Privacy Policy
Last updated 10 September 2026. This policy covers two separate things: this website, rubikcombinedlistings.com, and the Rubik Combined Listings app on the Shopify App Store. They collect different data, so they are described separately.
Who we are
Both are operated by CraftShift, a company registered in the Netherlands. You can reach us at [email protected] about anything in this policy, including a request to see, correct or delete data we hold.
This website
This site is a marketing and documentation site. It has no accounts, no shopping cart and no forms that collect personal data.
- No advertising or analytics trackers. We do not run Google Analytics, an advertising pixel or any cross-site tracker here, which is why there is no cookie banner: there is nothing to consent to.
- Server logs. Our web server records the usual request log: IP address, the page requested, the time, the browser’s user agent string and the referring page. These are kept for a short period for security and debugging, and are not used to build a profile of you.
- Content delivery. The site sits behind Cloudflare, which terminates the connection and may set a strictly necessary cookie to protect against attacks. Fonts are loaded from Google Fonts, which means Google receives the request for the font file, including your IP address.
- Embedded video. The videos on our tutorials page load nothing from YouTube until you press play. If you do press play, YouTube’s privacy policy then applies to that player. We use the no-cookie player domain.
- Outbound links. Links to the Shopify App Store carry a campaign parameter so we can tell which page sent a visitor. That parameter identifies the page, not you.
The Shopify app
The app runs inside your Shopify admin and is installed by you, the merchant. Shoppers on your storefront never interact with it directly, and it does not identify them.
What it stores about your shop
- Your myshopify domain, the contact email Shopify gives us, your Shopify plan, your country and your install date. This is what lets us support you and bill correctly.
- The product groups you build: which products are in them, the option name and values you chose, and the swatch colours or images assigned.
- Your app settings: the swatch styling, the sorting and sold out rules, and your translations.
- Counts of swatch clicks on your storefront, aggregated by product, group, device type and position. These are counts, not visitor records: no shopper identifier, IP address or session is stored.
What it does not store
- No customer or order data. The app asks Shopify for five permissions and no more: read and write products, read themes, and write metaobjects and their definitions. Customers, orders and payments are not among them, so that data never reaches us.
- No payment details. Billing is handled entirely by Shopify and appears on your Shopify invoice; we never see a card.
- No copies of your product images. Images are referenced by their Shopify URL and served from Shopify’s own CDN.
The AI features
Magic Fill and the visual assistant send the product image URL and the product title to OpenAI, which reads the image and returns an option value and a colour. Nothing about your shop’s identity, your customers or your orders is sent. OpenAI processes this through its API, which is not used to train its models. If you never press those buttons, nothing is sent to OpenAI at all.
Sub-processors
These are the third parties that process data on our behalf. Each does one job:
- Our hosting provider, which runs the servers the app’s admin interface and API are served from. Ask us and we will name the current one.
- OpenAI, for the AI features described above, and only when you use them.
- Resend, for the emails we send you, such as install and plan notices.
- Sentry, for error reports. An error report carries your shop domain so we can find the shop it happened on.
- Crisp, for the support chat inside the app.
- Shopify itself, which is the source of most of the data above and the processor of all billing.
How long we keep it
Your groups and settings are kept while the app is installed, so that reinstalling does not lose your work, and for a period afterwards for the same reason. Ask us at any time and we will delete them sooner. Server logs and error reports are kept for a short period and then rotate away on their own.
Your rights
If you are in the EU, the UK or another region with comparable law, you can ask us for a copy of the data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to [email protected] from the email address on the shop and we will answer within thirty days. You also have the right to complain to your local data protection authority.
Changes to this policy
When this policy changes in a way that matters, the date at the top changes and merchants on a paid plan are emailed. Small corrections are made without notice.