Privacy Policy
Last updated: 2 August 2026
Marquee ("the app") is a Shopify application published by Bismuth Studio ("we", "us"). This policy explains what the app stores, why, and how long for. It applies to merchants who install Marquee on a Shopify store.
What we collect
When you install Marquee, we store the following:
- Your store domain — for example
your-store.myshopify.com, used to identify your installation. - An access token issued by Shopify — required for the app to function. Tokens are short-lived and refreshed automatically.
- Your subscription state — which plan you are on and the identifier of your active charge, so we can tell whether your subscription is current.
- Installation timestamps — when you installed the app and whether you have completed onboarding.
What we do not collect
Marquee does not collect, receive or store personal data belonging to your customers or your storefront visitors. It reads no orders, no customer records and no checkout data.
The banner Marquee renders on your storefront is produced entirely by your theme using Shopify's Liquid templating. It makes no network requests to us and runs no JavaScript, so we do not observe your storefront traffic, set cookies on it, or receive visitor IP addresses.
Where your banner content lives
The text, colours, fonts and placement of your marquee are stored as theme settings inside your own Shopify store, alongside the rest of your theme configuration. We do not hold a copy. If you uninstall the app, those settings remain yours and stay in your theme.
How your data is protected
- All traffic is transmitted over HTTPS using TLS.
- Data is held in a managed PostgreSQL database that is not publicly reachable.
- Every webhook Shopify sends us is verified by HMAC signature before it is processed.
- Access tokens are never exposed to your storefront or to browsers.
Retention and deletion
When you uninstall Marquee, we delete your session records and your shop record immediately, on receipt of Shopify's app-uninstalled webhook. Shopify also sends a shop redaction request 48 hours after uninstall; we process that as a second deletion pass, so your data is removed even if the first webhook was not delivered.
Because we hold no customer personal data, customer data requests and customer redaction requests from Shopify have nothing to return or erase. We acknowledge them as required.
Sub-processors
- Shopify — the platform the app runs on and the source of all data we receive.
- Render — application hosting and the managed PostgreSQL database.
We do not sell, rent or trade your data, and we do not share it with anyone other than the sub-processors above.
Your rights
Under the GDPR, the UK GDPR and the CCPA you may request a copy of the data we hold about your store, ask us to correct it, or ask us to delete it. Uninstalling the app triggers deletion automatically. To make any other request, email gizmo@bismuth.studio from an address associated with the store and we will respond within 30 days.
In GDPR terms you are the data controller for your store's data and we act as a data processor, handling that data only to provide the app.
Changes to this policy
If we change what the app collects, we will update this page and revise the date at the top. Material changes affecting existing merchants will be notified by email.
Contact
Bismuth Studio — gizmo@bismuth.studio