1. Introduction
CircleHalo ("CircleHalo," "Company," "we," or "us") provides a software-as-a-service (SaaS) platform that helps sellers of personalized and made-to-order products manage, monitor, and fulfill eCommerce orders (the "Services").
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in connection with our Services. It applies to all users, visitors, and customers who access CircleHalo's websites, applications, or connected integrations (collectively, the "Software").
By using our Services, you acknowledge and agree to this Privacy Policy. If you do not agree, you should discontinue use of the Services.
2. Scope, Roles, and Responsibility
(a) Scope of policy
This Privacy Policy applies to the following data categories:
- User Data: Information collected directly from you when you create an account, subscribe, or interact with us.
- Order Data: Data imported from third-party platforms you connect, such as Etsy, Amazon, or Shopify, for order management.
- Payment Data: Payment and billing information processed through our merchant-of-record provider, Paddle.
- This Privacy Policy does not govern the privacy practices of third parties such as Etsy, Amazon, Shopify, or Paddle. Those providers maintain their own privacy policies and data practices.
(b) Data controller and processor roles
For the purposes of the General Data Protection Regulation (GDPR) and similar privacy laws, CircleHalo and our customers may have different responsibilities depending on the data involved.
- You (our customer or seller) are the Data Controller for the personal data of your end customers that is imported into the Services. You determine the purposes and means of processing that data.
- CircleHalo acts as the Data Processor for that Order Data and processes it only on your instructions in order to provide the Services, including importing, unpacking, and displaying data for fulfillment.
When you connect your Shopify store to CircleHalo:
- You (the merchant) are the Data Controller for all customer order data imported from your Shopify store.
- CircleHalo acts as a Data Processor for Shopify order data and processes it solely to provide order management and fulfillment services.
- Shopify Inc. maintains its own privacy policy and data practices for data stored on Shopify's platform.
When you connect your Etsy shop to CircleHalo:
- You (the Etsy seller) are the Data Controller for all Etsy Member personal information accessed through the Etsy API.
- CircleHalo acts as a service provider to you and processes Etsy Member personal information only to fulfill the services provided under our application terms with you.
- Etsy, Inc. maintains its own privacy policy and data practices for data stored on Etsy's platform.
(c) Etsy notice
The term "Etsy" is a trademark of Etsy, Inc. This Application uses Etsy's API, but is not endorsed or certified by Etsy.
3. Data We Collect
We collect information that is necessary to provide, maintain, secure, and improve our Services.
(a) Information you provide directly (User Data)
- Account Data: Name, email address, password, phone number, company details, and business identification information.
- Billing Data: Payment details and billing address processed securely by Paddle as our Merchant of Record.
- Communications: Support requests, survey responses, platform feedback, and other correspondence.
(b) Information from connected platforms (Order Data)
When you connect CircleHalo to your eCommerce accounts such as Etsy, Amazon, or Shopify, we collect personal data related to your sales and fulfillment workflows.
- Authentication Data: API tokens or credentials required for secure, ongoing synchronization.
- Order Details: Order IDs, customer names, shipping addresses, personalization requests, and files, including ZIP files, containing design or order information.
- Product Data: Listing details and inventory information required for effective order management.
Etsy integration
- Etsy API credentials, including API keys and access tokens, required for secure API access to your Etsy shop through Etsy's official API.
- Order data such as buyer names, email addresses, shipping addresses, order items, transaction details, and order metadata.
- Listing data such as product listings, inventory information, and shop details.
- Etsy Member personal information accessed solely through the Etsy API for order management and fulfillment.
Shopify integration
- OAuth access tokens and API credentials required for secure API access to your Shopify store through Shopify's GraphQL Admin API (version 2026-01).
- Order data including customer names, email addresses, shipping addresses, billing addresses, order items, fulfillment status, and order metadata.
- Product data including product listings, variants, and inventory information.
- Customer data from orders, including personalization requests and custom attributes.
- Webhook data including order events such as create, update, cancel, and fulfill, along with app lifecycle events such as install and uninstall.
- GDPR compliance webhook data, including customer data requests, customer deletion requests, and shop deletion requests, as required by Shopify App Store requirements.
(c) Automatically collected data
- Device and Connection Data: IP address, operating system, device identifiers, browser type, and time zone.
- Usage Data: Login timestamps, activity logs, performance metrics, pages viewed, and feature interactions.
- Tracking Technologies: Data collected via cookies, pixels, and similar technologies used to authenticate sessions, analyze platform usage, and improve security.
4. How We Use Data
We process personal data only for legitimate and clearly defined service-related purposes.
- Service Delivery: To provide, operate, and maintain the Services you subscribe to.
- Order Management: To import, unpack, and display Order Data for fulfillment as your processor.
- Billing and Payments: To process subscriptions and generate invoices through Paddle.
- Account Security and Support: To create, secure, and maintain your user account and respond to inquiries.
- Analytics and Improvements: To analyze platform performance, enhance features, and monitor usage patterns.
- Compliance and Legal: To comply with tax, legal, and regulatory requirements.
