providers who assist in operating our app (subject to confidentiality agreements)

Data Retention

We retain your data for as long as you have our app installed. When you uninstall the app, we delete your data within 30 days, unless we are required to retain it for legal purposes.

Data Storage and Security

Your data is stored on secure servers in the United States. We implement industry-standard security measures including encryption in transit (TLS) and at rest to protect your information.

Your Rights

Depending on your location, you may have rights regarding your personal data, including:

  • Access to your data
  • Correction of inaccurate data
  • Deletion of your data
  • Data portability

To exercise these rights, please contact us using the information below.

GDPR Compliance

For merchants and customers in the European Economic Area (EEA), we comply with GDPR requirements. We process data as a data processor on behalf of merchants (data controllers). We respond to data subject requests through Shopify's mandatory webhooks.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the effective date.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@fitsinthebox.com