Radiant Size ChartLegal and trust centre
Current document

Privacy policy · Effective July 20, 2026 · Updated July 31, 2026

Privacy Policy

A clear boundary around every sizing result. This policy explains what Radiant handles, why, for how long, and what choices merchants and shoppers have. The product summary comes first; the complete policy follows below.

Effective
July 20, 2026
Last updated
July 31, 2026

Body details in. Size guidance out.

The calculation happens where the shopper is interacting, without turning body inputs into a cross-store profile.

  1. 01

    Body details

    Height, weight, age, selected body shape, and calculated measurements are temporary inputs for the active experience.

  2. 02

    Browser calculation

    The storefront evaluates those details against the assigned chart in the shopper's browser.

  3. 03

    Size outcome

    The result can include a recommended size, an alternative, fit detail, and the selected unit system.

Keep only what the experience needs.

Body answers stay out

Height, weight, birth year, shape answers, and calculated measurements are not attached to analytics or plan-usage records.

A result can be remembered

When enabled by the merchant and permitted by site preferences, the same store and chart can remember the final outcome for the current visit, 1, 7, or 30 days.

Service data has a purpose

Merchant-created charts, assignments, settings, subscription state, plan usage, and eligible reporting are stored so the service can operate.

Operational insight, not a customer list.

When analytics is enabled and privacy-eligible, Radiant can record sizing opens, consultations, results, active interaction time, eligible add-to-cart attribution, and attributed returned units.

  • Limited store, product, chart, order, time, quantity, final size, and final fit references may be included
  • Identity, contact fields, body answers, calculated measurements, and a shopper IP attached to the event are excluded
  • Direct order references are removed after 60 days while non-linked metrics remain; applicable privacy requests can access or erase order-linked records earlier, and uninstall starts the shop-scoped operational purge described below

Keep the notice aligned with the configuration.

Merchants can use the standard notice or provide store-specific text. Review it after changes to language, analytics, result memory, or retention, and use a qualified adviser for store-specific legal wording.

Analytics off
Stops new activity; it does not erase previously verified reporting.
Start over
Clears the active sizing result for the current experience.
Site data cleared
Removes longer-lived result preferences stored in that site context.

Privacy Policy

DAWSEN SA, trading as Ash Spark, operates Radiant Size Chart ("Radiant", "we", "us"). This policy applies to the Radiant website, the embedded Shopify app, the Radiant listing in the Shopify App Store, and the Radiant storefront sizing experience. It describes product behavior and our data practices; it does not replace a merchant's own storefront privacy policy.

1. Scope and privacy roles

For merchant account, support, and direct website information, DAWSEN SA determines why and how that information is used. For shopper information processed through a merchant's store, the merchant normally acts as the controller or business and DAWSEN SA acts as its processor or service provider through Radiant. The merchant controls whether Radiant is installed, which products use it, the storefront notice, analytics, and result-memory settings.

For support, DAWSEN acts independently for the merchant account, contact relationship, service administration, and security. DAWSEN acts on the Merchant's instructions only to the extent a merchant chooses to include shopper or other Merchant-controlled personal data in a support request.

For optional measurement and advertising on Radiant's Shopify App Store listing, DAWSEN determines why the configured Google and Meta services are used. Shopify operates the listing and sends the eligible listing and installation events described below. Google and Meta process those events under their applicable service and privacy terms.

Shoppers should normally send privacy requests to the store where they used Radiant. Shopify then sends applicable access and deletion instructions to Radiant through its privacy request process.

For merchants, this Privacy Policy and our Data Processing Addendum form part of the Terms of Service accepted when the app is installed or used.

2. Information we handle

Body details used for a recommendation

The sizing experience can use sex, birth-year-derived age, height, weight, relevant body-shape choices, and measurements calculated for the active result. The calculation runs in the shopper's browser. Radiant does not receive or retain those body inputs as app data, attach them to Analytics, or include them in plan-usage records.

Completed result on the shopper's device

When enabled and Shopify permits preference processing, the browser can store a completed recommendation for the same store and chart. It can include recommended and alternative sizes, fit detail, and the selected unit system. It does not include the shopper's body inputs or calculated measurements.

Consent-eligible storefront Analytics

When the merchant enables Analytics and Shopify permits analytics processing, Radiant can receive limited operational events: store, product, chart, surface, time, quantity, final size and fit references, active interaction time, and eligible order references used for purchase or return attribution. An event does not contain shopper name, email, postal address, phone number, body answers, calculated measurements, or a shopper IP address attached to the Analytics record. Because an order reference can be present, these records are not described as legally anonymous.

