Appointments
A Shopify app that lets a store take appointment bookings from its storefront. It is installed by merchants from the Shopify App Store and runs inside the Shopify admin.
Merchant log in
Privacy and data handling
The merchant you booked with is the controller of your personal data. MySellStack Appointments processes it on their behalf, and only to run their bookings. We do not sell personal data, do not use it for advertising, and do not use one merchant’s data to serve another.
What we hold
From shoppers: the name, email address and phone number entered in the booking form, any answers to the questions the merchant asks, the appointment itself, and — for paid bookings — the related Shopify order. From merchants: store and staff details, the credentials needed to sync their calendar, and which subscription plan the store is on. Payments are handled by Shopify — customer checkout and app subscriptions alike; we never see card details. We set no advertising or analytics cookies.
Who else receives it
- Shopify
- Store platform, checkout and app proxy; bookings are written back to the merchant's orders. Booking pages also load a font from Shopify's CDN, which sees the visitor's IP address.
- Fly.io
- Application hosting (primary region London, UK) and logs.
- Supabase
- Managed PostgreSQL — the primary database.
- Tigris
- Object storage for nightly database backups, encrypted before they leave our servers.
- Resend
- Sends booking confirmations, reminders and cancellations.
- Google, Microsoft, Apple
- Calendar sync and meeting links, for merchants who connect Google Calendar, Outlook or iCloud.
- Nager.Date
- Public-holiday dates by country. Receives no personal data.
How long we keep it
- Bookings and intake answers
- Kept while the merchant's store uses the app. An erasure request strips the personal details out of the booking; uninstalling the app deletes the store's records outright.
- Unfinished booking attempts
- The details entered before checkout are deleted 30 days after the reservation lapses.
- Email delivery records
- The delivery status is kept for the merchant's history; the recipient address and the subject line are removed after 12 months, or sooner on an erasure request.
- Calendar-sync and export logs
- 30 days and 180 days respectively.
- Encrypted database backups
- 30 days, or the newest 7 copies if that is longer.
- Booking management links
- Expire 30 days after they are issued, and the merchant can revoke every link for their store at any time.
Google user data
When a merchant connects a Google account, the app accesses their Google Calendar data for one purpose: running bookings. Concretely, it lists the account’s calendars so the merchant can pick which ones to use, creates and updates calendar events for bookings (including Google Meet links for virtual services), and reads events on the chosen calendars to know when staff are busy so those times can’t be double-booked. Calendar data is not used for advertising, is never sold, and is not read by humans except with the merchant’s explicit consent for support, or where required for security or by law. Disconnecting the calendar in the app or revoking access in the Google account ends this access. MySellStack Appointments’ use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We do not share, transfer, or disclose Google user data to anyone, with three narrow exceptions. First, the infrastructure providers that run this app process it on our instructions and on our servers’ behalf — Fly.io (application hosting), Supabase (database), and Tigris (encrypted backups), the same subprocessors listed above under “Who else receives it”. Second, we would disclose data where a law, regulation, or court order compels it. Third, if this business is ever merged or acquired, data would transfer to a successor bound by this policy, with prior notice posted on this page. Google user data is never shared with or sold to advertisers, data brokers, or analytics providers; OAuth tokens are held server-side only and are never exposed to shoppers, staff members, or other merchants.
Access and erasure
To see or delete the data held about a booking, contact the merchant you booked with: as the controller, they can raise the request through Shopify, which passes it to us. Erasure covers our live records, and we also clear the details out of the calendar events this app itself created in the merchant’s Google, Outlook or iCloud calendar, as far as that calendar’s connection still allows. Encrypted backups taken beforehand still contain the earlier data until they age out on the schedule above, and copies the merchant holds elsewhere — their Shopify orders, their own mailbox — remain theirs to delete.
How to reach us
Shoppers: contact the store you booked with. They are the controller of your data, and a request made to them reaches us through Shopify. Where the store has given us a contact address, it appears on the booking emails and pages this app sends.
Merchants, App Store reviewers and data-protection contacts: reach the operator of this app through the support contact on its Shopify App Store listing, which is the channel we monitor.
Security
All traffic is served over HTTPS. Calendar credentials and Shopify access tokens are encrypted before they are stored, and nightly database backups are encrypted with a separate key before they leave our servers. We hold no security certification and claim none.
Report a suspected vulnerability or incident through the support contact on this app’s Shopify App Store listing, marking it as a security report — it reaches the maintainer directly. There is no bounty programme. Please don’t test against a live store or access data that isn’t yours; a description and a proof of concept against your own development store is enough.