PrintRight Privacy Policy
1. Who we are
PrintRight is a Shopify application that generates order documents, invoices, packing slips, returns forms and gift receipts, from a merchant’s Shopify order data.
PrintRight is operated by Darren Dodson, a sole proprietor established in North Carolina, United States, of 2203 Hendricks Hill Lane, Holly Springs, NC 27540 (“we”, “us”, “our”).
For any question about this policy or about personal data handled by PrintRight, contact us at dylan@dodson-development.com.
2. Scope of this policy
This policy covers personal data processed by the PrintRight application. It applies to two distinct groups:
- Merchants, the Shopify store owners and staff who install and use PrintRight. In respect of merchant data, we act as a data controller.
- End customers, the people who place orders with those merchants and whose details appear on the documents PrintRight produces. In respect of end-customer data, we act as a data processor on behalf of the merchant, who remains the controller.
This policy does not cover the merchant’s own privacy practices, Shopify’s processing of store data, or any third-party service a merchant connects independently of PrintRight.
3. Personal data we process
3.1 Merchant information
When a merchant installs PrintRight, we receive from Shopify the store domain, the store’s primary contact email, the store name, and plan and locale information. We use this to provision the account, apply the correct subscription plan, and provide support.
3.2 End-customer information
When a document is generated, PrintRight reads the following fields from the relevant Shopify order:
- Customer name
- Customer email address
- Customer telephone number
- Shipping address
- Billing address
- Order contents, line items, pricing, discounts and taxes
These fields are read because they appear on the face of the document. An invoice or packing slip is not usable without them. No other customer field is read, and no customer data is read except at the moment a document is generated.
Note that Shopify makes end-customer personal data available only on the Shopify, Advanced and Plus plans. On other plans PrintRight cannot access these fields and cannot produce complete documents.
3.3 Operational records
For each document generated, PrintRight records the Shopify order identifier, the order name, the document type, the file size, how long the render took, and whether it succeeded. This record contains no name, address, email address or telephone number.
3.4 Technical and diagnostic data
We process standard application logs, including request timestamps, store domain, response status and error information, for the purpose of operating and debugging the service. Logs are configured to exclude end-customer personal data.
4. Why we process personal data, and our legal basis
Merchant data is processed to perform our contract with the merchant, and on the basis of our legitimate interest in operating, securing and supporting the service.
End-customer data is processed solely on the documented instructions of the merchant, for the single purpose of generating and, where the merchant enables it, delivering the order documents the merchant has requested.
We do not use personal data for any of the following:
- Advertising, marketing or profiling
- Training machine learning or artificial intelligence models
- Sale, rental, licensing or other disclosure to data brokers
- Data enrichment or resale in any form
- Any purpose other than generating and delivering order documents
5. Storage
PrintRight does not maintain a customer database. No field in our database holds an end customer’s name, address, email address or telephone number, and there is no customer record to query, export or browse.
There is one exception. When a merchant uses bulk printing, the combined document file produced for them is written to storage so that they can download it. Customer names and addresses are printed on the face of those documents, and so that file does contain end-customer personal data for as long as it is held.
For single-document generation, customer data exists only in memory for the duration of the render and is not written to disk.
6. Retention and deletion
Operational records described in section 3.3 are retained for the life of the merchant’s account and deleted on uninstall, and in any event within 48 hours.
Bulk document files described in section 5 are deleted automatically seven days after they are created. They are deleted sooner if the merchant deletes the job, or if the app is uninstalled.
On uninstall, all data associated with the store is deleted, both database records and stored files. File deletion is performed before database records are removed, so that an interruption partway through cannot leave document files behind without a record of them.
Invoice emails are sent through Postmark. Until message content retention can be disabled on that account, automatic email is switched off in production and no customer document is transmitted to the provider.
