App Privacy Policy
Privacy Policy — Three Little Birds Boutique App
Effective Date: March 11, 2026
Last Updated: March 11, 2026
Three Little Birds Boutique (“we” or “us”) built this app to bring our three Central PA boutiques to your phone. This Privacy Policy explains how we collect, use, and protect your information when you use the Three Little Birds Boutique app (“the App”).
By using the App, you are agreeing to the practices described below. We have tried to keep this policy clear and straightforward, because you deserve to know exactly how your information is handled.
1. Information We Collect
Information You Provide
- Account Information: When you create an account, we collect your name and email address through our Shopify-powered authentication system.
- Sizing Profile: If you choose to save your clothing sizes (e.g., top, bottom, dress, shoe sizes, denim inseam, and fit preferences), this information is stored locally on your device and synced to our secure server so it is available across sessions.
- Wishlist: Products you save to your wishlist are stored locally on your device and synced to our server to enable features like “Show to Staff.”
- Preferred Store: If you select a preferred store location (Mechanicsburg, Hershey, or Lancaster), this preference is saved to personalize your experience.
Information Collected Automatically
- Purchase History: We retrieve your order history from Shopify to calculate VIP status (based on order frequency) and to display your past orders within the App. We do not store your purchase history on our servers — it is fetched directly from Shopify when you view it.
- Device Token: When you enable push notifications, we collect your device’s Firebase Cloud Messaging (FCM) token to deliver notifications such as new arrival alerts and VIP early access.
- Analytics Events: We use Firebase Analytics to understand how people use the App in general — things like which screens are most popular and which features get the most use. This data is anonymous and is never tied to your name or account. We use it to make the App better for everyone.
- Notification Preferences: Your choices about which types of notifications you would like to receive (new arrivals, restocks, promotions, VIP access) are stored to respect your preferences.
Information We Do NOT Collect
- Precise or coarse location data
- Payment or credit card information (see Section 3)
- Contacts, photos, or camera data
- Health or fitness data
- Browsing history outside the App
2. How We Use Your Information
We use the information we collect to:
- Make the App work for you: Display products, manage your wishlist, show what is in stock at your preferred store, and remember your sizes when you are browsing.
- Calculate VIP status: Determine whether you qualify for VIP early access based on your order history (5 or more orders within the past 365 days).
- Send push notifications: Deliver new arrival alerts, VIP early access notices, wishlist restock alerts, and other notifications you have opted in to receive.
- Improve the App: Analyze anonymous usage data to understand which features are most valuable and where we can improve.
- Remember your preferences: Your preferred store, your sizes, and which notifications you want to receive.
We do not use your information for cross-app tracking, targeted advertising, or sale to third parties.
3. Payment Information
All purchases made through the App are processed entirely by Shopify via their Checkout system. We never see your payment card information, billing address, or any financial data — that all stays between you and Shopify’s secure checkout, which may include Apple Pay and Shop Pay.
For questions about how Shopify handles your payment data, please see Shopify’s Privacy Policy.
4. Third-Party Services
The App uses the following third-party services, each with their own privacy policies:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase Analytics | Google LLC | Anonymous app usage analytics | Aggregate event data (not linked to identity) |
| Firebase Cloud Messaging | Google LLC | Push notification delivery | Device token |
| Firebase Firestore | Google LLC | Server-side storage for wishlists, sizing, and preferences | Wishlist items, sizing profile, notification preferences |
| Firebase Authentication | Google LLC | Secure per-user data access | Authentication token |
| Shopify | Shopify Inc. | Customer accounts, product data, order history, checkout | Account credentials, order data |
We do not share your data with advertising networks, data brokers, or any other third parties beyond those listed above.
5. Data Storage and Security
- Local data is stored on your device using Apple’s SwiftData framework and is protected by your device’s built-in encryption.
- Server-side data (wishlist, sizing profile, notification preferences) is stored in Google Firebase Firestore with per-user authentication rules — only you can access your own data.
- Login credentials are stored in your device’s Keychain — the same secure vault your iPhone uses to protect your passwords.
- All data sent between the App and our servers is encrypted in transit.
6. Data Retention
- Local data (SwiftData): Persists on your device until you delete the App or delete your account.
- Firestore data: Retained until you delete your account via the App (see Section 7).
- Firebase Analytics: Anonymous analytics data is retained for 14 months per Google’s default retention policy.
- Shopify customer data: Retained per Shopify’s data retention policy. Deleting your account in the App does not delete your Shopify customer account (see Section 7).
- Notification tokens: If you uninstall the App or stop using it, we automatically clean up your notification registration within 24 hours.
7. Your Rights and Account Deletion
Deleting Your Account
You can delete your account at any time from within the App:
My TLB tab > Account Settings > Delete Account
When you delete your account, the following data is permanently removed:
- Firebase Authentication record
- Firestore data (wishlist, sizing profile, notification preferences, user document)
- FCM device token registration
- All locally stored data (SwiftData)
Important: Deleting your account in the App does not delete your Shopify customer account. Your Shopify account is separate — it is used for the Three Little Birds website and online store as well. You will see a reminder about this before confirming deletion in the App. To delete your Shopify account, please contact us directly (see Section 10).
Requesting Your Data
You may request a copy of the data we hold about you by contacting us at the email address below. We will respond within 30 days.
Opting Out of Notifications
You can disable push notifications at any time through:
- The App: My TLB tab > Notification Preferences
- Your device: Settings > Notifications > Three Little Birds
8. Children’s Privacy
The App is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately and we will take steps to delete it.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last Updated” date at the top of this policy. For significant changes, we may notify you through an in-app message or push notification. If you continue using the App after we make changes, that means you are okay with the updated policy.
10. Contact Us
We are real people, not a legal department. If you have questions about this policy, your data, or anything else, we would love to hear from you:
Three Little Birds Boutique LLC
Email: thetlbboutique@gmail.com
Website: tlbboutique.com
You may also visit us in person at any of our three locations:
- Mechanicsburg — 6455 Carlisle Pike Unit c, Mechanicsburg, PA 17050
- Hershey — 131 W Chocolate Ave Suite 120, Hershey, PA 17033
- Lancaster — 1200 Gilbert Wy Ste D111, Lancaster, PA 17601