Shopify App Store listing measurement and advertising

When listing tracking is enabled, Shopify can send Google Analytics 4 events for an app-details page view, an Install button click, a completed app installation, and a visit attributed to a Shopify App Store ad. Related parameters can include the app identifier or handle, listing surface, locale, value and currency, and, for a completed installation, the merchant's Shopify shop identifier, shop name, and shop domain.

Shopify can also send Meta Pixel and Conversions API events for viewing the listing, clicking Install, and completing an installation. Google Ads and Meta can use eligible listing activity for campaign attribution, audience measurement, remarketing, and advertising optimization. These listing integrations do not receive shopper body answers, calculated measurements, size recommendations, merchant support messages, or the storefront operational Analytics records described above.

Merchant and service information

Through Shopify APIs and authenticated app sessions, Radiant handles the shop domain and Shopify shop identifier; merchant user identifiers, name, email, locale, role flags, access scopes, and session credentials; and the product, variant, collection, vendor, product-type, tag, locale, theme, logo, and media details needed to configure, verify, and display size charts. Radiant stores the relevant assignment identifiers, cached display names and thumbnails, and merchant settings rather than a separate copy of the complete Shopify catalog.

Radiant also stores merchant-created charts and content, subscription and billing status, plan usage, eligible reporting, and privacy-request status needed to provide the service. Images a merchant uploads through Radiant are created in that merchant's Shopify Files library; Radiant stores the resulting file URL with the applicable configuration. If a person contacts us, we handle the message and contact information they choose to provide.

When a merchant uses the in-app support chat, Radiant sends the current message and up to eight recent entries from that support conversation to DAWSEN's backend so the reply can preserve context. The backend can compare that text with product help materials through a DAWSEN-controlled, Vercel-hosted knowledge service and use Google Cloud's managed generative model service to prepare a response. Support messages are not copied into storefront Analytics. Merchants should not include credentials, payment information, shopper body details, or other unnecessary sensitive information.

Order and return information used for reporting

For eligible purchase attribution, Radiant can store a Shopify order reference, product reference, and quantity with the sizing event. The direct order reference is retained for no more than 60 days; the product, quantity, event, and aggregate reporting metrics can remain without that order link. When an authorized merchant views return reporting during that window, Radiant can request the related product reference and processed or refunded return-line quantity from Shopify to calculate attributed returned units. Radiant does not request customer contact, shipping, or payment fields for that calculation or copy them into its Analytics records.

Technical request data

Hosting and security systems can process standard request metadata, such as timestamps, browser information, and network addresses, to deliver, rate-limit, and protect the service. A network address or logged-in Shopify customer identifier can be processed transiently to derive a keyed Smart Selector usage event identifier; the raw value is not written to the usage or storefront Analytics record.

Shopify privacy-request payloads

A mandatory Shopify privacy-request payload can contain contact fields while Shopify, the configured message transport, and Radiant process the request. Radiant handles the original payload transiently and persists only the minimized request and order references needed to locate, report, or delete applicable records. It does not copy those contact fields into Analytics.

3. Purposes and legal bases

  • Provide the app, sizing experience, merchant configuration, reporting, billing, and support under the merchant contract.
  • Protect, troubleshoot, and improve the service where this is necessary for our legitimate interests and does not override applicable individual rights.
  • Store a persistent sizing preference or collect storefront Analytics only when the applicable Shopify permission allows that processing. If the consent service is unreachable, Radiant keeps only a current-visit session result and never creates persistent preference storage.
  • Measure how merchants discover and interact with Radiant's Shopify App Store listing, and attribute completed installations through Google Analytics 4. DAWSEN relies on consent where applicable law requires consent for storage, access, or analytics; where consent is not required and the processing is permitted, DAWSEN relies on its legitimate interest in measuring and improving the listing after balancing that interest against individual rights.
  • Measure paid promotion, build or evaluate relevant audiences, and optimize advertising through Google Ads and Meta. DAWSEN relies on consent where required for device access, personalized advertising, audience creation, or similar marketing processing; otherwise it uses its legitimate interest in measuring and promoting Radiant only where that basis is permitted after a balancing assessment. The integration is not used where a required permission is absent.
  • Respond to privacy requests, prevent misuse, resolve disputes, and comply with legal obligations.

The merchant remains responsible for selecting the legal basis that applies to its storefront and for configuring Shopify Customer Privacy accordingly.

4. Device storage and consent

Shopify classifies size as a preference. Radiant checks Shopify's preference-processing permission before writing or restoring a completed result. With permission, “Current visit” uses session storage; 1, 7, or 30-day choices use local storage when available. If Shopify explicitly denies permission, no result is written to either storage area and the active result remains only in the open widget state. If the privacy feature does not respond, Radiant uses session storage only for the current visit and never writes persistent local storage.

