Privacy policy

Last Updated: July 20, 2026

This Privacy Policy explains how Shelash (the "Company", "we", "us", or "our") collects, uses, protects, and discloses your personal information when you visit our website at shelash.com, use the Shelash mobile application (the "App"), purchase products, create an account, communicate with us, or otherwise use our services (collectively, the "Services").

For purposes of this Privacy Policy, "you" and "your" means any individual who accesses or uses our Services, including customers, website visitors, App users, lash artists, beauty professionals, or any other individual whose information we process.

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your personal information as described below.

If you do not agree with this Privacy Policy, please do not access or use our Services.


Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, technology, legal requirements, or operational needs.

When we update this Privacy Policy, we will revise the "Last Updated" date and publish the updated version on our website and within our App where applicable.


How We Collect and Use Your Personal Information

We collect personal information from different sources depending on how you interact with Shelash.

We may collect information:

  • Directly from you

  • Automatically through your device or browser

  • Through third‑party service providers that support our Services

We use your information to:

  • Provide and improve our Services

  • Process and fulfill your orders

  • Manage your account

  • Provide customer support

  • Process payments

  • Deliver marketing communications

  • Send promotional offers and personalized recommendations

  • Provide loyalty program benefits

  • Display and manage product reviews

  • Improve App performance and user experience

  • Prevent fraud and protect our users


Personal Information We Collect

Information You Provide Directly

When you use our Services, you may provide us with:

Account Information – including name, email address, phone number, password, account login information, and profile information.

Order Information – including name, billing address, shipping address, phone number, email address, order history, purchased products, and payment confirmation information.

Customer Support Information – when you contact us through customer service channels (including QuickCEP or Willdesk), we may collect your messages, customer service conversations, attachments, or information you provide.

Review Information – when you submit product reviews through Judge.me Reviews, we may collect review content, photos or videos, rating information, and the display name associated with your review.

Mobile Application Information

When you use the Shelash mobile application, we may collect additional information including:

Device Information – such as device type, operating system, mobile device identifiers, App version, language settings, and network information.

App Usage Information – including pages viewed, products viewed, search activity, shopping behavior, App interaction data, crash reports, and performance information.

This information helps us improve App functionality, personalize your shopping experience, and provide better services.

Push Notifications

The Shelash App uses push notification services provided by OneSignal.

With your permission, we may send notifications including: order updates, shipping notifications, promotional offers, new product announcements, loyalty rewards, and special events.

You can disable push notifications at any time through your device settings.

Cookies and Tracking Technologies

We use cookies, pixels, SDKs, and similar technologies to improve your experience.

These technologies may collect: IP address, browser type, device information, website/App activity, shopping preferences, and marketing interaction data.

We use this information to: remember your preferences, analyze website and App performance, improve shopping experiences, provide personalized recommendations, and measure marketing effectiveness.

You may control cookies through your browser settings. However, disabling cookies may affect certain features of our Services.


Third‑Party Services and Service Providers

We work with trusted third‑party providers to operate and improve our Services. These providers process your information only for the services they provide to us.

A. Services Integrated Directly in the Client App

1. Google Firebase Analytics (Usage Analytics)

  • Provider: Google LLC

  • Purpose: To track App page views, searches, product browsing, add‑to‑cart, checkout, promotion effectiveness, and order conversions; to analyze product usage and shopping funnel.

  • Data Collected: Page/route names; search terms and result counts; product or variant IDs, names, prices, quantities, currencies, and categories; cart amounts; promotion IDs, names, placements, and discount codes; Firebase App ID, App Instance ID, OS platform; order numbers, amounts, taxes, shipping costs, and line items. The SDK may automatically collect: App instance identifier, App version, device model, OS version, language/region, IP address and coarse geolocation inferred from IP, network and performance information, session events, and automatic events like first open. The exact scope depends on Firebase SDK and console configuration.

  • Trigger: When the App starts and when you use relevant features.

  • Advertising Identifiers / Cross‑App Tracking: We do not read IDFA.

  • Third‑Party Privacy Policies: Google Privacy Policy · Firebase Data Processing


2. OneSignal (Push Notifications)

  • Provider: OneSignal, Inc.

