Privacy Policy — Easy 3D Viewer


Effective date: August 16, 2026 Last updated: August 31, 2026

Easy 3D Viewer (“the App”, “we”, “us”, “our”) is a Shopify app developed and operated by bPlugins LLC. The App lets a Shopify merchant upload 3D model files and display them on their online store through a theme app block.

This policy explains what personal information the App collects, why we collect it, who we share it with, and the choices available to merchants and to their customers. It applies to the App only — it does not cover the merchant’s own store, which is governed by that merchant’s privacy policy.


1. Who this policy covers

GroupWhat it means here
MerchantsShopify store owners and staff who install and use the App in the Shopify admin.
Store visitorsPeople who browse a merchant’s storefront and view a 3D model rendered by the App.

2. Information we collect

2.1 Information we receive from Shopify when the App is installed

When a merchant installs the App and completes authorization, we query the Shopify Admin API for the store’s own details and receive:

We read the same store details again when the App is uninstalled and when a subscription changes status, so that our records stay current. In the uninstall case they arrive in Shopify’s app/uninstalled webhook payload.

2.2 Permissions the App requests

The App requests these Shopify access scopes and no others:

The App does not request, receive, or store customer records, order data, or payment data. We have no access to your customers’ names, email addresses, shipping addresses, or payment details.

2.3 Information merchants provide directly

2.4 Support requests

If a merchant uses the support form inside the App, we send the name, email address, subject and message entered on the form to bPlugins’ support ticket system, together with the store’s .myshopify.com domain, the name of this App, and whether the store is on a paid plan. The shop domain and plan are added by us rather than typed by the merchant, so that support can identify the store without asking.

2.5 Billing information

If a merchant subscribes to a paid plan, we store the plan name, price, subscription status, Shopify charge ID, trial and billing dates, and activation or cancellation dates. Billing is handled entirely by Shopify’s Billing API. We never see or store credit card numbers or any other payment instrument details.

2.6 Usage analytics in the Shopify admin

Pages of the App inside the Shopify admin include Google Analytics 4 and Microsoft Clarity. These collect:

We use this strictly to understand how merchants use the App, to find bugs, and to improve the interface.

These analytics run on merchant-facing admin pages only. The public storefront viewer embed, the shareable model links, and the authentication screens carry no analytics scripts, so your store visitors are not tracked by these tools.

2.7 Information collected from store visitors

When a store visitor loads a page containing a 3D model, their browser requests the model file and its configuration — either directly from Shopify’s CDN, or through the App’s proxy on the store’s own domain (/apps/viewer-3d/...). Our server processes proxied requests and may record standard server log data — IP address, user agent, timestamp, and the requested model ID — for security, abuse prevention, and diagnostics. We do not set advertising cookies, build visitor profiles, or run behavioural tracking on the storefront.

2.8 Server logs

Our servers keep operational logs of errors and API requests. These may incidentally contain a shop domain, an IP address, or a request path.


3. How we use information

We use the information described above to:

We do not sell personal information, and we do not share it with advertisers or data brokers.


4. Legal bases for processing (EEA and UK merchants)

Where the GDPR or UK GDPR applies, we rely on:


5. Where your data is stored

3D model files uploaded through the App are stored in the merchant’s own Shopify Files library, on Shopify’s infrastructure, and are served from Shopify’s CDN. We store only a reference to each file (its Shopify file ID and URL), its name, its size, and its viewer configuration.

Model references and viewer settings are also written into metafields on the merchant’s own store, which is how the theme block reads them without calling out to us. That copy is part of the merchant’s Shopify data and stays under the merchant’s control.

App data — sessions, plan records, model references, and configuration — is also stored in our application database, hosted on MongoDB Atlas, with the App itself running on servers operated by our hosting provider. Data may be processed in countries other than the merchant’s own. Where personal data is transferred out of the EEA or the UK, we rely on Standard Contractual Clauses or an equivalent recognized transfer mechanism.


6. Third parties we share information with

We share only what each provider needs to perform its function. Our current sub-processors are:

ProviderPurposeData shared
Shopify Inc.App platform, authentication, file storage, billingStore and merchant identifiers, uploaded files, subscription records
MongoDB, Inc. (Atlas)Database hostingAll App data described in Section 2
Our hosting providerRunning the App’s serversAll App data described in Section 2
SwipeOneCustomer relationship management and merchant lifecycle messagingShop domain, store owner name, email, phone, address, country, store creation date, Shopify plan name, and lifecycle events — install, uninstall, first visit to the pricing page, and subscription status changes
bPlugins support ticket system (operated by us)Handling support requestsName, email, subject and message from the in-app support form, plus shop domain and whether the store is on a paid plan
Google LLC (Google Analytics 4)Product usage analytics in the adminPage views, device and browser data, IP-derived approximate location, shop domain, analytics cookie identifier
Microsoft Corporation (Clarity)Session replay and heatmaps in the adminInteraction recordings within the App’s admin pages, device and browser data, IP-derived approximate location

We may also disclose information where required by law, court order, or a valid governmental request, or to establish, exercise, or defend legal claims.

