You are the one responsible for telling your shoppers what happens to their information. Inner Circle handles it for you, which means your own privacy policy and cookie notice should mention it.
Below is wording you can copy and adapt. It is a starting point, not legal advice, so check it against your own situation.
For your privacy policy
Access control on this store
Parts of this store are available only to visitors who have been granted access. To manage this we use Inner Circle, a Shopify app provided by Monochrome, which handles the information below on our behalf and under our instructions.
If you request access, we collect the details you enter on the request form, including your email address and anything else the form asks, along with the products you added to your interest list and the page you submitted from. We use this to decide whether to grant you access and to get in touch about it.
If you enter an access code, we record that the code was used, along with your browser type, the page you entered it from, and a scrambled version of your IP address that cannot be turned back into the original. We use this to prevent abuse and to understand which campaigns are working.
If you join a waiting list, we record your email address and when you joined, which is what decides your place in the queue. If we give you a referral link, we also count how many people join through it, because that moves you up the queue.
If you ask to be told when something opens, we keep your email address against that item until we have sent you the announcement.
If you are signed in to an account with us, we may add a tag to your customer record so your access continues to work when you come back. Where we use named levels of access, the name of your level is stored as a tag too.
Emails about your access, your code, a link that unlocks the store, a confirmation that your request arrived, are sent through the app's email provider on our behalf.
We keep this information for as long as we use the app, and it is deleted within 48 hours of us removing it. The data is stored in the European Union.
To ask for a copy of what we hold about you, or to have it corrected or deleted, contact us at [your email address].
For your cookie notice
ic_grant, stored in your browser when you unlock restricted parts of this store, so you are not asked again on every page. It contains a random identifier and no personal information. Strictly necessary. Expires after [30] days.
Change the number if you have changed the access duration in Inner Circle's settings.
This is normally kept in your browser's local storage rather than as a cookie, with a cookie used only where storage is unavailable. List it either way: European rules treat storing a value in a visitor's browser the same regardless of the mechanism, and a cookie notice is where shoppers look for it.
Things to check on your side
- If you use the access request form for marketing, and not only for granting access, you need a lawful basis for that. In most of Europe that means a clear, separate opt-in. Inner Circle has a consent checkbox you can switch on in the form builder.
- Do not add sensitive questions to the form. Health, ethnicity, religion, political views, sexual orientation, biometric or genetic data, criminal records, government ID numbers and card numbers are all prohibited under our terms and would create obligations you almost certainly do not want.
- If you are in Europe or serve European shoppers, our Data Processing Addendum is already part of your agreement with us and covers the transfer. Nothing to sign.