Last updated: 28 July 2026
This privacy policy explains how MB "Bit by bit developers" ("we", "us", "Company") collects, uses, and protects personal information through the 3D Bits application ("App"), available on the Shopify App Store.
The 3D Bits app enables Shopify merchants to add interactive 3D product viewers and parametric configurators to their storefronts. This privacy policy describes what data we access, why we need it, how we store it, and with whom we share it.
For questions about our broader platform privacy practices, see our Platform Privacy Policy.
Data Collected: Name, email address, phone number, and physical address.
Purpose: To ensure effective communication between the store owner and the app developer and to administer our taxes.
Storage: Your store domain and, for admin login sessions, your name and email address are stored in our app's database as part of the authentication session Shopify creates when you use the App. Other store owner contact details remain within Shopify. We reserve the right to use this information for tax purposes in our accounting documents.
Sharing: If the private information of the store owner lands on the invoice produced by Shopify, we may share this information with our accounting firm "UAB Justicija". Apart from that, we do not share this information with third parties unless required by law.
Data Collected: None.
Purpose: The App requests the write_content scope so it can manage the metafield definitions your products need. Shopify treats that scope as also covering store content such as blog posts, pages and their comments, and a comment can carry its author's email address and IP address.
Storage: The App never requests, reads, receives or stores any of that content. It queries no articles, pages or comments, so no content-provider email address or IP address ever reaches us. Nothing of this kind exists in the 3D Bits database.
Sharing: There is nothing here for us to share.
Data Collected: The 3D projects you create in the App - project names and settings, work-in-progress drafts, published version history (scene configurations and scripts), and records of the assets you upload (file names, file types, sizes, and links to the files in your store).
Purpose: To save your work between sessions, keep version history of your published projects, and publish 3D experiences to your products.
Storage: Stored in our app's database. The uploaded asset files themselves are stored in your own store on Shopify's CDN (Content → Files), not on our servers.
Sharing: We do not share your project content with other merchants or third parties, except as required by law.
Deletion: Your project content is deleted when Shopify sends us the shop data erasure request, approximately 48 hours after you uninstall the App - unless you reinstall within that window, in which case it is preserved. Files in your store's Content → Files section and metafields on your products remain under your control and are not deleted by us.
Data Collected: None stored.
3D rendering and price calculation happen entirely in customers' browsers - no customer data is sent to our servers by the storefront.
Order review. The App includes an order review screen that helps you check what your configured orders collected. While you have that screen open, the App reads your recent orders from Shopify - line items, quantities, amounts, and the configuration recorded on each configured line - recomputes what those lines should have cost, and shows you the result.
Customer uploads. If a merchant enables a file-upload option in a configurator (for example to personalise an engraving or a printed decal), the image a customer uploads is stored in that merchant's own Shopify store, in their Content → Files section, and is attached to the resulting order so the merchant can produce the item. Such an image may itself contain personal information, depending on what the customer chooses to upload. These files never reach our servers, and we cannot access or delete them - only the merchant can, in their Shopify admin. The merchant is the data controller for that content.
Storage in the customer's own browser. So that a customer can reopen and adjust a configuration they are working on, the storefront may keep their uploaded image and a link back to their configuration in their own browser's local storage. This is functional only, stays on their device, is never transmitted to us, and is not used to identify, profile, or track anyone.
Tracking: The 3D Bits app does not track or log user actions on the store, and sets no advertising or analytics cookies. The storefront runtime does use your customer's own browser storage for functional purposes only - for example keeping an uploaded image available so a customer can reopen and adjust their configuration. That data stays in their browser, is never sent to our servers, and is not used to identify or profile anyone.
App Scopes: Our application uses the following Shopify scopes:
write_content and write_products - to create and manage the product metafields and metafield definitions our theme app extension reads, and to create the hidden helper products that configurator pricing charges through.write_files - to store the assets you upload and your published project files in your own store's Content → Files section (Shopify CDN).read_themes - to check whether the 3D Bits app embed is enabled in your theme and to locate existing 3D Bits blocks. We only read theme information; we never modify your theme code.write_publications - to publish the hidden helper products configurator pricing creates to your Online Store channel, so they can be added to a cart.read_markets - to read your Shopify Markets and their price lists, so price units can be given an exact price in each currency you sell in.write_cart_transforms and write_validations - to install the two checkout functions that present configured products as one cart line and prevent a configured order completing at the wrong price. These run on Shopify's own infrastructure; we do not see your checkouts.read_orders - to power the order review screen described above. Read on demand, no customer fields, nothing stored.We retain store owner information only for as long as the App is installed on your Shopify store and for any additional period required by applicable tax and accounting laws. Upon uninstallation, we delete your login session data immediately, and your remaining data (including project content) is deleted when Shopify sends us the shop data erasure request, approximately 48 hours later. In all cases, app-specific data is removed from our systems within 30 days of uninstallation, except where retention is required by law.
We keep the App deliberately narrow: the great majority of your data stays inside your own Shopify store rather than with us. Where we do process data, we rely on a small number of third-party providers, in these categories:
We name categories rather than individual providers here: keeping the specifics of our infrastructure out of a public document is part of how we keep it secure. Merchants who need the specific list - for their own records, a vendor assessment, or a data processing agreement - can request it at info@bitbybit.dev and we will provide it.
Where your data is processed. We are established in Lithuania. Some of our providers may process data outside the European Economic Area. Where that happens, the data is protected either by a European Commission adequacy decision for that country, or by the European Commission's standard data protection clauses agreed with the provider. You can request a copy of those safeguards at info@bitbybit.dev.
We use commercially reasonable measures to protect any personal information we access, including encryption in transit and access controls on our systems. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at info@bitbybit.dev.
If you are a shopper rather than a store owner: we do not hold your personal information, and we have no relationship with you. The store you purchased from is the data controller for your order and for anything you uploaded while personalising a product. Please contact that store directly. If they pass a request to us through Shopify, we respond to it as described below.
Requests received through Shopify. We implement Shopify's mandatory privacy webhooks. When a store or a shopper submits a customer data request or an erasure request, Shopify notifies us and we respond. Because we do not store data about a store's customers, there is no customer record for us to return or erase; merchant and project data is deleted as described under Data Retention.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage users to review this page periodically for any changes. Changes are effective immediately after they are posted.
If you have any questions about this Privacy Policy, please contact us at info@bitbybit.dev.
If you want to learn more about Shopify's privacy practices, please visit the Shopify Privacy Policy.
MB "Bit by bit developers" Volungės g. 5-1, Vilnius LT-10315, Lithuania