Headless Boost

Privacy Policy

Effective August 5, 2026

Overview

Headless Boost provides software that helps businesses create and operate their digital storefronts. This policy explains how we handle information when a business uses Headless Boost, including when it connects a third-party service such as Shopify.

Information we process

  • Account and workspace information, such as a user's name, email address, role, and the business workspace they belong to.
  • Connected-service information, such as the Shopify store domain, approved permissions, and an access token needed to provide the requested connection.
  • Workspace content and activity, such as site configuration, media, form submissions, and support requests that a business chooses to create or collect through Headless Boost.
  • Service and security data, such as authentication events, device or browser details, and diagnostic logs used to keep the service reliable and secure.

How we use information

We use information to provide and improve Headless Boost; create and secure workspaces; connect services requested by the business; respond to support requests; communicate about the service; and prevent fraud, abuse, or security incidents.

Connected services and sharing

A business decides whether to connect services such as Shopify. Headless Boost uses information from a connected service only as authorized by that business and the permissions granted during the connection. We may also use service providers that help us operate the platform, such as hosting, authentication, email delivery, and connected-service providers. We do not sell personal information.

Security

We use reasonable technical and organizational measures designed to protect information. Shopify access tokens stored by Headless Boost are encrypted at rest and are not displayed after they are saved. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

Retention and your choices

We retain information for as long as needed to provide the service, meet legitimate operational or legal needs, and resolve disputes. A workspace administrator can remove a connected service. To request access, correction, or deletion of information associated with Headless Boost, contact us using the address below.

Changes

We may update this policy as Headless Boost evolves. When we do, we will post the updated policy here and change the effective date.

Contact

Questions about this policy or Headless Boost privacy practices can be sent to kship@kship.com.