PrintRight Privacy Policy

Effective date: 17 August 2026  ·  Version 1.0  ·  Last updated: 17 August 2026

1. Who we are

PrintRight is a Shopify application that generates order documents, invoices, packing slips, returns forms and gift receipts, from a merchant’s Shopify order data.

PrintRight is operated by Darren Dodson, a sole proprietor established in North Carolina, United States, of 2203 Hendricks Hill Lane, Holly Springs, NC 27540 (“we”, “us”, “our”).

For any question about this policy or about personal data handled by PrintRight, contact us at dylan@dodson-development.com.

2. Scope of this policy

This policy covers personal data processed by the PrintRight application. It applies to two distinct groups:

This policy does not cover the merchant’s own privacy practices, Shopify’s processing of store data, or any third-party service a merchant connects independently of PrintRight.

3. Personal data we process

3.1 Merchant information

When a merchant installs PrintRight, we receive from Shopify the store domain, the store’s primary contact email, the store name, and plan and locale information. We use this to provision the account, apply the correct subscription plan, and provide support.

3.2 End-customer information

When a document is generated, PrintRight reads the following fields from the relevant Shopify order:

These fields are read because they appear on the face of the document. An invoice or packing slip is not usable without them. No other customer field is read, and no customer data is read except at the moment a document is generated.

Note that Shopify makes end-customer personal data available only on the Shopify, Advanced and Plus plans. On other plans PrintRight cannot access these fields and cannot produce complete documents.

3.3 Operational records

For each document generated, PrintRight records the Shopify order identifier, the order name, the document type, the file size, how long the render took, and whether it succeeded. This record contains no name, address, email address or telephone number.

3.4 Technical and diagnostic data

We process standard application logs, including request timestamps, store domain, response status and error information, for the purpose of operating and debugging the service. Logs are configured to exclude end-customer personal data.

4. Why we process personal data, and our legal basis

Merchant data is processed to perform our contract with the merchant, and on the basis of our legitimate interest in operating, securing and supporting the service.

End-customer data is processed solely on the documented instructions of the merchant, for the single purpose of generating and, where the merchant enables it, delivering the order documents the merchant has requested.

We do not use personal data for any of the following:

5. Storage

PrintRight does not maintain a customer database. No field in our database holds an end customer’s name, address, email address or telephone number, and there is no customer record to query, export or browse.

There is one exception. When a merchant uses bulk printing, the combined document file produced for them is written to storage so that they can download it. Customer names and addresses are printed on the face of those documents, and so that file does contain end-customer personal data for as long as it is held.

For single-document generation, customer data exists only in memory for the duration of the render and is not written to disk.

6. Retention and deletion

Operational records described in section 3.3 are retained for the life of the merchant’s account and deleted on uninstall, and in any event within 48 hours.

Bulk document files described in section 5 are deleted automatically seven days after they are created. They are deleted sooner if the merchant deletes the job, or if the app is uninstalled.

On uninstall, all data associated with the store is deleted, both database records and stored files. File deletion is performed before database records are removed, so that an interruption partway through cannot leave document files behind without a record of them.

Invoice emails are sent through Postmark. Until message content retention can be disabled on that account, automatic email is switched off in production and no customer document is transmitted to the provider.

7. Disclosure and sub-processors

We do not sell personal data and we do not share it for any purpose beyond operating the service. We disclose personal data only to the infrastructure providers below, each of which processes it solely to run PrintRight and is bound by contractual data protection obligations.

Sub-processorPurposePersonal data processedLocation
Shopify Inc.Source platform; order and store dataAll order and customer data originates hereGlobal
Fly.io, Inc.Application hosting, database and file storageBulk document files containing customer name and address; no structured customer recordsUnited States
Upstash, Inc.Job queueStore domain, order identifier and document type onlyUnited States
Postmark (ActiveCampaign, LLC)Transactional email delivery (Pro plan only)Recipient email address and the attached documentUnited States

Email delivery applies only where a merchant is on the Pro plan and has enabled automatic emailing. Merchants on the free plan never send email through PrintRight, and no end-customer data reaches our email provider from those stores.

We may also disclose personal data where we are legally required to do so, or to establish, exercise or defend legal claims. We will notify affected merchants of any such disclosure unless prohibited by law.

We will give merchants advance notice of any change to this list of sub-processors.

8. International transfers

We are established in the United States and all of our infrastructure providers are located in the United States. Where personal data originating in the United Kingdom, European Economic Area or Switzerland is processed by us or by our sub-processors, that transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable.

9. Security

No system is perfectly secure, and we cannot guarantee absolute security. We do commit to the measures above and to the notification obligations in section 12.

10. Rights of end customers

Because we act as a processor for end-customer data, requests from end customers should be directed to the merchant they ordered from. The merchant is the controller and is responsible for responding. We support merchants in responding through Shopify’s mandatory privacy webhooks:

Subject to applicable law, end customers have the right to access their personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. These rights are exercised through the merchant.

11. Rights of merchants

Merchants may request access to, correction of, or deletion of their own account data, and may object to or restrict processing, by contacting us at dylan@dodson-development.com. We respond within 30 days.

Merchants in the United Kingdom or European Economic Area have the right to lodge a complaint with their national supervisory authority.

California residents have the right to know what personal information is collected and how it is used, to request deletion, to correct inaccurate information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not discriminate against anyone exercising these rights.

12. Data breach notification

If we become aware of a personal data breach affecting merchant or end-customer data, we will investigate and contain it, notify affected merchants without undue delay and in any event within 72 hours of becoming aware of it, notify Shopify in accordance with our partner obligations, and notify supervisory authorities where required. Notification will describe what happened, what data was affected, what we have done, and what the merchant should do.

13. Children

PrintRight is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. Any end-customer data we process reaches us from the merchant’s order records, and the merchant is responsible for the lawfulness of collecting it.

14. Changes to this policy

We may update this policy from time to time. The effective date at the top of this document shows when it was last changed. Where a change materially affects how we handle personal data, we will notify merchants by email or within the app before it takes effect.

15. Contact

Darren Dodson
2203 Hendricks Hill Lane, Holly Springs, NC 27540, United States
dylan@dodson-development.com