
Last updated: April 2026. This Privacy Policy explains how personal data may be collected, used, shared, protected and retained when a customer visits the Mistglide store, views products, uses the cart, completes Shopify checkout, contacts support, receives order communications, requests a return or interacts with marketing and analytics tools.
By using the store, the visitor or customer acknowledges that personal data may be processed as described in this policy. If a visitor does not agree, they should not use the store or submit personal data.
For theme-level public pages, no private company address, personal address, private phone number or internal registration detail is published. Privacy requests should be sent through the contact page linked in the footer. When the request concerns an order, the customer should include the order number and checkout email so the request can be verified.
The store may process information provided directly by the customer, including name, email address, phone number where supplied, billing address, shipping address, order number, selected products, selected colors, cart contents, customer messages, return reasons, photos or videos submitted for support, review content where enabled, marketing preferences and consent choices.
Shopify checkout and enabled payment providers process payment information. The theme does not store full payment card numbers. The store may receive payment status, fraud risk signals, transaction references, partial card details where provided by the payment provider, refund status, chargeback information and order totals needed to process purchases and refunds.
When a visitor browses the store, technical and usage data may be collected, including IP address, approximate location, device type, browser, operating system, screen size, language, country or market selection, pages viewed, clicks, cart actions, products viewed, referring source, session events, cookie identifiers, consent status and security logs.
Cookies, pixels, web beacons and similar technologies may be used for essential store functions such as cart persistence, checkout, language and country selection, security, fraud prevention and session management. Optional analytics or advertising cookies depend on tools enabled on the store and on the consent choices available to the visitor. Browser settings may also allow cookies to be blocked or deleted.
The store may receive information from Shopify, payment processors, delivery providers, fulfilment partners, analytics providers, fraud-prevention services, review tools, email platforms, advertising platforms and support tools. This can include payment status, delivery status, tracking events, risk signals, campaign interactions and aggregated performance data.
Personal data may be used to display the store, operate localization, maintain the cart, process checkout, accept payment, prepare orders, ship products, send order confirmations, provide tracking, respond to support, manage returns and refunds, prevent fraud, protect the store, comply with accounting, tax, consumer and product-safety obligations, improve website performance and send marketing where a valid legal basis exists.
Depending on the context, processing may be based on contractual necessity, steps requested before purchase, legal obligations, legitimate interests such as fraud prevention, support, store security and service improvement, or consent for non-essential cookies, marketing communications and certain advertising activities. Consent can be withdrawn where processing depends on consent.
Data may be shared with service providers necessary to operate the store, including Shopify, payment providers, shipping carriers, fulfilment partners, email tools, customer support tools, hosting providers, analytics tools, advertising platforms, fraud-prevention providers, tax or accounting tools and legal or compliance advisers where necessary. Providers should process data only for the relevant service or lawful purpose.
Because ecommerce infrastructure and service providers may operate internationally, data may be processed outside the customer’s country. Where applicable law requires safeguards, appropriate mechanisms may be used, such as adequacy decisions, standard contractual clauses, provider data-processing terms or other recognized transfer tools.
Order, refund, payment, tax and accounting records may be retained for the period required by law. Support messages may be kept as long as reasonably necessary to resolve requests, maintain service history, defend legal claims and prevent fraud or abuse. Marketing data is retained until consent is withdrawn, the customer unsubscribes or the data is no longer needed. Technical logs are usually retained for shorter security and troubleshooting periods unless an incident requires longer retention.
Depending on applicable law, customers may have rights of access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority. These rights are not absolute: some records may need to be retained for accounting, tax, fulfilment, fraud prevention, legal claims or consumer-law obligations. Requests should be submitted through the contact page and may require identity verification.
Customers may opt out of marketing communications through available unsubscribe links, account preferences where available or by contacting support. Service messages such as order confirmations, delivery updates, refund information, legal notices and security communications may still be sent where necessary.
Appropriate technical and organizational measures are used to protect personal data, including Shopify-hosted checkout, encrypted transmission where applicable, access controls, provider security measures and fraud-prevention tools. No transmission or storage method is perfectly secure. Customers should use accurate contact details, keep email accounts secure and report suspicious order or payment messages.
The store is intended for adults or persons who have the legal capacity to purchase in their jurisdiction. The store does not knowingly seek to collect personal data from children. If a parent or guardian believes a child has submitted personal data, they should contact support so the request can be reviewed.
The store may contain links or integrations involving third-party services. This privacy policy does not govern third-party websites or services that are not controlled by the store. Visitors should review the policies of any third-party service they use.
This policy may be updated when store operations, Shopify features, service providers, legal requirements or data practices change. The version displayed on the store applies from the date shown above.