Last updated: 29 August 2026
Privacy Policy
1. Who we are, and in what capacity
myDiagnostic is a Shopify application published by Webesencia.
Two different relationships exist, and the distinction decides your rights and who you should contact.
As a shopper, you interact with a quiz on a merchant's online store. The merchant decides to run that quiz, decides what it asks, and decides what to do with the answers. The merchant is the data controller. myDiagnostic is the data processor: we process what the quiz collects on the merchant's behalf and on their instructions, and we do not use it for our own purposes. If you want your data accessed, corrected or erased, the merchant is your first point of contact. You can also write to us at the address in section 9 and we will route your request to the merchant and act on their instruction.
As a merchant, you install myDiagnostic on your Shopify store. For your own account data (your shop domain, your plan, your app settings), we are the data controller.
2. What the app collects from shoppers
Only what the merchant's quiz is configured to ask, plus what is needed to produce and deliver a result. Concretely, per completed quiz:
| Data | When it is collected |
|---|---|
| Email address | Only if the merchant enabled the email gate, or added an email capture field |
| First name | Only if the merchant added a name capture field |
| Age | Only if the merchant added an age capture field |
| Any other capture field the merchant defined | Only if the merchant added it. The merchant chooses the label and the field type, so the content is under their control |
| The answers selected in the quiz | Always, for every completed quiz |
| The recommended products | Always, as the outcome of the quiz |
| Language of the session | Always, to render the result in the right language |
| Marketing consent, yes or no | Only if the merchant connected an email marketing service |
| A random result token | Always, so the result page can be reopened from its link |
| The date and time the quiz was completed | Always, and it is what the retention clock in section 4 counts from |
| Which editorial scenario the answers matched | Always, when the answers match one the merchant wrote |
What the app does not collect. We do not use advertising or analytics trackers, we do not build cross-site profiles, and we do not sell or share personal data with third parties for their own purposes. IP addresses are used transiently to rate-limit abusive traffic and are not stored in the database. We do not record whether a shopper went on to buy: the app has no order or cart tracking, and nothing links a quiz response to a purchase.
What we hold about the merchant, not the shopper. Installing the app makes Shopify issue us an access token, which we store so the app can read the merchant's products and manage the images they upload to the app, on their behalf. Shopify also gives us the identity of the staff account that installed or opened the app: name, email address, language and whether it is the store owner. We store the shop domain, the billing plan and its usage counters, an optional notification address, and, when a merchant connects their own mail server or email marketing service, the credentials for it, encrypted at rest.
Where the images go. Images uploaded from the app are sent to the file storage of the merchant's own Shopify store and registered in Shopify Files. They stay the merchant's property and remain available in their Shopify admin under Content, then Files. We keep no copy of them: the app stores only the Shopify URL of the image, which is what the quiz renders.
A capture field is free-form: a merchant can, in principle, ask for anything. Merchants are responsible for not asking for data they have no lawful basis to collect, and in particular for not asking for special-category data such as health information without meeting the additional conditions that requires.
3. Why we process it
- To produce the quiz result. The answers are scored against the merchant's configuration to select recommended products. This is the purpose of the app.
- To send the result by email, when the merchant enabled that and a shopper provided an address.
- To let a shopper reopen their result from the permanent link.
- To give merchants aggregate statistics about their quiz (how many responses, how many email addresses collected, which scenarios matched).
- To pass a shopper to the merchant's email marketing service, but only when the merchant connected one AND the shopper actively ticked the consent box. Consent is off by default and is never assumed.
4. How long we keep it
Quiz responses are automatically anonymised after 24 months by a scheduled job: the name, the email address, the age, the language, every capture field value and the detailed answers are erased, while the response itself, its quiz, its scenario, its recommended products and its date are kept, so the merchant's figures stay true.
When we handle a data-protection request we keep a record proving it was handled, for 12 months. That record holds a one-way hash of the email address, never the address itself, together with the store, the date, the outcome and how many entries were involved. It never holds the data the request was about: an access request is answered by sending the export to the merchant, and no copy of it is kept.
Merchant account data is kept for as long as the app is installed. Uninstalling the app resets the account to the free plan and removes the login sessions. Shopify then sends us a shop-deletion request 48 hours after the uninstall, and that erases the shop, its quizzes and every response attached to them.
