Privacy

What data
this app touches.

LightsOff generates night versions of your catalogue photos and adds a switch to your storefront. This document explains what information it needs to do that, where it goes and how long it stays.

Last updated: 31 August 2026

Company details still to be filled in. Everything this document says about how the app works is accurate and comes from the app's own code. What is missing are the company details, marked below in brackets.

1 · Who processes the data

The controller is [Legal name], with registered address at [address] and tax ID [Tax ID]. For anything about privacy: [email].

With respect to your shop's data, we act as a processor: you decide what is processed and we process it in order to provide you with the service.

2 · What permissions the app asks for, and why

When you install it, Shopify asks you to authorise these scopes:

PermissionWhat it is used for
read_products Read your products and the URLs of their photos, which are the input for generation.
write_products Write to your shop's metafields which night photo corresponds to which daytime one. That is what the storefront reads.
write_files Upload the generated night photos to your own shop's files.
read_orders Requested so that sales could be attributed to the visits that turned the lights off. It is not used today: that feature is switched off and the app reads no orders. See point 7.

3 · Your catalogue photos

To generate a night version, the app downloads the product photo and sends it to an artificial intelligence provider, which returns the generated image. That image is uploaded to your own shop's files: it is yours and it lives in your Shopify account, not in ours.

Our database only stores the record of what was generated: your shop domain, the URL of the original photo, the URL of the night version, its status and some technical details of the generation (prompt version, model and aspect ratio). No copy of the images is kept.

Catalogue photos do not usually contain personal data. If identifiable people appear in yours, bear in mind that they will be sent to the AI provider like any other photo.

4 · Storefront analytics

When somebody presses the switch in your shop, the app records the fact so that it can tell you whether this sells. What is stored for each event is this and nothing else:

What is NOT stored, which is the part that matters:

The session identifier is a random number stored in the browser's sessionStorage and it is deleted when the tab is closed. It is not a cookie, it does not survive the visit and it cannot recognise anybody from one day to the next. It exists only so that somebody who presses five times is not counted five times.

5 · Who it is shared with

WhoWhat they receiveWhy
Shopify All of the above, because that is where your shop lives It is the platform the app runs on
[AI provider] The product photos being generated It is what produces the night version
[Hosting provider] The generation records and the analytics It is where the server and the database run

We do not sell data to anybody, nor do we share it for advertising purposes.

6 · How long it is kept and how it is deleted

The generation records and the analytics are kept for as long as you have the app installed. When you uninstall it, your shop's session is removed immediately and its data is deleted within [X] days.

The generated night photos are not deleted: they are in your shop's files and they are yours. If you want to remove them, you delete them from the Shopify admin itself.

You can ask us at any time to delete everything before that deadline.

7 · Your shop's customer data

The app does not process your customers' personal data. It does not read orders, it does not access customer records and it stores nothing that could identify whoever visits your storefront.

The read_orders scope appears during installation because it is intended to be used for attributing sales, but that feature is switched off and no order is read. If it is ever switched on, this document will be updated first and you will be told.

8 · Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to [email]. If you believe we are not handling your request properly, you can complain to the [relevant supervisory authority].

9 · Changes

If this changes, the date above is updated. If the change affects what data is processed or who it is shared with, we will tell you inside the app before it takes effect.