Effective date: 2026-08-12 Last updated: 2026-08-12
This Privacy Policy explains how ClassKit ("ClassKit", "we", "us", "our") collects, uses, discloses, retains, and protects personal data in connection with the ClassKit application (the "App"), which enables Shopify merchants to sell group class sessions on a repeating schedule and manages the resulting bookings.
It applies to personal data of (a) the merchants who install the App and (b) the merchants' customers whose orders create bookings.
References to "GDPR" include the EU General Data Protection Regulation and, as applicable, the UK GDPR and Data Protection Act 2018. References to "CCPA" include the California Consumer Privacy Act as amended by the CPRA.
We follow the principle of data minimization and process only the following:
| Category | Data elements | Source |
|---|---|---|
| Customer identifiers | Name (first, last), email address | Shopify order (orders/create) |
| Transaction data | Order ID, purchased session(s), quantity, line items, refund details | Shopify order/refund webhooks |
| Merchant account data | Shop domain, offline access token, plan/subscription status, sender-email settings | Shopify OAuth and app configuration |
We do not process customer phone numbers, postal/billing addresses, payment card data, geolocation, or any special-category (sensitive) data, and we do not knowingly process data of children.
We process the above data solely to: (a) create and manage class bookings and seat allocation; (b) present an attendance roster to the merchant; (c) send customers transactional booking emails (confirmation, 24-hour reminder, cancellation/refund and waitlist notices); (d) process refunds and waitlist promotions; and (e) operate, secure, support, and improve the App for the merchant.
We do not use personal data for marketing, advertising, behavioral analytics, profiling, automated decision-making producing legal or similarly significant effects, or for any purpose incompatible with the above.
Where GDPR applies, our legal bases are:
Customers should direct consent-related and other requests to the merchant (controller); we assist the merchant in fulfilling them.
We do not sell or "share" (as defined by the CCPA) personal data, and we do not disclose it except:
| Sub-processor | Function | Location |
|---|---|---|
| Shopify Inc. | Platform; source of order/customer data | Canada / United States |
| Render Services, Inc. | Application hosting and PostgreSQL database (and encrypted backups) | United States |
| Resend (Plusfive, Inc.) | Transactional email delivery | United States |
| Functional Software, Inc. (Sentry) — if enabled | Error monitoring | United States |
Where personal data is transferred across borders, we and our sub-processors rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses (and the UK Addendum), adequacy decisions, or equivalent mechanisms.
We retain personal data only as long as necessary for the purposes above and per our Data Retention Policy. In summary: booking data is retained while the merchant uses the App and for up to 24 months after the related session, then deleted or anonymized. We delete or anonymize personal data in response to Shopify's customers/redact and shop/redact webhooks and provide data on customers/data_request. Encrypted backups are deleted on their normal rotation.
We implement appropriate technical and organizational measures, including encryption of data in transit (TLS) and at rest, encrypted backups, separation of test and production environments, least-privilege access secured with multi-factor authentication, secrets excluded from source control, audit logging of data operations, and a documented incident-response plan. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Subject to applicable law, data subjects have rights to:
Because we act as a processor for customer data, customers should exercise these rights with the merchant, who can trigger deletion/export through Shopify; we honor Shopify's redaction and data-request webhooks automatically.
In the preceding 12 months we processed the categories identifiers (name, email) and commercial information (order/transaction data) for the business purpose in Section 4. We do not sell or share personal information and do not use sensitive personal information for inferring characteristics. California residents have rights to know, access, correct, delete, and to non-discrimination for exercising them; requests should be directed to the merchant, whom we assist.
The App is not directed to children, and we do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent).
We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date; continued use of the App after changes take effect constitutes acceptance.
For privacy questions or to exercise rights (via the merchant where applicable), contact:
ClassKit — Giorgi Khatiashvili (sole trader) Tbilisi, Georgia Email: giorgikhat93@gmail.com