  • Integration: Client SDK; iOS uses Apple Push Notification service (APNs), Android uses Firebase Cloud Messaging (FCM) as the push transport.

  • Purpose: To request and read notification permissions, create push subscriptions, send order/shipping notifications, handle notification clicks and in‑App deep‑links, and maintain push audience tags based on recent activity/purchase status.

  • Data Read or Transmitted: OneSignal push subscription ID; notification permission status; iOS/Android platform; OneSignal App ID; subscription enabled status; notification title, body, deeplink, and optional image/button payloads; click records. The SDK may automatically collect: push tokens, device and App technical information, IP address, timezone/language, SDK version, network information, delivery/open/click status, and device or subscription identifiers assigned by OneSignal. The exact scope depends on OneSignal console and SDK configuration.

  • Association with Logged‑in Users: The App does not call OneSignal login to transmit email or Shopify customer ID directly to OneSignal. The push subscription ID is linked to a user’s backend identity only when registered on our server during an authenticated request.

  • Permissions and Trigger: OneSignal initializes when the root layout loads. System notification permission is only requested after the user taps the authorization entry in the notification settings page. Authorized devices sync subscriptions on startup or session changes.

  • Features Not Used: The App code does not request location permissions or call the OneSignal Location API.

  • Your Controls: You may decline permission when first prompted, or turn off App notifications at any time in your system settings: iOS "Settings → Notifications" → Shelash; Android "Settings → Apps → Shelash → Notifications". After turning off notifications, you will no longer receive push messages. You can also adjust notification category preferences within the App. Operating system notification consent is not the same as full legal consent required for marketing communications under European law.

  • Third‑Party Privacy Policy: OneSignal Privacy Policy


3. Shopify (E‑commerce Platform)

  • Provider: Shopify Inc. and applicable Shopify affiliates

  • Integration: Client SDK, GraphQL API, Shelash server API, OAuth/Customer Account hosted pages, and Shopify Checkout hosted checkout interface. Shopify is the core e‑commerce platform for the App. Data necessary for order fulfillment, account services, and checkout – disabling processing will usually make those features unavailable.

  • Purpose: To display products and store content, search, create and manage carts, manage logged‑in accounts and addresses, checkout, payments, orders and fulfillment, and store user‑uploaded profile pictures.

  • Data Collected or Processed:

    • Product & usage data: search terms; browsed or interacted product/collection IDs, handles, variants, quantities, prices, currencies, inventory/store availability; country and language context.

    • Account & contact data: Shopify customer ID, name, email, phone, birthday/gender (if provided in App extensions), address, Customer Account token.

    • Cart & order data: Cart ID, line items, discount codes, buyer identity, shipping address, checkout URL, order number, amounts, taxes, shipping costs, payment status, and fulfillment status.

    • Payment data: You submit payment information in the Shopify Checkout or its payment provider interface. Shelash App and our backend do not store full credit card numbers; payment data is processed directly by Shopify and its payment providers.

    • Profile picture data: The image you select from your photo library is uploaded via our server to Shopify Files storage.

  • Trigger: When you browse, log in, shop, checkout, or update your profile.

  • Your Controls: Your account profile, addresses, and order information can be viewed, modified, or deleted in the App’s account settings or the Shopify Customer Account page. Your profile picture can be changed at any time from your profile page. To close your account, please contact customer support.

  • Third‑Party Privacy Policies: Shopify Consumer Privacy Policy · Shopify Privacy Controls


B. Functions Processed via Our Server (App Does Not Communicate Directly with External Services)

For these features, data is first sent to our server; our server then calls the external service. The App itself does not communicate directly with these services.

1. Email Notifications and Marketing Automation (Omnisend)

  • Integration: The App does not embed the Omnisend SDK. Our backend calls Omnisend Contacts API and Events API.

  • Purpose: Email subscription/unsubscription sync; marketing automation; add‑to‑cart and checkout‑start events for logged‑in users; App order creation/payment/fulfillment events.

  • Data Processed: Email, name, subscription status, cart, checkout URL, product and order information.

  • Trigger Limitations: Events are sent only for logged‑in users whose email we have; guest users do not generate Omnisend events.

