Skip to content

Privacy policy — FlexiBlocks

Last updated: September 9, 2026

App name: FlexiBlocks (ecom-gutenberg)
Developer: K2 Digital
Contact: support@k2.digital

This Privacy Policy describes how FlexiBlocks (“the App”, “we”, “us”) collects, uses, and protects information when you install or use the App on your Shopify store.


When you install and use the App, we may collect and process:

  • Shopify store domain (e.g. your-store.myshopify.com)
  • Shop name and shop identifier
  • OAuth access tokens issued by Shopify (stored securely; used only to operate the App)
  • App installation status and subscription status
  • Blog article body HTML and related app metafields you save through the editor
  • Online Store page body HTML and related app metafields
  • Product description HTML and related app metafields
  • Collection description HTML and related app metafields
  • Reusable block library entries (metaobjects) you create or update in the App
  • Editor settings you configure in the App (e.g. appearance preferences)

We access this data only to provide editing, save, sync, and storefront rendering features you request.

  • Server logs (IP address, request timestamps, URLs, error logs) for security and debugging
  • Session identifiers stored in our database to keep you signed in to the App

We do not intentionally collect end-customer (shopper) personal data through the App. Storefront visitors may load theme app embed assets; those requests may appear in standard server logs.


We use collected information to:

  • Authenticate your shop and maintain your App session
  • Load, edit, and save content to your Shopify store via the Shopify Admin API
  • Sync reusable blocks when library entries change
  • Deliver theme app embed assets on your Online Store when enabled
  • Enforce subscription access where applicable
  • Respond to support requests
  • Maintain security, prevent abuse, and improve reliability

We do not sell your personal information or shop content to third parties.


The App is built for Shopify merchants. Shopify’s own privacy practices apply to your Shopify account and store data outside this App. See Shopify’s Privacy Policy.

When you install the App, you authorize us to access Shopify data according to the permissions (scopes) shown at install time.


The App requests access limited to what it needs:

Scope Purpose
read_content / write_content Read and save blog articles and Online Store pages
read_products / write_products Read and save product and collection descriptions
read_metaobjects / write_metaobjects Store and manage reusable block library entries
read_metaobject_definitions / write_metaobject_definitions Install and maintain reusable block schema

We do not request access to orders, customers, or payment data.


App data is processed and stored on Cloudflare infrastructure (Workers, D1 database, and related services). Data may be processed in regions where Cloudflare operates.

OAuth tokens and session records are stored encrypted at rest where supported by our hosting provider and are accessible only to systems required to run the App.

Content you save is stored in your Shopify store (native body fields and app metafields). We do not maintain a separate long-term copy of your article or page content except transiently during save/load operations and operational logs.


  • Session and shop records: retained while the App is installed and for a reasonable period after uninstall for operational and legal purposes, then deleted or anonymized.
  • Server logs: retained for a limited period (typically up to 90 days) unless needed longer for security investigations.
  • Shopify content: remains in your Shopify store according to your Shopify settings and uninstall behavior.

When you uninstall the App, we delete or invalidate OAuth sessions for your shop. HTML saved in Shopify body fields remains in your store. App metafields and reusable-block metaobjects are kept so you can reinstall and re-open the same block JSON unless you remove them in Shopify Admin.


We share data only:

  • With Shopify — as required for the App to function via Shopify’s APIs
  • With infrastructure providers (e.g. Cloudflare) — strictly to host and operate the App
  • When required by law — if compelled by valid legal process

We do not share shop content with advertisers or data brokers.


We use industry-standard measures including HTTPS, scoped API access, and secure credential storage. No method of transmission or storage is 100% secure; contact us if you believe your account has been compromised.


Depending on your location, you may have rights to access, correct, or delete personal data we hold about you as the merchant user.

To exercise these rights or ask questions, contact support@k2.digital. You can also uninstall the App at any time from Shopify Admin.


The App is intended for businesses and is not directed at children under 13 (or 16 where applicable).


We may update this Privacy Policy from time to time. We will post the revised version at the same URL and update the “Last updated” date. Continued use of the App after changes constitutes acceptance of the updated policy.


K2 Digital
Email: support@k2.digital
Web: https://flexiblocks.k2.digital