Stickerfi
Get launch updates
Get launch updates

Legal

Privacy Policy

Effective September 1, 2026 · Last updated September 1, 2026

Stickerfi is a Shopify app, operated by Eyespike Corporation (“Eyespike”, “we”, “us”), that embeds a custom sticker editor into a merchant’s storefront. A shopper uploads an image, the app removes the background and traces a die-cut contour, the shopper picks size, material and laminate, and adds the sticker to the cart. The merchant receives a print-ready PDF for each order.

This policy explains what personal data flows through Stickerfi, who is responsible for it, how long we keep it, and who else touches it. It is written for two audiences: merchants who install the app, and the shoppers who use the editor in a merchant’s store.

Questions, requests, or complaints: support@stickerfi.app.

The short version

Two roles, and which one applies

Data protection law distinguishes the party that decides why personal data is processed (the controller) from the party that processes it on that party’s behalf (the processor).

Shopper data — the merchant is the controller, we are the processor

When a shopper designs a sticker in a merchant’s store, the merchant decides that the editor is offered, sets the retention window, and owns the resulting order. We process that data only to provide the app to that merchant, under the Data Processing Agreement that every merchant accepts by installing the app.

Shoppers: if you want to access, correct, or delete your data, contact the store you ordered from. They are the controller. If you contact us directly, we will pass your request to the merchant and help them answer it — we cannot act on it independently.

Our own operational data — we are the controller

Merchant account, billing, audit and security data is ours to run the business. That part of this policy is our own commitment to merchants, not the merchant’s instruction to us.

What we process on behalf of merchants

This is the complete list. We do not collect anything else from shoppers.

Shopper email address
Taken from the Shopify order, to tie a design to its order and — where the merchant sends it — to include the design in order communication.
Free-text notes left with a design
Typed by the shopper and passed to the merchant with the order, so the sticker gets printed as intended.
Text typed into the design (text layers)
It is part of the artwork, and gets printed.
Uploaded images, and everything derived from them
The background-removed cutout, the preview, the thumbnail, and the print artwork — used to produce the sticker the shopper designed and the print-ready file the merchant fulfils.
Shopify order metadata
Order number, line items, quantities and prices — to match artwork to the right order and to bill usage.

A note about uploaded images

An upload is whatever the shopper chose to upload. It may itself contain personal data — a photo of a person, a signature, handwriting. We do not analyse uploads to identify anyone, extract faces, or build profiles; the server processes an upload only to remove its background, trace its contour, and generate the render and print files. But shoppers should upload only images they have the right to use, and merchants should keep in mind that the artwork they receive may contain personal data belonging to someone other than the shopper.

What we do not process

We do not collect or receive shopper names, postal addresses, phone numbers, payment card data, or government identifiers, and we do not process special-category data (health, biometrics for identification, race, religion, political opinion, sexual orientation, trade union membership) as a defined category. Payment information never reaches us — it is handled entirely inside Shopify’s checkout.

What we process as controller

This is what we hold to run Stickerfi as a business, with the legal basis we rely on under the GDPR.

Merchant staff identity in our audit log
Shopify staff ID, and name and email where Shopify makes them available, written to an internal audit log of privileged actions — so a privileged action can be traced to the person who took it. Legal basis: legitimate interests (securing the service and being able to investigate misuse).
Shopify shop domain and plan
To identify and support the installation. Legal basis: performance of our contract with the merchant.
Internal audit log of privileged actions
Merchant staff identity, kept for as long as it is needed to trace and investigate privileged actions on the merchant’s installation, and for a limited period after the merchant uninstalls so that a later security question can still be answered.
Contact-form submissions
Until the enquiry is resolved, and for a limited period afterwards so that we can respond to follow-up.
Billing and usage records
To charge usage-based fees through Shopify, and to keep our own financial records. Legal basis: performance of our contract; legal obligation (financial record-keeping).
Server logs
Operating, debugging and securing the service. Legal basis: legitimate interests (service reliability and security).
Contact-form submissions
The name, email address and message you send us through the contact form, so we can answer the enquiry. Legal basis: legitimate interests (responding to someone who contacted us).

Who else touches the data

We use a small, fixed set of third parties. Each is bound by its own contract and processes data only for the purpose listed.

Shopify Inc.
The platform itself: order data, the merchant’s store, app billing, and the CDN that serves design media into order communication. Location: per Shopify’s own terms and transfer safeguards. Role: platform (independent of us), and sub-processor for the data it holds.
netcup GmbH
Hosting for the server that runs the app and performs all image processing. Location: Manassas, Virginia, USA. Role: sub-processor — holds shopper data.
DigitalOcean, LLC
Hosting for the app database (Managed Databases product), which stores the app’s records of designs, orders and shopper email addresses. Location: United States. Role: sub-processor — holds shopper data.
Resend
Delivery of transactional email for messages sent through our contact form. Location: United States. Role: sub-processor (our own controller data only).
Cloudflare, Inc. (Turnstile)
Bot protection on our contact form. Location: global. Role: sub-processor (our own controller data only).

