Who we are
Rarity is a Shopify app that lets merchants run auctions, accept offers and schedule product drops. It is operated by Callio LLC, a Georgia limited liability company in the United States ("Rarity", "we", "us"). You can reach us at alex@gocallio.com.
This policy explains what personal data Rarity handles, why, and what choices you have. It is written in plain language on purpose. If anything is unclear, ask us.
Merchants and shoppers
Two kinds of people interact with Rarity:
- Merchants install the app on their Shopify store and run auctions, offers and drops from their admin.
- Shoppers (we call them collectors) bid, make offers or join a drop's launch list on a merchant's storefront.
For shopper data, the merchant decides what to collect and why; Rarity processes it on the merchant's behalf under our Data processing agreement. For merchant account data and this website, Rarity decides how data is used and is responsible for it directly.
What we collect
| Data | From | Why |
|---|---|---|
| Email address and name of a bidder or offer-maker | Shoppers who bid or make an offer | Identify the bidder, verify their email once, send outbid, won and offer emails |
| Hashed IP address (SHA-256; the raw address is never stored) | Bid and offer requests | Fraud and shill-bidding detection, rate limits |
| Shopify customer ID | When a bidder is also a customer of the store | Link bids and offers to the merchant's customer record |
| Email address and name of a launch-list subscriber | Shoppers who press "Notify me" on a drop | Send the drop announcement they asked for |
| Email send log (recipient address, email template, sent or failed) | Emails Rarity sends | Delivery troubleshooting |
| Bids, offers, amounts, timestamps | Shopper activity | Run the auction or offer and show the merchant its history |
| Order totals from paid orders | Shopify (orders/paid notification) | Mark an auction win or drop sale as paid. We keep counts and amounts, not the order's customer details |
| Store name, domain, plan, settings and the merchant's chosen options | Merchants, via Shopify | Run the app, bill through Shopify, show the right settings |
| Integration credentials (a Klaviyo API key or a webhook URL) that a merchant chooses to add | Merchants | Send events to the merchant's own tools. Stored encrypted |
We do not collect postal addresses, phone numbers, payment details or raw IP addresses. Payment happens in Shopify's checkout, which is covered by Shopify's privacy policy, not ours.
Emails from Rarity show the Rarity logo as an image loaded from our server. Opening one therefore sends the recipient's IP address and browser details to our server, like any web request. We do not store these or track opens. Our hosting provider's access logs may keep them for its standard retention period.
Why we use it
- To run auctions, offers and drops: accept bids, work out winners, create checkout links, count remaining stock.
- To send the emails shoppers expect: email verification, outbid, won, offer accepted or countered, drop opened.
- To protect merchants and honest bidders from fraud: verification, rate limits, risk scoring, blocking.
- To bill merchants through Shopify and enforce plan limits.
- To help merchants when they contact support.
We do not sell personal data, use it for advertising, or use it to train machine-learning models.
Data we write to your store
Rarity writes a small amount of information into the merchant's Shopify store so the storefront can display it:
- Product metafields for edition labels, edition size, auction state and drop timing.
- Draft orders for auction winners and accepted offers, which include the buyer's email so they can check out.
- Customer tags (such as a subscriber or VIP tag) only when the merchant turns on the Shopify customer tags option.
The app requests these Shopify permissions: read and write products, read and write draft orders, read orders, read and write customers, read markets and read locales. Each is used only for the purposes above.
Who we share it with
| Recipient | When | What |
|---|---|---|
| Our hosting provider, in the United States | Always | Hosts the app and its database, encrypted at rest |
| Resend (email delivery) | When an email is sent | Recipient address, name and the content of the email |
| Klaviyo | Only if the merchant connects their Klaviyo account | Launch-list sign-ups and auction, offer and drop events |
| The merchant's own webhook endpoint | Only if the merchant adds one | The same events, as JSON |
| Shopify | Always | The app runs inside Shopify; draft orders, metafields and optional customer tags are stored in the merchant's store |
We may also disclose data if the law requires it, or to protect the rights and safety of merchants, shoppers or Rarity. We will tell the affected merchant unless we are legally prevented from doing so.
How long we keep it
- While the app is installed: bidder and subscriber records are kept so the merchant can see history and honour VIP status. A bidder or subscriber with no activity for 24 months is deleted automatically.
- Email send logs are deleted after 90 days.
- Email verification tokens expire after 30 minutes.
- When a merchant uninstalls: all of that store's data, including every bidder, offer, bid, subscriber and log, is deleted when Shopify sends us the uninstall notice, and again when Shopify sends its 48-hour shop redaction notice.
- Backups are encrypted and rotate within 30 days, after which deleted data is gone from them too.
Your rights and deletion
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how it is used, and to complain to a data protection authority. We honour these rights for everyone, wherever they are.
If you are a shopper, the fastest route is the merchant whose store you used: they can delete your bidder record from their Rarity admin. You can also email us at alex@gocallio.com and we will handle it within 30 days. Launch-list emails include an unsubscribe link.
If you are a merchant, uninstalling removes everything. For anything else, email us.
Shopify requests: when Shopify sends us a customer data request, customer redaction or shop redaction notice, we respond automatically. Customer redaction anonymises the bidder's email and name and deletes their subscriber and email-log entries.
Security
Data is encrypted in transit (HTTPS everywhere) and at rest. Integration secrets are additionally encrypted in the database. Access to production systems is limited to the people who run Rarity and is logged, including when a merchant views a collector's details in the app. Our security and incident response policy describes what happens if something goes wrong, including notifying affected merchants within 72 hours.
This website
This website does not use analytics cookies or tracking pixels. It loads fonts from Google Fonts, which receives your IP address to serve the font files. If you email us, we keep the email so we can reply and refer back to it.
Changes
When we change how Rarity handles personal data, we update this page first and change the effective date at the top. For material changes we also tell merchants in the app.
Contact
Callio LLC
Atlanta, Georgia, United States
alex@gocallio.com
We'll provide our registered postal address on request for legal notices.