Privacy Policy

Effective date: 2026-08-12 Last updated: 2026-08-12

1. Introduction

This Privacy Policy explains how ClassKit ("ClassKit", "we", "us", "our") collects, uses, discloses, retains, and protects personal data in connection with the ClassKit application (the "App"), which enables Shopify merchants to sell group class sessions on a repeating schedule and manages the resulting bookings.

It applies to personal data of (a) the merchants who install the App and (b) the merchants' customers whose orders create bookings.

2. Our role: controller and processor

References to "GDPR" include the EU General Data Protection Regulation and, as applicable, the UK GDPR and Data Protection Act 2018. References to "CCPA" include the California Consumer Privacy Act as amended by the CPRA.

3. Personal data we process

We follow the principle of data minimization and process only the following:

CategoryData elementsSource
Customer identifiersName (first, last), email addressShopify order (orders/create)
Transaction dataOrder ID, purchased session(s), quantity, line items, refund detailsShopify order/refund webhooks
Merchant account dataShop domain, offline access token, plan/subscription status, sender-email settingsShopify OAuth and app configuration

We do not process customer phone numbers, postal/billing addresses, payment card data, geolocation, or any special-category (sensitive) data, and we do not knowingly process data of children.

4. Purposes of processing

We process the above data solely to: (a) create and manage class bookings and seat allocation; (b) present an attendance roster to the merchant; (c) send customers transactional booking emails (confirmation, 24-hour reminder, cancellation/refund and waitlist notices); (d) process refunds and waitlist promotions; and (e) operate, secure, support, and improve the App for the merchant.

We do not use personal data for marketing, advertising, behavioral analytics, profiling, automated decision-making producing legal or similarly significant effects, or for any purpose incompatible with the above.

5. Legal bases (GDPR)

Where GDPR applies, our legal bases are:

Customers should direct consent-related and other requests to the merchant (controller); we assist the merchant in fulfilling them.

6. Disclosure and sub-processors

We do not sell or "share" (as defined by the CCPA) personal data, and we do not disclose it except:

Sub-processorFunctionLocation
Shopify Inc.Platform; source of order/customer dataCanada / United States
Render Services, Inc.Application hosting and PostgreSQL database (and encrypted backups)United States
Resend (Plusfive, Inc.)Transactional email deliveryUnited States
Functional Software, Inc. (Sentry) — if enabledError monitoringUnited States

7. International data transfers

Where personal data is transferred across borders, we and our sub-processors rely on appropriate safeguards, which may include the European Commission's Standard Contractual Clauses (and the UK Addendum), adequacy decisions, or equivalent mechanisms.

8. Data retention

We retain personal data only as long as necessary for the purposes above and per our Data Retention Policy. In summary: booking data is retained while the merchant uses the App and for up to 24 months after the related session, then deleted or anonymized. We delete or anonymize personal data in response to Shopify's customers/redact and shop/redact webhooks and provide data on customers/data_request. Encrypted backups are deleted on their normal rotation.

9. Security

We implement appropriate technical and organizational measures, including encryption of data in transit (TLS) and at rest, encrypted backups, separation of test and production environments, least-privilege access secured with multi-factor authentication, secrets excluded from source control, audit logging of data operations, and a documented incident-response plan. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10. Your rights

Subject to applicable law, data subjects have rights to:

Because we act as a processor for customer data, customers should exercise these rights with the merchant, who can trigger deletion/export through Shopify; we honor Shopify's redaction and data-request webhooks automatically.

11. California privacy notice (CCPA/CPRA)

In the preceding 12 months we processed the categories identifiers (name, email) and commercial information (order/transaction data) for the business purpose in Section 4. We do not sell or share personal information and do not use sensitive personal information for inferring characteristics. California residents have rights to know, access, correct, delete, and to non-discrimination for exercising them; requests should be directed to the merchant, whom we assist.

12. Children's data

The App is not directed to children, and we do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent).

13. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by the "Last updated" date; continued use of the App after changes take effect constitutes acceptance.

14. Contact

For privacy questions or to exercise rights (via the merchant where applicable), contact:

ClassKit — Giorgi Khatiashvili (sole trader) Tbilisi, Georgia Email: giorgikhat93@gmail.com