Images uploaded from the app are not part of that erasure. They live in the merchant's Shopify file storage and not in ours, so they survive both the uninstall and the 48-hour deletion, and the merchant can remove them at any time from Content, then Files in their Shopify admin.
5. Who else processes it
We use the following sub-processors. Each one processes data only to provide its service to us.
| Sub-processor | Role | Where |
|---|---|---|
| Shopify | Hosts the merchant's store and delivers the app. Shopify is the source of the shop identity and the billing relationship | Per Shopify's own terms |
| Supabase | Managed PostgreSQL database holding quizzes, responses and settings | AWS eu-west-3 (Paris, France) |
| Fly.io | Runs the application itself | Primary region cdg (Paris, France) |
| Resend | Sends the result email and data-protection notifications | Resend is established in the United States; its sending infrastructure for our sending domain mydiagnostic.webesencia.com resolves to AWS eu-west-1 (Ireland) |
Optional, and only if the merchant turns them on:
| Sub-processor | Role |
|---|---|
| Klaviyo | Receives a shopper's email address and quiz result, only when the merchant connected Klaviyo and the shopper consented |
| Mailchimp | Same, for Mailchimp |
A merchant may also configure their own SMTP server, in which case result emails are sent through that server instead of Resend, and that server is under the merchant's control rather than ours.
Transfers outside the European Union. Resend is established in the United States, so sending a result email can involve a transfer of personal data there. That transfer is covered by the EU-U.S. Data Privacy Framework and by the European Commission's Standard Contractual Clauses. The database and the application itself stay in France, and a merchant who enables Klaviyo or Mailchimp contracts with that provider on their own terms.
A data processing agreement covering the shopper data we process for merchants is set out in section 11. It applies for as long as the app is installed and forms part of the Terms of Service.
6. Legal basis
For shopper data, the merchant is the controller and determines the legal basis. In practice it is normally their legitimate interest in recommending products, or your consent where the quiz asks for it. Sending your data to an email marketing service always relies on your consent, given by ticking the box, and never on anything else.
7. Your rights
Under the GDPR and comparable laws you can ask for access to your data, its correction, its erasure, a portable copy, and you can object to or restrict its processing.
Because the merchant is the controller for quiz data, address your request to the store you took the quiz on. Shopify also provides a standard channel: when a shopper asks a merchant for their data or for erasure, Shopify notifies us and we act within the deadline the regulation sets. We support both, automatically:
- Access: we assemble every response linked to that email address and hand it to the merchant to pass on to you.
- Erasure: we anonymise the matching responses. The statistical record that a quiz was completed remains, with nothing left that identifies anyone.
You also have the right to complain to your national data protection authority.
8. Security
Data in transit is encrypted (HTTPS everywhere). Credentials merchants give us for third-party services are encrypted at rest. Access to production systems is restricted to the people who operate the app. We log operational events, and personal data is reduced to a one-way hash before it reaches a log line.
9. Contact
Questions about this policy, or about data we hold as a processor, go to support@webesencia.com.
No Data Protection Officer has been appointed: our processing does not meet the conditions that make one mandatory. The address above is the point of contact for every data protection question.
10. Changes
We will update this page when the app's data handling changes, and we will change the date at the top. Material changes affecting shoppers will be communicated to merchants so they can inform their customers.
11. Data Processing Agreement
This section is the data processing agreement between the merchant and Webesencia for the shopper data the app handles. It applies for as long as the app is installed and forms part of the Terms of Service.
Roles. The merchant is the data controller for everything their quiz collects. Webesencia is the data processor and acts only on the merchant's instructions.
Instructions. Those instructions are given through the app itself: the questions asked, the capture fields defined, whether the email gate is on, and which integrations are connected. We process shopper data for no other purpose, and never for our own.
Sub-processors. We engage Supabase for the database, in region eu-west-3, Fly.io for hosting the application, and Resend for sending email. Section 5 lists them in full, together with the optional ones a merchant turns on, and this policy is updated before a new sub-processor starts processing.
Security measures. Data is encrypted in transit, access to production systems is restricted to the people who operate the app, and backups are encrypted. Section 8 describes this in more detail.
Deletion and retention. Shopper data is deleted when the merchant uninstalls the app, on the schedule Shopify sets, and quiz responses are anonymised after 24 months. Section 4 states both, and this section adds nothing to them.
Assistance. We answer access and erasure requests through the Shopify channel described in section 7, and we notify the merchant without undue delay of any personal data breach affecting their shoppers.