Privacy Policy for BoxFit 3D — Smart Auto Bundler

Effective date: August 24, 2026

This Privacy Policy describes how Claymind LLC (“we,” “us,” or “our”) collects, uses, discloses, and retains information when merchants install or use BoxFit 3D — Smart Auto Bundler (“BoxFit” or the “App”) with a Shopify store.

Replace all bracketed information before publishing this policy.

1. Our role

For information that Shopify merchants and their customers provide through a Shopify store, the merchant generally determines why and how that information is processed. We process that information on the merchant’s behalf to provide BoxFit.

We may act as an independent controller for information concerning merchant administrators, App accounts, billing, security, and communications with us.

2. Information we collect

Depending on how the App is used, we may process the following information:

Merchant and store information

  • Shopify store domain and store identifiers.

  • App installation, authorization, subscription, and access-scope information.

  • Merchant administrator information supplied through Shopify authentication, which may include a user ID, name, email address, locale, account-owner status, and collaborator status.

  • Authentication tokens required to connect the App to Shopify.

  • The store’s measurement system and App configuration.

Product and inventory information

  • Product and variant identifiers, titles, handles, SKUs, vendors, product types, tags, prices, and inventory availability.

  • Product and variant dimensions, weights, eligibility settings, and related Shopify metafields.

  • Box definitions, capacity settings, fitting allowances, weight limits, quantity limits, and enabled status.

  • Merchant-created fill preferences, including collection selections and product rules.

Storefront and cart information

  • Product variant identifiers and quantities placed into a box.

  • Customer-selected and automatically suggested box contents.

  • Box identifiers, budget preferences, fill preferences, and packing results.

  • Temporary identifiers used to distinguish individual boxes in a cart.

  • A visitor’s IP address for short-term security and rate-limiting purposes.

BoxFit may use browser session storage to retain temporary box-capacity information during a storefront browsing session. This information remains in the visitor’s browser and is not used for advertising.

Order information

When a relevant order is created, BoxFit may receive and store:

  • Shopify order ID, order number, and creation time.

  • Product and variant identifiers, titles, quantities, and box-related line-item properties.

  • A snapshot of the products assigned to each box.

  • Packing coordinates, orientations, dimensions, and other information needed to create fulfillment pack patterns.

BoxFit does not request or intentionally store customer names, email addresses, telephone numbers, billing addresses, shipping addresses, or payment-card information. Order and cart information may nevertheless constitute personal information because it relates to an identifiable Shopify order or customer.

Privacy and operational information

  • Shopify webhook identifiers, topics, and delivery times.

  • Records and generated exports associated with privacy requests.

  • Packing-optimization request counts.

  • Technical logs, errors, and security events necessary to maintain and protect the App.

3. How we use information

We use information to:

  • Authenticate merchants and connect the App to Shopify.

  • Configure box products and eligible products.

  • Calculate whether selected products fit inside a box.

  • Recommend products that fit remaining box capacity, budget, weight, inventory, and merchant-defined preferences.

  • Generate three-dimensional packing results and fulfillment pack patterns.

  • Preserve temporary packing state and support alternate product mixes.

  • Maintain packed-order history and calculate aggregate completed-box usage.

  • Verify App subscriptions and enforce plan features.

  • Respond to privacy access and deletion requests.

  • Prevent abuse, enforce rate limits, investigate errors, and secure the App.

  • Maintain, troubleshoot, and improve the reliability of the App.

  • Comply with legal obligations and enforce our agreements.

We do not use Shopify customer or order information for unrelated advertising, customer profiling, or marketing.

4. How we disclose information

We disclose information only as reasonably necessary to operate the App, including to:

Shopify

BoxFit exchanges information with Shopify to authenticate merchants, read authorized store information, update App-owned product metafields, receive order and compliance webhooks, provide the storefront app proxy, and verify subscriptions. Shopify processes information under its own agreements and privacy policies.

Packing Optimizer

BoxFit sends container and item identifiers, dimensions, weights, allowed rotations, and existing packing coordinates to Packing Optimizer to calculate packing arrangements. We do not intentionally send customer names, email addresses, telephone numbers, postal addresses, or payment information to Packing Optimizer.