  • Your Controls: The App already records marketing email consent/withdrawal and syncs opt‑in/opt‑out to Omnisend. Add‑to‑cart and checkout automations currently use "logged‑in and has email" as the technical condition; there is no separate Omnisend behavioral analytics switch. For the European market, please refer to actual email strategy and DPA to confirm consent or other legal basis.

  • Third‑Party Privacy Policy: Omnisend Privacy Policy


2. Product Reviews (Judge.me)

  • Data Path:

    • Viewing reviews: App → Shelash backend → Judge.me API.

    • Submitting reviews: App opens Judge.me HTTPS page → you interact directly with Judge.me.

  • Purpose: To display product ratings and reviews; to allow you to submit store reviews.

  • Data Sent by Our Server for Queries: Shopify product numeric ID, to match Judge.me products and retrieve reviews.

  • Data Displayed in App: Review ID, author display name, rating, title, body, creation date, and verified status (these are typically public or configured by us as displayable review content).

  • Data You Actively Submit: When you enter the Judge.me hosted page, Judge.me may process rating, review text, name, email, order/product associations, and automatically collected device, IP, Cookie information, etc. The actual fields depend on the page and Judge.me’s policies.

  • Trigger: When you view product reviews or open the Judge.me review page.

  • Your Controls: Viewing products does not require you to submit a review. Submitting a review is your active choice when you enter the third‑party page. To modify or delete a review you have submitted, please contact Judge.me or our customer support.

  • Third‑Party Privacy Policy: Judge.me Privacy Policy


3. Loyalty Points and Coupons (BON Loyalty)

  • Integration: The App does not embed the BON SDK. Our backend calls BON Loyalty GraphQL API.

  • Data Path: App → Shelash backend (using login token to identify Shopify customer) → BON Loyalty API.

  • Purpose: Create or match member profiles; display points/history/levels/referral codes/rewards; redeem coupons; sync birthday.

  • Customer Data Sent to BON: Shopify Customer ID, email, first name, last name, account enabled status, App status; birthday is synced when you save it.

  • Member Data Read or Generated: BON customer ID, points, total points, referral code, member level and progress, point history, rewards/coupons, redemption status, discount codes, and expiry dates.

  • Trigger Conditions: Only when a logged‑in user accesses membership, points, coupons, or redemption features. Birthday is synced only when you fill in, modify, and save it.

  • Your Controls: Membership features are only available to logged‑in users. Birthday is optional – you may update or clear it at any time.

  • Third‑Party Privacy Policy: BON Loyalty Privacy Policy


4. Live Chat Support (Willdesk)

  • Integration: In‑App WebView loads a launcher page hosted by Shelash backend, which then loads the static.willdesk.com script.

  • Purpose: To provide floating customer service entry, live chat, support conversations, and issue handling.

  • Data Explicitly Transmitted by Us: The App provides the WebView with only the launcher URL and injects UI style/switch communication scripts. Current code does not pass Shopify Customer ID, email, or access token as URL parameters or JavaScript messages to Willdesk.

  • Data Automatically Processed by the Page: IP address, User‑Agent, device/OS and network information, Cookies, DOM/local storage identifiers, page load and chat usage records. The exact fields depend on Willdesk scripts and merchant console configuration.

  • Data You Actively Submit: Chat messages, and any name, email, order information, problem description, images/files you voluntarily provide in the chat interface (if the current Willdesk interface supports such capabilities).

  • WebView Configuration: The WebView enables JavaScript, DOM Storage, shared cookies, and third‑party cookies.

  • Load Trigger: When the Willdesk launcher is enabled, the WebView loads as a root‑level component; explicit interaction begins when you expand the customer service window.

  • Your Controls: You may choose not to open or use customer service. For the European market, non‑essential Cookies or similar identifiers on the Willdesk page may require your consent before loading.

  • Third‑Party Privacy Policy: Willdesk Privacy Policy


5. Profile Picture Selection / Photo Library Access (expo‑image‑picker)

  • Integration: The App uses expo‑image‑picker (the system’s native image picker module); we do not upload selected images to Expo.

  • Purpose: To allow you to choose a profile picture from your system photo library.

  • Data Accessed: System photo library permission status; the single image you explicitly select; image URI, file name, MIME type, and necessary metadata (file size, etc.).

