Privacy Policy
Last updated: 17 August 2026 · getoptical.app
This Privacy Policy explains how Carlos Enrique Herrera Betancourt, a sole trader (autónomo) with Spanish tax ID (NIF) 54263611X, trading as "GetOptical" ("GetOptical", "we"), handles information when a merchant installs our Shopify apps — including Optical Form — and when a merchant's customers use features we provide on the storefront.
1. Who is responsible
For merchant account data, GetOptical is the data controller. For prescription and order data that a merchant's customers submit through our on-store forms, the merchant is the controller and GetOptical acts as a processor on their behalf.
2. Data we collect
- Merchant & store data — shop domain, store name, language, contact email address and the other store details Shopify syncs to us, along with the data needed to run the app, accessed via Shopify with the scopes you approve on install (products, metaobjects and their definitions, store languages and files). We use the store's email address to write to you about the app: getting set up, and the status of your subscription. We also store the state of those notices — which message was sent, when, how many attempts there were, and whether your mailbox rejected it or marked it as spam, so we stop writing.
- Customer prescription data — values a shopper enters or uploads in the configurator (prescription figures such as SPH, CYL, AX, ADD, PD, and uploaded prescription files). This is submitted to the merchant's Shopify order as line-item properties; Optical Form does not store it on its own servers.
- Order & selection data — the lens, treatment and accessory choices attached to the order on Shopify.
- Anonymous configurator telemetry — so the merchant can see which step shoppers drop out on, we record the shape of the funnel: step, step type, duration, total price and the non-clinical options chosen, tagged with a random identifier generated in the browser when the configurator opens and never stored on the device. It carries no prescription values and nothing that identifies the shopper: our server discards any options sent alongside a prescription step, and rejects the whole payload if a label looks like personal data.
- Technical data — minimal operational logging by our hosting providers, needed to run and secure the merchant-facing app.
3. How we use it
To provide the app's functionality (build the configuration, add it to cart, save it to the order), to support merchants, and to keep the service secure and reliable. We also email the store's address to help you get the app working and to tell you where your subscription stands: these are notices about the service you have installed, not marketing, and you can ask us to stop sending them by replying to any of them or writing to support@getoptical.app. We do not sell personal data, and we do not use prescription data for advertising.
4. Processors & hosting
The app runs on Shopify (the store platform) and Gadget (our application backend and database). Gadget stores merchant and store account data, form configurations and subscription status — not customer prescription data, which lives on the merchant's Shopify order.
Alongside them we use:
- Resend — delivery of the emails we send to merchants. It receives the store's email address, the subject and the body of the message (which includes the store name), and reports bounces and complaints back to us so we stop writing to a mailbox that does not want to hear from us. We hand it no mailing lists and no segments: each notice is a single message to a single recipient.
- Vercel — hosting for this site (getoptical.app) and for the documentation site (docs.getoptical.app).
- Crisp (Crisp IM SAS, Nantes, France) — the support chat on this site, which only loads if you press the chat button. If you do, it receives your IP address, your browser information and the contents of the conversation, and stores a cookie in your browser; section 8 has the detail. It runs on getoptical.app only: never inside a merchant's storefront or the configurator.
- Google — the support@getoptical.app mailbox runs on Google Workspace, so support correspondence passes through it.
These providers act as sub-processors under their own security and privacy terms. Some of them may process data outside the European Economic Area; where they do, the transfer is governed by that provider's own data processing terms, which we will share on request using the contact details below.
5. Prescription (sensitive) data
Prescription data is submitted to the merchant's Shopify order to fulfil it; we do not keep a copy on our own servers. It is transmitted over TLS. Because the data lives on the Shopify order, requests to access or delete it are handled by the merchant and Shopify; we also support Shopify's mandatory data-redaction requests.
6. Retention
We retain data only as long as needed to provide the service or as required by law — generally the periods set by applicable tax and commercial rules (typically 4–6 years for order- and invoicing-related data). On a valid redaction request, or when Shopify notifies us after you uninstall the app, we erase the customer data that request covers. In practice we hold none: prescriptions and selections travel straight to the merchant's Shopify order and never reach our servers. Anonymous configurator telemetry is deleted automatically after 195 days. Your form configurations and store account record are retained — including the state of the email notices: which message was sent, when, how many attempts there were, and whether your mailbox was flagged by a bounce or a complaint — so that reinstalling the app restores your forms rather than starting from an empty account, and so we do not write to you again if you asked us to stop. You can ask us to delete them at any time using the contact details below; note that deleting the record also deletes that "do not write" flag.
7. Your rights (GDPR / CCPA and similar)
Depending on your location you may request access, correction, deletion, portability, or restriction of your data. Merchants' customers should direct requests to the store they purchased from; we assist merchants in fulfilling them. Contact us at support@getoptical.app. If you believe the processing does not comply with the law, you may lodge a complaint with the competent supervisory authority; in Spain, the Spanish Data Protection Agency (AEPD, aepd.es).
8. Cookies and third-party services on this site
This site sets no analytics, advertising or cross-site tracking cookies. Opening a page loads no third-party service at all: the typefaces are served from this same domain and there is no external analytics. There is a single exception, and you decide it:
- Crisp (Crisp IM SAS, Nantes, France) — the support chat. Nothing from Crisp loads until you press the chat button. From that moment it writes first-party cookies (crisp-client/…) — the main one lasting 6 months — valid for getoptical.app and its subdomains, including the documentation site, plus two local-storage entries, so it can recognise your conversation if you come back. It also receives your IP address, your browser information, the contents of your messages and any contact details you give us.
If you never press that button, your visit leaves no cookie and contacts no third party. You can clear or block that storage in your browser settings; the chat will still open, but it will not remember earlier conversations.
The storefront app writes no cookies and uses no browser storage on the shopper's device: the configurator works in memory and the cart is handled by Shopify itself.
9. Changes
We may update this policy; the "last updated" date reflects the current version.
10. Contact
Carlos Enrique Herrera Betancourt (NIF 54263611X) · Calle Arroyo 27, 41003 Sevilla, Spain · support@getoptical.app