Withdrawing preference permission removes saved results for the active store and chart. Selecting Start over or clearing site data also removes them. A chart change invalidates an older result. After the configured visit, 1-day, 7-day, or 30-day boundary, Radiant does not restore an expired result. Because longer-lived results use browser-controlled local storage, the physical entry can remain until the widget next reads or cleans that storage, or until the shopper clears site data. Analytics is checked separately using Shopify's analytics-processing permission and is not sent when that permission is unavailable or denied.

When Analytics is permitted, Shopify's Web Pixel storage can keep up to 20 recent consultation references so a product add-to-cart or completed order can be attributed to the relevant sizing consultation. A reference is eligible for attribution for 24 hours; older references are ignored and removed when the storage is next rewritten. References can include store origin, product and chart identifiers, the storefront surface, random event identifiers, and a timestamp; they do not include body inputs, calculated measurements, or shopper contact details.

Shopify App Store listing tracking is separate from the merchant storefront widget and is implemented on Shopify-operated listing and installation surfaces. Shopify controls its page-level privacy mechanisms. Where applicable law requires a choice for analytics or marketing, DAWSEN uses the configured Google and Meta services only subject to the applicable Shopify and provider controls. A merchant can also use browser, Shopify, Google, or Meta privacy controls where available.

DAWSEN is responsible for the legal basis, transparency, and controls for optional tracking that it configures on the Shopify App Store listing. A privacy permission obtained for a merchant's storefront does not authorize this separate listing processing.

5. Sharing and service providers

We disclose information only as needed to:

  • Shopify, which provides the store, authentication, billing, consent signals, order references, and privacy-request flow;
  • Vercel, which hosts and secures the application and processes standard request and operational logs;
  • Supabase, which provides the managed PostgreSQL database, connection pooling, monitoring, and provider-managed backups;
  • Google Cloud Pub/Sub, which authenticates, queues, retries, and delivers Shopify app-lifecycle, access-scope, and mandatory privacy webhooks to Radiant; this use does not include the optional support chat;
  • Google Analytics, which measures Shopify App Store listing views, Install interactions, ad-attributed listing visits, and completed app installations;
  • Google Ads, which provides optional listing remarketing, campaign attribution, audience measurement, and advertising optimization;
  • Meta, which provides optional Meta Pixel and Conversions API measurement for listing views, Install interactions, completed installations, audiences, and advertising optimization;
  • authorities or professional advisers when law, security, or legal claims require it; or
  • a successor in a merger, financing, acquisition, or asset transfer, subject to applicable notice and safeguards.

Radiant does not sell shopper body details or use them for cross-context behavioral advertising. We do not receive those body details in the first place. The current contracted provider list and purposes are published on our Subprocessors page.

6. Retention and deletion

  • Body inputs and calculated measurements are not retained by Radiant as server-side shopper data.
  • Device results are eligible for restoration only for the current visit or until the configured 1, 7, or 30-day boundary, according to the merchant choice and Shopify preference permission. Passing that boundary prevents restoration; a local-storage entry can remain physically present until the widget next reads or cleans that storage, or the shopper clears site data.
  • Direct Shopify order references in Operational Analytics are removed after 60 days. Event totals, product references, and quantities remain available for reporting without the direct order link. Applicable order-linked records are erased earlier after a Shopify customer deletion request.
  • After a customer deletion request, Radiant keeps a keyed, non-reversible fingerprint of the shop and deleted order only to prevent erased analytics from being created again. It does not contain the raw order or customer identifier and is removed when the retained shop lifecycle marker is safely deleted after Shopify's shop-erasure request.
  • Smart Selector usage-event records become eligible for cleanup after 62 days. Monthly aggregate usage buckets become eligible for cleanup after 13 months. They are also included in the operational purge started when the store uninstalls Radiant.
  • Google Analytics 4 event and user-level data for this property is configured for two months. Google Ads conversion attribution uses a 30-day post-click window. If DAWSEN later creates a remarketing audience, its membership duration will be configured and disclosed before use. Meta can retain event data for up to two years and an audience created from that data until DAWSEN deletes the audience through its account tools. DAWSEN can remove or disable listing credentials when an integration is no longer needed and does not copy provider advertising profiles into Radiant's application database.
  • The Google Cloud Pub/Sub source topic retains published webhook messages for up to 7 days, including messages already acknowledged by its subscription. Its dead-letter topic retains published dead-letter messages for up to 31 days for incident handling. The subscriptions use those same respective windows and do not add separate acknowledged-message retention.
  • The current application route does not deliberately write in-app support messages or their recent conversation context to Radiant's application database. It transmits that content to the Vercel-hosted support service and Google Cloud's managed generative model service to prepare the active reply. The approved help corpus is stored in Google Cloud BigQuery and Cloud Storage in the United States; the support question is used to search that corpus but is not written into it through this support flow. The current message, up to eight recent entries, and retrieved excerpts remain in request memory until the reply completes or fails. DAWSEN does not deliberately log that content. Vercel Pro runtime logs remain available for up to one day and can contain request metadata and application status or error messages, not deliberately the submitted support text. Google's current Gemini terms permit isolated in-memory caching for up to 24 hours and retention of a prompt flagged for suspected abuse for up to 90 days. Radiant does not enable request-response logging, grounding with Google Search or Maps, or resumable model sessions for this flow.
  • For completed privacy access requests, report snapshots and token inputs are cleared on completion, and stored Shopify order identifiers are cleared within seven days. A minimal receipt without customer or order identifiers can remain for up to 30 days after completion, after which the full request record is deleted. Incomplete requests remain available until handled, erased, or removed with the store lifecycle.
  • When Radiant receives an app-uninstall notice, it starts a durable, retryable purge of shop-scoped operational data. The purge runs in bounded batches, so completion may follow the webhook response rather than occur immediately. A minimal shop lifecycle marker remains until Shopify's mandatory shop-erasure request permits its safe removal. After a purge completes, the retained receipt has its direct shop reference cleared, remains for at least 30 days for idempotency and operational verification, and is then eligible for recurring cleanup. Files created in the merchant's Shopify Files library remain under that merchant's Shopify file controls unless the merchant deletes them there.

