Last updated: 2026-06-27

OriginStory (“we”, “our”, “the app”) is a Shopify app published by Sagiris Web Development that lets merchants attach scannable QR codes to physical product packaging. Each scan opens a hosted product story page showing origin, maker, process, and brand story.

This privacy policy describes what data the app collects, why, how long we keep it, and the rights merchants and their customers have.

What data the app collects

From merchants (Shopify store owners and staff)

When a merchant installs the app, Shopify provides us with an OAuth session that includes:

We additionally store, per shop:

From customers (shoppers who scan a QR code)

When a shopper scans an OriginStory QR code, we record an anonymous scan event containing:

We do not collect or store:

Because nothing in the scan event can be tied back to an individual, no scan data constitutes personal data under GDPR / CCPA.

How we use the data

DataPurpose
OAuth sessionAuthenticate the merchant on each request to Shopify on their behalf
Brand stylingRender the merchant’s hosted story pages with their brand
Product story contentDisplay the story when a shopper scans the QR code
Anonymous scan eventsAggregate “scans per day” analytics shown only to the merchant on the Plus plan

We do not sell, share, or transfer any data to third parties for marketing or advertising purposes.

Data retention

DataRetention
OAuth sessionKept while the app is installed. Deleted immediately when the merchant uninstalls (via the app/uninstalled webhook).
Brand stylingKept while the app is installed. Deleted on uninstall.
Product story contentStored in Shopify as metaobjects on the merchant’s store — controlled by the merchant; deletion is governed by Shopify’s own data lifecycle.
Anonymous scan eventsKept while the app is installed. Deleted on uninstall.

On uninstall, all data we hold for the shop is deleted within seconds via the app/uninstalled webhook. A second cleanup pass runs 48 hours later via the shop/redact webhook (Shopify’s GDPR compliance flow) as a safety net.

GDPR mandatory webhooks

OriginStory implements the three GDPR-mandatory webhooks Shopify requires for App Store listing:

Sub-processors

We rely on the following third-party services to operate the app:

We do not use any analytics, advertising, or tracking SDKs.

Your rights

Merchants

Customers (shoppers)

Contact

Privacy questions, data requests, or concerns: support@sagirisdev.com

Sagiris Web Development
Edmonton, Canada

Changes to this policy

When we update this policy, we’ll change the Last updated date at the top. Material changes will be highlighted in our App Store listing or via in-app notice.