Shopper artwork and shopper order data are held only on our server at netcup, in our database at DigitalOcean, and within Shopify. Neither Resend nor Cloudflare receives any of it. All image processing happens on our own server; no image is sent to a third-party AI or image API.

We do not sell personal data, share it for advertising, use it to train machine-learning models, or send it to any third-party AI or image-processing API.

How long we keep things

Artwork is deliberately short-lived. These are the actual retention rules the app enforces:

In-progress designs
Uploads and typed notes not yet attached to an order — deleted after 24 hours.
Abandoned-cart artwork
Dereferenced after a window the merchant sets, between 1 and 14 days.
Unreferenced files
Any stored file no longer referenced by a design or order is deleted once it is 72+ hours old.
Design media on Shopify’s CDN
14 days after the order.
Artwork for completed or cancelled orders
Deleted after a configured retention window. Small preview thumbnails are kept beyond it so order history stays visual.
Server logs
14 rotations, then the oldest is discarded.
Billing and usage records
Retained as our own financial record — see below.

On uninstall

When a merchant uninstalls Stickerfi, Shopify sends us a shop/redact request approximately 48 hours later. On receiving it we erase all data for that shop — designs, artwork, order metadata, shopper email addresses.

The one exception is billing and usage records, which we retain as our own financial record of what was charged. Those are our controller data, not the merchant’s, and we keep them for as long as our accounting and tax obligations require.

Rights, and how requests are handled

Shoppers in the EU and UK (GDPR)

You have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. For anything you did in a store’s sticker editor, the merchant is the controller — send the request to them. We support the merchant in answering it, including through Shopify’s built-in privacy requests.

We implement all three of Shopify’s mandatory privacy webhooks:

customers/data_request
A shopper asks a merchant for their data; we supply what we hold.
customers/redact
A shopper asks a merchant to erase their data; we erase it.
shop/redact
A merchant uninstalls; we erase the shop’s data.

You also have the right to lodge a complaint with the supervisory authority in the EU or UK country where you live or work. We do not make any automated decisions about you that have legal or similarly significant effects.

California residents (CCPA/CPRA)

You have the right to know what personal information is collected, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising. With respect to shopper data we act as a service provider to the merchant: we process it only to perform the service, and we do not retain, use, or disclose it for any other purpose. Requests about a store’s data should go to that store.

The categories of personal information we collect, and why, are set out under what we process on behalf of merchants and what we process as controller; the retention period for each is under how long we keep things. We do not collect sensitive personal information as defined by the CPRA. Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” link. We will not discriminate against you for exercising any of these rights.

Merchants

For your own account, billing and audit data, contact us at support@stickerfi.app and we will respond. EU and UK merchants also have the right to lodge a complaint with their local supervisory authority.

Security

No system is perfectly secure, and we do not claim otherwise. We describe what we do, not a guarantee of outcome.

International transfers

Eyespike Corporation is a United States company, and all data that Stickerfi handles is stored and processed in the United States — on our server at netcup in Manassas, Virginia, in our database at DigitalOcean, and by our own staff in Florida. Shopper data is not sent to any third party or country beyond those listed under who else touches the data and Shopify. Where Shopify moves data internationally, it does so under its own data protection terms and transfer safeguards.

If you are in the EEA or UK, this means your personal data is transferred to the United States. For shopper data, the merchant is the data exporter and we are the data importer, and the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), with the UK International Data Transfer Addendum for UK transfers, as incorporated in the Data Processing Agreement every merchant accepts by installing the app. The Standard Contractual Clauses are governed by the law of Ireland. Where an adequacy decision covers a transfer, we rely on it instead. We have assessed the laws and practices of the United States as they affect this data, and will provide a summary of that assessment to a merchant on request.

Cookies and browser storage

We do not use advertising cookies, analytics that track you across sites, or any cross-site tracking on stickerfi.app or in the editor.

Cloudflare Turnstile sets what it needs to tell a person from a bot when you submit our contact form. The editor uses your browser’s own storage to hold your in-progress design so you do not lose it while designing — that stays in your browser. In the merchant admin, the app uses Shopify’s session token to keep you signed in; this is strictly necessary for the app to work and is not used for tracking.

Children

Stickerfi is a tool for merchants and their shoppers and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has submitted personal data through a store’s editor, contact the merchant, or us at support@stickerfi.app, and it will be deleted.

Changes to this policy

We will update this policy when the app changes, when we add or replace a sub-processor, or when the law requires it. The effective date at the top always reflects the current version.

For changes that materially affect how we handle merchant or shopper data, we will notify merchants — by email to the address on the Shopify account, or in the app — at least 30 days before the change takes effect, so a merchant who does not accept it has time to object or uninstall. Sub-processor changes follow the notice and objection mechanism in the Data Processing Agreement.

Contact

Eyespike Corporation

156 SW Kelliche Gln, Lake City, Florida 32024

Email: support@stickerfi.app

For data protection questions, use the same address and mark the message for the attention of the data protection contact.

Shopify is a trademark of Shopify Inc. Stickerfi is an independent app and is not endorsed by or affiliated with Shopify.