Barcode Genie — Privacy & Data Protection
Last updated: 2026-07-13
Barcode Genie scans variable-measure (price/weight-embedded) barcode labels into Shopify POS. This policy describes exactly what data the app processes, why, and how it is protected.
What we process, and why
| Data | Source | Purpose |
|---|---|---|
| Scan records (barcode digits, parsed PLU/amounts, timestamps) | POS scans by your staff | Resolving each scan, pricing, audit trail, troubleshooting |
| Product/variant data (titles, SKUs, prices, app metafields) | Your Shopify catalog | Matching scale PLUs to products; readiness checks |
| Order line records (order/line IDs, amounts, discounts, taxes, location) | Shopify order webhooks | Your sales reports, cost/margin estimates, refund handling |
| Inventory quantities and adjustments | Shopify inventory API | Fractional-weight inventory reconciliation you enable in settings |
| Staff member ID and POS device ID | Shopify POS session | Attributing scans in your reports; support diagnostics |
What we deliberately do not collect
- No customer identity data. The app does not request access to customer names, emails, phone numbers, or addresses; Shopify redacts these from the data we receive.
- No payment or card data. No browsing/behavioral tracking. No marketing profiles.
Data minimization and use limitation
We process the minimum needed for the features above and use it for nothing else. Data is never sold, rented, shared with third parties, or used for advertising or automated decision-making about people.
Storage, security, and retention
- All data is transmitted over TLS (HTTPS).
- Production data is stored in a managed database encrypted at rest, isolated per shop.
- Access tokens and secrets are never written to logs; operational logs are redacted.
- Retention: records are kept only while the app is installed on your store. On uninstall, volatile data is purged immediately and all remaining shop data is permanently deleted when Shopify issues the post-uninstall redaction request (approximately 48 hours later).
Privacy requests
The app implements Shopify's mandatory privacy webhooks: customer data requests, customer redaction, and shop redaction are honored automatically. Because no customer identity data is stored, customer-level requests typically have nothing to return or erase; each request is logged for accountability.
Sub-processors
Hosting and database providers for the production deployment. No other sub-processors.
Contact
Questions or requests: the support contact listed on the app's Shopify listing.