MySellStack Appointments

Privacy policy

How this app handles personal data — what it holds, who receives it, how long it is kept, and how to reach us. Last updated 14 August 2026.

Privacy and data handling

The merchant you booked with is the controller of your personal data. MySellStack Appointments processes it on their behalf, and only to run their bookings. We do not sell personal data, do not use it for advertising, and do not use one merchant’s data to serve another.

What we hold

From shoppers: the name, email address and phone number entered in the booking form, any answers to the questions the merchant asks, the appointment itself, and — for paid bookings — the related Shopify order. From merchants: store and staff details, the credentials needed to sync their calendar, and which subscription plan the store is on. Payments are handled by Shopify — customer checkout and app subscriptions alike; we never see card details. We set no advertising or analytics cookies.

Who else receives it

Shopify
Store platform, checkout and app proxy; bookings are written back to the merchant's orders. Booking pages also load a font from Shopify's CDN, which sees the visitor's IP address.
Fly.io
Application hosting (primary region London, UK) and logs.
Supabase
Managed PostgreSQL — the primary database.
Tigris
Object storage for nightly database backups, encrypted before they leave our servers.
Resend
Sends booking confirmations, reminders and cancellations.
Google, Microsoft, Apple
Calendar sync and meeting links, for merchants who connect Google Calendar, Outlook or iCloud.
Nager.Date
Public-holiday dates by country. Receives no personal data.

How long we keep it

Bookings and intake answers
Kept while the merchant's store uses the app. An erasure request strips the personal details out of the booking; uninstalling the app deletes the store's records outright.
Unfinished booking attempts
The details entered before checkout are deleted 30 days after the reservation lapses.
Email delivery records
The delivery status is kept for the merchant's history; the recipient address and the subject line are removed after 12 months, or sooner on an erasure request.
Calendar-sync and export logs
30 days and 180 days respectively.
Encrypted database backups
30 days, or the newest 7 copies if that is longer.
Booking management links
Expire 30 days after they are issued, and the merchant can revoke every link for their store at any time.

Access and erasure

To see or delete the data held about a booking, contact the merchant you booked with: as the controller, they can raise the request through Shopify, which passes it to us. Erasure covers our live records, and we also clear the details out of the calendar events this app itself created in the merchant’s Google, Outlook or iCloud calendar, as far as that calendar’s connection still allows. Encrypted backups taken beforehand still contain the earlier data until they age out on the schedule above, and copies the merchant holds elsewhere — their Shopify orders, their own mailbox — remain theirs to delete.

How to reach us

Shoppers: contact the store you booked with. They are the controller of your data, and a request made to them reaches us through Shopify. Where the store has given us a contact address, it appears on the booking emails and pages this app sends.

Merchants, App Store reviewers and data-protection contacts: reach the operator of this app through the support contact on its Shopify App Store listing, which is the channel we monitor.

Security

All traffic is served over HTTPS. Calendar credentials and Shopify access tokens are encrypted before they are stored, and nightly database backups are encrypted with a separate key before they leave our servers. We hold no security certification and claim none.

Report a suspected vulnerability or incident through the support contact on this app’s Shopify App Store listing, marking it as a security report — it reaches the maintainer directly. There is no bounty programme. Please don’t test against a live store or access data that isn’t yours; a description and a proof of concept against your own development store is enough.