Infrastructure providers

We may use hosting, database, logging, security, and cloud infrastructure providers to operate BoxFit. These providers may process information only as necessary to provide services to us and subject to appropriate contractual restrictions.

Legal and business purposes

We may disclose information:

  • To comply with applicable law, legal process, or a valid governmental request.

  • To investigate fraud, abuse, security threats, or violations of our agreements.

  • To protect the rights, safety, and property of merchants, customers, us, or others.

  • In connection with a merger, financing, acquisition, reorganization, or sale of all or part of our business, subject to appropriate confidentiality protections.

  • With a person’s consent or at the merchant’s direction.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising or targeted advertising.

5. Legal bases for processing

Where applicable law requires a legal basis, we process information:

  • To perform our contract with the merchant and provide the App.

  • To pursue legitimate interests such as securing, maintaining, and improving the App, provided those interests are not overridden by individual rights.

  • To comply with legal obligations.

  • With consent, where consent is required.

When we process customer information on behalf of a merchant, the merchant is responsible for identifying an appropriate legal basis and providing any required notices or choices to its customers.

6. Data retention

We retain information only for as long as reasonably necessary for the purposes described in this policy:

  • Packed-order snapshots are retained for 365 days.

  • Webhook delivery receipts are retained for 30 days.

  • Generated customer privacy-request exports are retained for 30 days.

  • Temporary packing state is retained only for the period needed to provide packing functionality and is removed when it expires or when the App is uninstalled.

  • Authentication information and temporary packing data are deleted when the App is uninstalled.

  • Remaining merchant configuration and order information may be retained during Shopify’s reinstall grace period and is deleted when Shopify sends its shop-redaction request, unless retention is required by law.

  • Customer-related packed-order information is deleted when we receive and process an applicable customer-redaction request from Shopify.

  • In-memory rate-limiting and packing-cache information expires automatically and is not retained as a permanent customer profile.

We may retain limited records longer when required to comply with law, resolve disputes, prevent fraud, or enforce agreements.

7. Privacy rights

Depending on location, individuals may have rights to request:

  • Access to personal information.

  • Correction of inaccurate information.

  • Deletion of personal information.

  • Restriction of or objection to processing.

  • Portability of certain information.

  • Withdrawal of consent.

  • An appeal of a denied privacy request.

  • Information about how personal information is disclosed.

Customers of a Shopify merchant should normally submit privacy requests directly to that merchant. Shopify may then send the appropriate privacy request to BoxFit. BoxFit provides the merchant with an authenticated export of matching packed-order information and processes applicable deletion requests.

Merchants and merchant administrators may contact us using the information below. We may need to verify a requester’s identity and authority before completing a request.

Individuals may also have the right to complain to their local data-protection authority.

8. International transfers

We and our service providers may process information in countries other than the country where it was collected. Those countries may have different data-protection laws. Where required, we use appropriate safeguards for international transfers, such as contractual protections approved by the relevant authorities.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. These measures include authenticated Shopify connections, signed App-proxy requests, restricted access, encrypted network communications, credential controls, request validation, and data-retention limits.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children

BoxFit is provided to Shopify merchants and is not directed to children. We do not knowingly collect personal information directly from children. Merchants are responsible for ensuring that their stores and use of the App comply with laws concerning children’s information.

11. Merchant responsibilities

Merchants are responsible for:

  • Providing their customers with any legally required privacy notices.

  • Obtaining required consent for information processed through their stores.

  • Responding to customer privacy requests.

  • Configuring and using BoxFit in accordance with applicable law.

  • Avoiding the submission of unnecessary sensitive or identifying information through product titles, tags, preferences, or other configurable fields.

12. Changes to this policy

We may update this Privacy Policy periodically. We will post the revised policy with a new effective date and provide additional notice when required by law. Continued use of the App after an update takes effect constitutes acceptance of the updated policy to the extent permitted by law.

13. Contact us

For privacy questions or requests, contact:

Claymind LLC
122 Shire Ct. San Dimas CA 91773
Email: support@claymind.com
Privacy contact or Data Protection Officer: Guillermo Misa III