Privacy Policy
This Privacy Policy describes how Sole Proprietor Artem Danylov (FOP Danylov Artem), Tax ID 3459515134, trading as PG ArtLab ("GiftPrint", "we", "us") handles data when a Shopify merchant installs and uses the GiftPrint app ("the App").
1. Who we are
GiftPrint is operated by Sole Proprietor Artem Danylov (FOP Danylov Artem), Tax ID 3459515134, trading as PG ArtLab, registered in Ukraine, with a contact address at 18a Voskresenska St, apt. 364, Kyiv, Ukraine. For any privacy-related request, contact us at support@pg-artlab.com.
2. Data we collect and store
GiftPrint stores the minimum data required to operate the App. All data is stored in a PostgreSQL database hosted on Fly.io (Amsterdam region).
2.1 Shopify session data
When a merchant installs the App, Shopify issues an OAuth session. We store:
- Shop domain (e.g.
example.myshopify.com) - Encrypted OAuth access token and refresh token
- Session state, scope, expiry
- Staff member metadata provided by Shopify: user ID, first name, last name, email, locale, account owner flag
2.2 Shop settings
For each installed shop we store:
- Current billing plan (FREE / STARTER / PRO)
- Default template ID, default page format
- Print settings (thermal mode, order footer, CJK support)
- Custom colors (Starter and Pro plans)
- QR code settings (Pro plan): whether to show a QR code and its URL
- Logo URL (Starter and Pro plans; the logo file itself is uploaded to Shopify Files, not to us)
2.3 Usage counters
For FREE plan limits we store a monthly counter per shop: shop ID, month (YYYY-MM), download count. No customer or order identifiers are attached.
We also store one row per printed card so that merchants can see their own usage statistics in the App: shop ID, month (YYYY-MM), template ID, and page format. These rows contain no customer, order, or gift-message data, and older rows are pruned automatically.
3. Data we do NOT store
GiftPrint does not persist customer or order data. Orders, gift messages, customer names, and product information are fetched from the Shopify Admin GraphQL API in real time every time a merchant opens an order or prints a card. None of it is written to our database, logs, or disk.
PDF generation runs entirely in the merchant's browser using @react-pdf/renderer. Gift messages never pass through our server on the render path.
4. Shopify scopes and why we need them
| Scope | Purpose |
|---|---|
read_orders | Read orders and gift messages to render cards |
write_orders | Write print status to order metafields and tags |
read_products, write_products | Create and maintain the hidden "Gift Note Service" product used for paid gift notes |
read_publications, write_publications | Publish the Gift Note Service product to the Online Store so the cart API accepts it |
5. Third-party services (sub-processors)
- Shopify — source of all merchant and customer data. Data flows via Shopify Admin GraphQL API v2026-04 under the merchant's OAuth token.
- Fly.io — application hosting and PostgreSQL database (ams region, Amsterdam). See Fly.io Privacy.
- Google Fonts — serves font files for HTML previews inside the admin UI. Fonts used for PDF output are bundled locally and do not touch Google.
- Twemoji (jsDelivr CDN) — emoji glyph PNGs used in PDF rendering.
GiftPrint does not use analytics, tracking pixels, advertising cookies, or third-party error reporting at this time.
6. GDPR compliance webhooks
GiftPrint implements all three Shopify compliance webhooks:
customers/data_request— GiftPrint does not store customer-identifiable data, so this webhook returns immediately with no payload to forward.customers/redact— no-op for the same reason; no customer data exists to delete.shop/redact— deletes theShoprecord, allUsageRecordrows, and relatedSessionrecords for the uninstalled shop. Shopify delivers this webhook 48 hours after uninstall.
7. Data retention
When a merchant uninstalls the App, OAuth sessions are deleted immediately. Shop settings and usage counters are retained for up to 48 hours so that reinstallation during that window preserves merchant configuration. After the shop/redact webhook fires, all data for that shop is deleted.
8. Security
- All traffic is served over HTTPS with TLS provided by Fly.io.
- OAuth sessions are verified on every admin request by
@shopify/shopify-app-remix. - GDPR and lifecycle webhooks are HMAC-verified.
- Paid features are gated server-side, not only in UI.
- Uploaded logo files are validated for MIME type and size (max 5MB).
9. Your rights
Merchants may request access, export, correction, or deletion of their data by contacting support@pg-artlab.com. Because GiftPrint stores only the data listed in Section 2, most requests can be satisfied by uninstalling the App and waiting for the automatic shop/redact flow.
10. Changes to this policy
Updates to this Privacy Policy will be reflected on this page with a new "Last updated" date.
11. Contact
Sole Proprietor Artem Danylov (FOP Danylov Artem), Tax ID 3459515134, trading as PG ArtLab
18a Voskresenska St, apt. 364, Kyiv, Ukraine
Email: support@pg-artlab.com