Etsy-specific processing
- Synchronize order data from your Etsy shop to support order management and fulfillment workflows.
- Display Etsy listing content that is no more than six (6) hours older than the corresponding information on the Etsy site.
- Display other Etsy content that is no more than twenty-four (24) hours older than the content displayed on the Etsy site.
- Maintain secure API connections using credentials required for ongoing synchronization.
- Cache and store Etsy content only as long as reasonably necessary to provide service to your account.
Shopify-specific processing
- Synchronize order data from your Shopify store to support order management and fulfillment workflows.
- Process GDPR compliance requests, including data export, customer deletion, and shop deletion, within required timeframes.
- Maintain secure API connections using OAuth tokens for ongoing synchronization.
- Process webhook events to keep order data current and accurate.
- Comply with Shopify App Store requirements, including mandatory GDPR webhook handling.
We do not sell personal data and we do not use customer order data for advertising or marketing unrelated to the Services. We also do not use Etsy order data for advertising, third-party marketing, resale, profiling, licensing, or for training artificial intelligence or machine learning models.
5. Legal Basis for Processing (GDPR)
If you are located in the EU, EEA, or UK, our legal bases for processing personal data include:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary to provide the Services and maintain your account.
- Compliance with a Legal Obligation (Art. 6(1)(c) GDPR): Processing required for tax, billing, security, or regulatory requirements.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing to improve the Services, prevent fraud, and protect platform security where our interests are not overridden by your rights.
- Consent (Art. 6(1)(a) GDPR): Processing based on your consent where applicable, including optional marketing communications.
6. Data Sharing and Disclosure
We disclose personal data only where necessary to operate the Services, comply with law, or complete a corporate transaction.
- Service Providers: Vendors that provide hosting, infrastructure, analytics, and platform support, under contractual confidentiality and security obligations.
- Payment Processing: Paddle processes billing and payment information as Merchant of Record. We do not store or process full credit card numbers ourselves.
- Connected Platforms: We exchange data with the marketplaces you explicitly connect, including Etsy, Amazon, and Shopify, solely to synchronize and manage orders.
- Corporate Transactions: Personal data may be transferred to a successor entity in connection with a merger, acquisition, financing, or asset sale.
- Legal Obligations: We may disclose data where required by law, subpoena, court order, or regulatory authority.
Etsy integration
- We exchange data with Etsy only through Etsy's official API and only to synchronize and display order information you choose to import for order management and fulfillment.
- We do not use Etsy order data for advertising, third-party marketing, resale, profiling, licensing, or for training artificial intelligence or machine learning models.
- Etsy API credentials are stored securely and used only to provide the Services.
- When you disconnect your Etsy shop, we delete associated API credentials and stop data synchronization.
- Etsy maintains its own privacy policy and data practices, which we recommend you review directly.
Shopify integration
- We exchange data with Shopify Inc. through their GraphQL Admin API (version 2026-01) and webhook system to synchronize orders and manage your store connection.
- OAuth tokens and API credentials are stored securely and used only to provide the Services.
- When you disconnect your Shopify store, we delete associated API credentials and stop data synchronization.
- We comply with Shopify's mandatory GDPR webhooks and process those requests within required timeframes.
- Shopify maintains its own privacy policy and data practices, which we recommend you review directly.
7. Cookies and Tracking
CircleHalo uses cookies and similar technologies for essential platform operations and service improvement.
- Strictly Necessary: To authenticate sessions and secure your account.
- Functionality: To remember preferences and improve the user experience.
- Analytics: To understand platform usage and monitor performance.
You may manage or disable cookies through your browser settings. Disabling strictly necessary cookies may limit important functionality of the Services. For additional detail, please refer to our separate Cookie Policy.
8. Data Retention
We retain personal data only for as long as necessary to provide the Services, comply with legal obligations, and resolve disputes.
- Account Data: Retained for as long as you maintain an active account.
- Order Data: Retained for as long as needed for your order fulfillment operations and your own legal obligations as Data Controller, typically tied to the life of your active account.
- Upon verified account deletion, personal data will be deleted or anonymized within 30 days, except where retention is legally required for tax, billing, or auditing purposes.
Etsy data
- Order data imported from Etsy is retained as long as your account remains active and the Etsy connection is maintained.
- Etsy listing content is displayed no more than six (6) hours older than the corresponding information on the Etsy site.
- Other Etsy content is displayed no more than twenty-four (24) hours older than the content displayed on the Etsy site.
- Etsy content is cached and stored only as long as reasonably necessary to provide service to your account.
- Upon disconnection of your Etsy shop, we delete API credentials immediately. Order data remains subject to our standard retention practices unless you request deletion.
Shopify data
- Order data imported from Shopify is retained as long as your account remains active and the Shopify connection is maintained.
- Upon disconnection of your Shopify store, we delete API credentials immediately. Order data remains subject to our standard retention practices unless you request deletion.
- When we receive a Shopify GDPR webhook for
shop/redact, all Shopify-related data will be deleted within 48 hours as required by Shopify App Store requirements. - Customer deletion requests received through
customers/redactwill be processed within 30 days, with personal information anonymized while preserving order records required for accounting purposes.