7. Disclosure and sub-processors
We do not sell personal data and we do not share it for any purpose beyond operating the service. We disclose personal data only to the infrastructure providers below, each of which processes it solely to run PrintRight and is bound by contractual data protection obligations.
| Sub-processor | Purpose | Personal data processed | Location |
|---|---|---|---|
| Shopify Inc. | Source platform; order and store data | All order and customer data originates here | Global |
| Fly.io, Inc. | Application hosting, database and file storage | Bulk document files containing customer name and address; no structured customer records | United States |
| Upstash, Inc. | Job queue | Store domain, order identifier and document type only | United States |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery (Pro plan only) | Recipient email address and the attached document | United States |
Email delivery applies only where a merchant is on the Pro plan and has enabled automatic emailing. Merchants on the free plan never send email through PrintRight, and no end-customer data reaches our email provider from those stores.
We may also disclose personal data where we are legally required to do so, or to establish, exercise or defend legal claims. We will notify affected merchants of any such disclosure unless prohibited by law.
We will give merchants advance notice of any change to this list of sub-processors.
8. International transfers
We are established in the United States and all of our infrastructure providers are located in the United States. Where personal data originating in the United Kingdom, European Economic Area or Switzerland is processed by us or by our sub-processors, that transfer is made under the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable.
9. Security
- All data is encrypted in transit using TLS, including connections to our database and job queue.
- Stored files and databases are encrypted at rest by our hosting providers.
- No feature of the application, no dashboard, export, report or support console, exposes end-customer personal data to us.
- Access to the hosting environment is restricted to the named individuals who operate the service, is used only for incident response and maintenance, is authenticated, and is logged.
- All webhook requests are verified by HMAC signature; unsigned or incorrectly signed requests are rejected.
- A generated document can be opened from a link that carries its own HMAC signature. Each link is scoped to one store, one order and one document type, and cannot be altered to reach a different store, order or document without invalidating its signature. Links are served with caching, referrer transmission and search-engine indexing disabled. They do not expire on a timer, so anyone who obtains the address can reopen that one document; treat a document link as you would the document itself. Links stop working as soon as the store uninstalls the application or its data is erased.
No system is perfectly secure, and we cannot guarantee absolute security. We do commit to the measures above and to the notification obligations in section 12.
10. Rights of end customers
Because we act as a processor for end-customer data, requests from end customers should be directed to the merchant they ordered from. The merchant is the controller and is responsible for responding. We support merchants in responding through Shopify’s mandatory privacy webhooks:
- Customer data request: we report the data we hold in relation to that customer, which in normal operation is none.
- Customer redaction: we delete any stored document file containing that customer’s order.
- Shop redaction: on uninstall, we delete all data and all stored files for that store.
Subject to applicable law, end customers have the right to access their personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. These rights are exercised through the merchant.
11. Rights of merchants
Merchants may request access to, correction of, or deletion of their own account data, and may object to or restrict processing, by contacting us at dylan@dodson-development.com. We respond within 30 days.
Merchants in the United Kingdom or European Economic Area have the right to lodge a complaint with their national supervisory authority.
California residents have the right to know what personal information is collected and how it is used, to request deletion, to correct inaccurate information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not discriminate against anyone exercising these rights.
12. Data breach notification
If we become aware of a personal data breach affecting merchant or end-customer data, we will investigate and contain it, notify affected merchants without undue delay and in any event within 72 hours of becoming aware of it, notify Shopify in accordance with our partner obligations, and notify supervisory authorities where required. Notification will describe what happened, what data was affected, what we have done, and what the merchant should do.
13. Children
PrintRight is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. Any end-customer data we process reaches us from the merchant’s order records, and the merchant is responsible for the lawfulness of collecting it.
14. Changes to this policy
We may update this policy from time to time. The effective date at the top of this document shows when it was last changed. Where a change materially affects how we handle personal data, we will notify merchants by email or within the app before it takes effect.
15. Contact
Darren Dodson2203 Hendricks Hill Lane, Holly Springs, NC 27540, United States
dylan@dodson-development.com