If bPlugins is involved in a merger, acquisition, or sale of assets, merchant data may be transferred as part of that transaction. We will notify affected merchants before their data becomes subject to a different privacy policy.


7. How long we keep data

DataRetention
Session and access tokenDeleted as soon as we receive the uninstall webhook
Model references, viewer configuration, plan and subscription records, onboarding stateErased when Shopify sends the shop/redact webhook, 48 hours after uninstall
Uploaded model filesRemain in the merchant’s own Shopify Files library and are under the merchant’s control; uninstalling the App does not delete them from Shopify
Metafields written into the merchant’s storePart of the merchant’s own store data. Shopify removes the App’s reserved-namespace metafields when the App is uninstalled; any in the custom namespace stay until the merchant deletes them
Server logsUp to 90 days
Analytics dataPer the provider’s retention settings — Google Analytics up to 14 months, Microsoft Clarity up to 30 days
CRM records in SwipeOneUntil deletion is requested, or the record becomes inactive under our retention schedule
Support ticketsRetained while the enquiry is open and for a reasonable period afterwards, so that follow-up questions have context
Payout and tax records received from ShopifyFor as long as tax and accounting law requires, typically 7 years

We do not hold your payment records. Shopify processes every charge and retains its own billing records under Shopify’s privacy policy; what we receive from Shopify are payout and tax documents identifying the store, not the payment instrument.

What happens when a merchant uninstalls

Shopify sends us an app/uninstalled webhook. On receipt we delete the store’s session records and access token, which ends our ability to reach the store at all. Shopify then sends shop/redact 48 hours later, and on that signal we erase the store’s remaining App data. We honour all three of Shopify’s mandatory data privacy webhooks:

Every webhook we accept is verified by HMAC signature; a request that fails verification is rejected.


8. Your rights and choices

For merchants

Depending on where you live, you may have the right to:

To exercise any of these rights, email support@bplugins.com. We respond within 30 days. We may need to verify your identity and your association with the store before acting.

You can also delete most App data yourself: uninstalling the App from your Shopify admin triggers the deletion process described in Section 7.

Opting out of analytics

For store visitors

The App does not collect personal information from store visitors beyond the server log data described in Section 2.7. If you are a store visitor with a privacy question, contact the merchant whose store you visited; they can raise it with us on your behalf, or you can email us directly at support@bplugins.com.

California residents (CCPA/CPRA)

We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding 12 months. California residents may request disclosure of the categories and specific pieces of personal information we have collected, request deletion, and are entitled not to be discriminated against for exercising these rights. Submit requests to support@bplugins.com.


9. Cookies

Within the Shopify admin, the App uses:

The storefront viewer embed does not set cookies of its own.


10. Security

We protect data with measures appropriate to its sensitivity, including encryption in transit over HTTPS, access controls limiting staff access to production data, HMAC verification of every Shopify webhook, and secure handling of access tokens. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant supervisory authority as required by law.

One thing worth knowing about share links. Every model in the App has a shareable viewer link. That link is public by design: anyone who has it can view that 3D model without signing in, in the same way that anyone with the URL of an image on your store can open it. The links contain a random identifier that cannot be guessed or stepped through to find other models, but treat a share link as public once you have sent it. A model you no longer want reachable should be deleted from the App.


11. Children’s privacy

The App is a business tool intended for merchants and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.


12. Changes to this policy

We may update this policy to reflect changes to the App, to our providers, or to legal requirements. The “Last updated” date at the top will change, and material changes will be announced within the App or by email to the store’s contact address. Continued use of the App after an update means you accept the revised policy.


13. Contact us

bPlugins LLC
Support: support@bplugins.com 
Website: https://bplugins.com 
Postal address: Ste 1200, 1309 Coffeen Avenue, Sheridan, WY, Sheridan, US, 82801

For merchants in the EEA or the UK, bPlugins LLC acts as a data processor for the personal data contained in your store, and as a data controller for the merchant account and usage data described in Sections 2.1, 2.4, 2.5, and 2.6. We do not have an EU or UK representative appointed under Article 27 at this time.