9. International Data Transfers
Your data may be transferred to and processed in jurisdictions outside your country, including the United States, the European Union, and Turkiye, where CircleHalo or our service providers operate.
Where required by law, especially for transfers outside the EU, EEA, or UK, we implement appropriate safeguards, including:
- Standard Contractual Clauses (SCCs): We use SCCs approved by the European Commission, and their UK equivalent, to support lawful data transfers.
- Encryption: We apply industry-standard encryption for data in transit and at rest.
By using the Services, you acknowledge and consent to the international transfer and processing of your data as described in this Privacy Policy.
10. Security Measures
We use industry-standard technical and organizational measures designed to protect personal data from unauthorized access, disclosure, alteration, or destruction.
- Encryption of data in transit using TLS/SSL and encryption of data at rest.
- Strict role-based access control for employees and service personnel.
- Secure servers, firewalls, and regular vulnerability monitoring.
- Routine security audits and backup procedures.
While we work to maintain a strong security posture, no internet-based system can guarantee absolute security.
Data breach notification
If any Etsy Member data accessed via the Etsy API is compromised or reasonably suspected to be compromised, we will promptly notify Etsy at [email protected] and the affected Etsy seller, and in no event later than 24 hours after discovery of the incident.
11. Your Privacy Rights
Depending on your location, you may have legal rights concerning your personal data.
(a) GDPR (EU/EEA and UK)
- Right to Access: To obtain confirmation about processing and receive a copy of your data.
- Right to Rectification: To correct inaccurate or incomplete data.
- Right to Erasure: To request deletion where data is no longer necessary for the purposes collected.
- Right to Restriction of Processing: To limit the way we use your data.
- Right to Data Portability: To receive your data in a structured, commonly used, machine-readable format.
- Right to Object: To object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: To withdraw consent at any time where processing is based on consent.
Etsy-specific rights
- You may request access to the data we have collected from your Etsy shop.
- You may request deletion of your Etsy connection and associated data at any time.
- You may export Etsy order data stored in your account.
- You retain control over the use, sharing, and access of Etsy Member information collected by our application.
Shopify-specific rights
- You may request access to the data we have collected from your Shopify store.
- You may request deletion of your Shopify connection and associated data at any time.
- If Shopify sends a GDPR deletion request on your behalf through a webhook, we will process it according to Shopify's requirements and notify you where appropriate.
- You may export Shopify order data stored in your account.
(b) CCPA/CPRA (California)
- Right to Know: To request the categories and specific pieces of personal data collected, used, and disclosed.
- Right to Delete: To request deletion of personal data we have collected, subject to legal exceptions.
- Right to Opt Out of Sale or Sharing: CircleHalo does not sell or share personal data for cross-context behavioral advertising.
- Right to Non-Discrimination: To exercise your rights without discriminatory treatment.
(c) KVKK (Turkiye)
- Right to Learn: Whether your personal data is being processed.
- Right to Request Information: About the purpose of processing and related details.
- Right to Correction or Deletion: To request correction or deletion where the grounds for processing no longer apply.
- Right to Object: To challenge outcomes produced by automated analysis that adversely affect you.
To exercise any of these rights, please contact us at [email protected].
12. Data Deletion Requests
You may request deletion of your CircleHalo account and associated personal data at any time.
To submit an account deletion request, please contact [email protected] with the subject line "Account Deletion Request" and include your registered email address. We will verify your identity before processing the request.
- Verified requests will be processed within 30 days of receipt.
- Certain data may be retained where required by tax, billing, or regulatory law, and we will explain that retention upon request.
Etsy shop disconnection
- You may disconnect your Etsy shop at any time through the CircleHalo interface.
- Upon disconnection, we immediately revoke API access and stop data synchronization.
- You may request complete deletion of Etsy-related data, which will be processed within 30 days.
Shopify store disconnection
- You may disconnect your Shopify store at any time through the CircleHalo interface.
- Upon disconnection, we immediately revoke API access and stop data synchronization.
- You may request complete deletion of Shopify-related data, which will be processed within 30 days.
- If Shopify sends a shop deletion webhook (
shop/redact), we will delete all associated data within 48 hours in line with Shopify App Store compliance requirements.
13. Children's Privacy
Our Services are intended for business use and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 18, we will take prompt steps to delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify you through our website, by email, or through platform notices. The revised version becomes effective as of the "Last Updated" date shown at the top of this page.
15. Contact Information
If you have questions, concerns, or would like to exercise your privacy rights, you can contact us using the details below.
CircleHalo
Email: [email protected]
Etsy-specific inquiries
For questions about our Etsy integration, data handling, or Etsy API compliance, please contact [email protected]. We process Etsy data solely through Etsy's official API and in compliance with Etsy's API Terms of Use.
Shopify-specific inquiries
For questions about our Shopify integration, data handling, or GDPR compliance related to Shopify data, please contact [email protected]. We process Shopify GDPR webhook requests automatically and respond to merchant inquiries within 30 days for customer requests and 48 hours for shop deletion requests.