Privacy policy — FlexiBlocks
Privacy Policy — FlexiBlocks
Section titled “Privacy Policy — FlexiBlocks”Last updated: September 9, 2026
App name: FlexiBlocks (ecom-gutenberg)
Developer: K2 Digital
Contact: support@k2.digital
This Privacy Policy describes how FlexiBlocks (“the App”, “we”, “us”) collects, uses, and protects information when you install or use the App on your Shopify store.
1. Information we collect
Section titled “1. Information we collect”When you install and use the App, we may collect and process:
1.1 Store and account information
Section titled “1.1 Store and account information”- Shopify store domain (e.g.
your-store.myshopify.com) - Shop name and shop identifier
- OAuth access tokens issued by Shopify (stored securely; used only to operate the App)
- App installation status and subscription status
1.2 Content you edit through the App
Section titled “1.2 Content you edit through the App”- Blog article body HTML and related app metafields you save through the editor
- Online Store page body HTML and related app metafields
- Product description HTML and related app metafields
- Collection description HTML and related app metafields
- Reusable block library entries (metaobjects) you create or update in the App
- Editor settings you configure in the App (e.g. appearance preferences)
We access this data only to provide editing, save, sync, and storefront rendering features you request.
1.3 Technical and usage data
Section titled “1.3 Technical and usage data”- Server logs (IP address, request timestamps, URLs, error logs) for security and debugging
- Session identifiers stored in our database to keep you signed in to the App
We do not intentionally collect end-customer (shopper) personal data through the App. Storefront visitors may load theme app embed assets; those requests may appear in standard server logs.
2. How we use information
Section titled “2. How we use information”We use collected information to:
- Authenticate your shop and maintain your App session
- Load, edit, and save content to your Shopify store via the Shopify Admin API
- Sync reusable blocks when library entries change
- Deliver theme app embed assets on your Online Store when enabled
- Enforce subscription access where applicable
- Respond to support requests
- Maintain security, prevent abuse, and improve reliability
We do not sell your personal information or shop content to third parties.
3. Shopify’s role
Section titled “3. Shopify’s role”The App is built for Shopify merchants. Shopify’s own privacy practices apply to your Shopify account and store data outside this App. See Shopify’s Privacy Policy.
When you install the App, you authorize us to access Shopify data according to the permissions (scopes) shown at install time.
4. Permissions (OAuth scopes)
Section titled “4. Permissions (OAuth scopes)”The App requests access limited to what it needs:
| Scope | Purpose |
|---|---|
read_content / write_content |
Read and save blog articles and Online Store pages |
read_products / write_products |
Read and save product and collection descriptions |
read_metaobjects / write_metaobjects |
Store and manage reusable block library entries |
read_metaobject_definitions / write_metaobject_definitions |
Install and maintain reusable block schema |
We do not request access to orders, customers, or payment data.
5. Data storage and hosting
Section titled “5. Data storage and hosting”App data is processed and stored on Cloudflare infrastructure (Workers, D1 database, and related services). Data may be processed in regions where Cloudflare operates.
OAuth tokens and session records are stored encrypted at rest where supported by our hosting provider and are accessible only to systems required to run the App.
Content you save is stored in your Shopify store (native body fields and app metafields). We do not maintain a separate long-term copy of your article or page content except transiently during save/load operations and operational logs.
6. Data retention
Section titled “6. Data retention”- Session and shop records: retained while the App is installed and for a reasonable period after uninstall for operational and legal purposes, then deleted or anonymized.
- Server logs: retained for a limited period (typically up to 90 days) unless needed longer for security investigations.
- Shopify content: remains in your Shopify store according to your Shopify settings and uninstall behavior.
When you uninstall the App, we delete or invalidate OAuth sessions for your shop. HTML saved in Shopify body fields remains in your store. App metafields and reusable-block metaobjects are kept so you can reinstall and re-open the same block JSON unless you remove them in Shopify Admin.
7. Sharing with third parties
Section titled “7. Sharing with third parties”We share data only:
- With Shopify — as required for the App to function via Shopify’s APIs
- With infrastructure providers (e.g. Cloudflare) — strictly to host and operate the App
- When required by law — if compelled by valid legal process
We do not share shop content with advertisers or data brokers.
8. Security
Section titled “8. Security”We use industry-standard measures including HTTPS, scoped API access, and secure credential storage. No method of transmission or storage is 100% secure; contact us if you believe your account has been compromised.
9. Your choices and rights
Section titled “9. Your choices and rights”Depending on your location, you may have rights to access, correct, or delete personal data we hold about you as the merchant user.
To exercise these rights or ask questions, contact support@k2.digital. You can also uninstall the App at any time from Shopify Admin.
10. Children’s privacy
Section titled “10. Children’s privacy”The App is intended for businesses and is not directed at children under 13 (or 16 where applicable).
11. Changes to this policy
Section titled “11. Changes to this policy”We may update this Privacy Policy from time to time. We will post the revised version at the same URL and update the “Last updated” date. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact us
Section titled “12. Contact us”K2 Digital
Email: support@k2.digital
Web: https://flexiblocks.k2.digital