We may retain limited records longer when law requires it or when reasonably necessary to establish, exercise, or defend a legal claim. We do not use a universal 732-day Analytics deletion rule.

7. International transfers

Shopify and our contracted service providers may process data outside the country where a merchant or shopper is located. Where data-protection law requires a transfer mechanism, we use an applicable adequacy decision, contractual safeguards, or another lawful transfer basis. The current provider locations are described on the Subprocessors page. Merchants remain responsible for transfer disclosures and agreements required for their own storefront processing.

8. Privacy rights

Depending on location and context, a person may have rights to know or access personal information, correct it, delete it, restrict or object to processing, receive a portable copy, withdraw consent, opt out of sale or sharing, and complain to a supervisory authority. Exercising a right will not result in unlawful discrimination.

Shoppers should contact the merchant where they used Radiant. Applicable Shopify access requests create a private report for the merchant to deliver; applicable deletion requests erase order-linked Analytics automatically. Merchant users and people who contacted Radiant directly can email info@ashspark.com. We may need to verify the request and cannot act on information we do not hold.

9. Security

Radiant uses technical and organizational measures designed to protect information, including HTTPS/TLS for production traffic, encryption at rest through the managed hosting and database providers, authenticated Shopify Admin access for merchant controls, shop-scoped authorization, and private, non-cacheable access report downloads. Provider-managed backups are encrypted and remain subject to provider access and retention controls. No system can guarantee absolute security. Merchants should protect their Shopify accounts and avoid sending passwords, payment-card details, or shopper body inputs in support messages.

The Google Analytics Measurement ID, Google conversion ID, and Meta Pixel ID identify the configured destinations; they are not server-side authentication secrets. The Google Analytics API secret and Meta Conversions API access token used for Shopify App Store installation attribution are confidential credentials generated in the relevant provider account and supplied directly to Shopify. They are not committed to Radiant's source code, written to Radiant's application logs, included in screenshots, or stored in Radiant's application database.

10. Children

Radiant is a merchant service and is not designed to create accounts for children. Body inputs entered in the sizing experience remain local and are not retained by Radiant. Merchants must decide whether and how to offer sizing guidance to minors and obtain parental authorization where required.

11. Changes to this policy

We may update this policy when product behavior, providers, or legal requirements change. The Last updated date at the top identifies the current version. Material changes will be communicated through an appropriate channel when required.

12. Contact

DAWSEN SA, trading as Ash Spark, operates Radiant Size Chart. Our legal address is Juan María Pérez 2965, CP 11300, Montevideo, Uruguay. For questions about this policy or a direct privacy request, email info@ashspark.com. Include the relevant Shopify store domain and do not include shopper body details, passwords, access tokens, or payment-card data.

This policy is designed to address transparency principles found in the GDPR and UK GDPR, CCPA/CPRA, LGPD, PIPEDA, Australia's Privacy Act, Singapore's PDPA, Japan's APPI, and China's PIPL. Rights and obligations vary by jurisdiction; this statement is not a certification that installing Radiant alone makes a merchant compliant with every law.

Need help with a privacy question?

Shoppers should start with the store where they used Radiant. Merchants can contact us with the store domain and the exact question.