  • Subsequent Transmission: The selected image is uploaded via our Shelash backend to Shopify Files. The image picker module itself does not upload the image to any Expo service in our project code.

  • Permissions: iOS photo library permission; Android uses system image picker capability. Our Android manifest explicitly removes camera, audio recording, and legacy external storage permissions; this feature does not take photos or record audio.

  • Your Controls: You may decline photo permission, cancel selection, or revoke permission in your system settings. Declining only affects profile picture updates.


Summary of Service Providers



Provider Purpose Privacy Policy
Shopify E‑commerce, order processing, account management Shopify Privacy Policy
QuickCEP Customer communication and support QuickCEP Privacy Policy
Willdesk Live chat support Willdesk Privacy Policy
Omnisend Email marketing and automation Omnisend Privacy Policy
BON Loyalty Loyalty points and rewards BON Loyalty Privacy Policy
Judge.me Product reviews Judge.me Privacy Policy
Google Firebase App usage analytics Google Privacy Policy · Firebase Data Processing
OneSignal Push notifications OneSignal Privacy Policy
Hidepay Payment and checkout support Handled directly by Shopify and payment providers

How We Use Your Personal Information

Providing Products and Services

We use your information to: process orders, deliver products, manage accounts, provide customer support, handle returns and exchanges, and provide loyalty benefits.

Marketing and Advertising

We may use your information to send: promotional emails, App push notifications, special offers, product recommendations, and event announcements. You can manage your communication preferences at any time.

Security and Fraud Prevention

We use personal information to: detect suspicious activity, prevent fraud, protect accounts, and maintain platform security.


How We Share Your Information

We may share personal information with:

  • Service providers that support our business operations

  • Payment processors

  • Shipping and fulfillment partners

  • Customer support providers

  • Marketing platforms

  • Analytics providers

  • Legal authorities when required by law

We do not sell your personal information.


User Reviews and Public Content

If you submit reviews, photos, or other content through our Services, that information may become publicly visible.

Please carefully consider what information you choose to share publicly.


Account Deletion

You may request deletion of your Shelash account and associated personal information.

To request account deletion, email us at: support@shelash.com

After verifying your request, we will delete or anonymize your personal information unless retention is required by law or necessary for legitimate business purposes.


Children's Privacy

Our Services are not intended for children under 13 years old.

We do not knowingly collect personal information from children.

If you believe a child has provided personal information to us, please contact us and we will take appropriate steps to remove such information.


Data Security

We use reasonable technical and organizational measures to protect your personal information.

However, no online transmission or storage system can be guaranteed to be completely secure.


Your Privacy Rights

Depending on your location, you may have rights including:

  • Right to Access – request access to personal information we hold about you.

  • Right to Delete – request deletion of your personal information.

  • Right to Correct – request correction of inaccurate information.

  • Right to Data Portability – request a copy of your information.

  • Right to Withdraw Consent – withdraw permission for certain data processing activities.

Marketing Preferences

You may unsubscribe from marketing emails or disable push notifications at any time.


International Data Transfers

Your information may be processed and stored in countries outside your country of residence, including the United States.

We take reasonable steps to ensure your information receives appropriate protection.


Third‑Party Links

Our Services may contain links to third‑party websites or services.

We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies before providing personal information.


Summary of Your Controls

Control How to Exercise
Push notifications Turn off notification permission in system settings; adjust category preferences within the App
Photo library access Revoke permission in system settings
Marketing emails Click the unsubscribe link in any email; manage preferences within the App
Account and order data View, modify, or delete in App account settings
Profile picture Change it at any time from your profile page
Birthday information Optional – fill in, update, or clear at any time in the App
Reviews Contact Judge.me or customer support to request modification or deletion
Account deletion Send a request to support@shelash.com

Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:

Shelash

Address:  3315 Broad River Rd Suite 20, Columbia, SC 29210

Email: support@shelash.com

Phone: +1 803 240 1313


Important Notice

This Privacy Policy is based on the actual integration of Shelash App v0.2.5. It does not replace formal legal advice regarding GDPR, UK GDPR, ePrivacy, CCPA/CPRA, or other applicable laws. The actual infrastructure, automatically collected fields, retention periods, and cross‑border transfer arrangements of third parties are governed by their respective latest privacy policies, data processing agreements, and console configurations.