Legal
Privacy Policy
Effective September 1, 2026 · Last updated September 1, 2026
Stickerfi is a Shopify app, operated by Eyespike Corporation (“Eyespike”, “we”, “us”), that embeds a custom sticker editor into a merchant’s storefront. A shopper uploads an image, the app removes the background and traces a die-cut contour, the shopper picks size, material and laminate, and adds the sticker to the cart. The merchant receives a print-ready PDF for each order.
This policy explains what personal data flows through Stickerfi, who is responsible for it, how long we keep it, and who else touches it. It is written for two audiences: merchants who install the app, and the shoppers who use the editor in a merchant’s store.
Questions, requests, or complaints: support@stickerfi.app.
The short version
- For everything a shopper does in the editor, the merchant owns the data. The merchant is the controller; we are the processor acting on the merchant’s instructions.
- For running our own business — billing a merchant, keeping the service secure, answering support email — we are the controller.
- We do not see payment card details. Checkout is Shopify’s, not ours.
- We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising.
- All image processing — background removal, contour tracing, PDF generation — runs on our own server. No third-party AI or image API receives shopper artwork.
- Uploaded artwork is short-lived by design. Most of it is deleted within hours or days.
Two roles, and which one applies
Data protection law distinguishes the party that decides why personal data is processed (the controller) from the party that processes it on that party’s behalf (the processor).
Shopper data — the merchant is the controller, we are the processor
When a shopper designs a sticker in a merchant’s store, the merchant decides that the editor is offered, sets the retention window, and owns the resulting order. We process that data only to provide the app to that merchant, under the Data Processing Agreement that every merchant accepts by installing the app.
Shoppers: if you want to access, correct, or delete your data, contact the store you ordered from. They are the controller. If you contact us directly, we will pass your request to the merchant and help them answer it — we cannot act on it independently.
Our own operational data — we are the controller
Merchant account, billing, audit and security data is ours to run the business. That part of this policy is our own commitment to merchants, not the merchant’s instruction to us.
What we process on behalf of merchants
This is the complete list. We do not collect anything else from shoppers.
- Shopper email address
- Taken from the Shopify order, to tie a design to its order and — where the merchant sends it — to include the design in order communication.
- Free-text notes left with a design
- Typed by the shopper and passed to the merchant with the order, so the sticker gets printed as intended.
- Text typed into the design (text layers)
- It is part of the artwork, and gets printed.
- Uploaded images, and everything derived from them
- The background-removed cutout, the preview, the thumbnail, and the print artwork — used to produce the sticker the shopper designed and the print-ready file the merchant fulfils.
- Shopify order metadata
- Order number, line items, quantities and prices — to match artwork to the right order and to bill usage.
A note about uploaded images
An upload is whatever the shopper chose to upload. It may itself contain personal data — a photo of a person, a signature, handwriting. We do not analyse uploads to identify anyone, extract faces, or build profiles; the server processes an upload only to remove its background, trace its contour, and generate the render and print files. But shoppers should upload only images they have the right to use, and merchants should keep in mind that the artwork they receive may contain personal data belonging to someone other than the shopper.
What we do not process
We do not collect or receive shopper names, postal addresses, phone numbers, payment card data, or government identifiers, and we do not process special-category data (health, biometrics for identification, race, religion, political opinion, sexual orientation, trade union membership) as a defined category. Payment information never reaches us — it is handled entirely inside Shopify’s checkout.
What we process as controller
This is what we hold to run Stickerfi as a business, with the legal basis we rely on under the GDPR.
- Merchant staff identity in our audit log
- Shopify staff ID, and name and email where Shopify makes them available, written to an internal audit log of privileged actions — so a privileged action can be traced to the person who took it. Legal basis: legitimate interests (securing the service and being able to investigate misuse).
- Shopify shop domain and plan
- To identify and support the installation. Legal basis: performance of our contract with the merchant.
- Internal audit log of privileged actions
- Merchant staff identity, kept for as long as it is needed to trace and investigate privileged actions on the merchant’s installation, and for a limited period after the merchant uninstalls so that a later security question can still be answered.
- Contact-form submissions
- Until the enquiry is resolved, and for a limited period afterwards so that we can respond to follow-up.
- Billing and usage records
- To charge usage-based fees through Shopify, and to keep our own financial records. Legal basis: performance of our contract; legal obligation (financial record-keeping).
- Server logs
- Operating, debugging and securing the service. Legal basis: legitimate interests (service reliability and security).
- Contact-form submissions
- The name, email address and message you send us through the contact form, so we can answer the enquiry. Legal basis: legitimate interests (responding to someone who contacted us).
Who else touches the data
We use a small, fixed set of third parties. Each is bound by its own contract and processes data only for the purpose listed.
- Shopify Inc.
- The platform itself: order data, the merchant’s store, app billing, and the CDN that serves design media into order communication. Location: per Shopify’s own terms and transfer safeguards. Role: platform (independent of us), and sub-processor for the data it holds.
- netcup GmbH
- Hosting for the server that runs the app and performs all image processing. Location: Manassas, Virginia, USA. Role: sub-processor — holds shopper data.
- DigitalOcean, LLC
- Hosting for the app database (Managed Databases product), which stores the app’s records of designs, orders and shopper email addresses. Location: United States. Role: sub-processor — holds shopper data.
- Resend
- Delivery of transactional email for messages sent through our contact form. Location: United States. Role: sub-processor (our own controller data only).
- Cloudflare, Inc. (Turnstile)
- Bot protection on our contact form. Location: global. Role: sub-processor (our own controller data only).
Shopper artwork and shopper order data are held only on our server at netcup, in our database at DigitalOcean, and within Shopify. Neither Resend nor Cloudflare receives any of it. All image processing happens on our own server; no image is sent to a third-party AI or image API.
We do not sell personal data, share it for advertising, use it to train machine-learning models, or send it to any third-party AI or image-processing API.
How long we keep things
Artwork is deliberately short-lived. These are the actual retention rules the app enforces:
- In-progress designs
- Uploads and typed notes not yet attached to an order — deleted after 24 hours.
- Abandoned-cart artwork
- Dereferenced after a window the merchant sets, between 1 and 14 days.
- Unreferenced files
- Any stored file no longer referenced by a design or order is deleted once it is 72+ hours old.
- Design media on Shopify’s CDN
- 14 days after the order.
- Artwork for completed or cancelled orders
- Deleted after a configured retention window. Small preview thumbnails are kept beyond it so order history stays visual.
- Server logs
- 14 rotations, then the oldest is discarded.
- Billing and usage records
- Retained as our own financial record — see below.
On uninstall
When a merchant uninstalls Stickerfi, Shopify sends us a shop/redact request approximately 48 hours later. On receiving it we erase all data for that shop — designs, artwork, order metadata, shopper email addresses.
The one exception is billing and usage records, which we retain as our own financial record of what was charged. Those are our controller data, not the merchant’s, and we keep them for as long as our accounting and tax obligations require.
Rights, and how requests are handled
Shoppers in the EU and UK (GDPR)
You have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. For anything you did in a store’s sticker editor, the merchant is the controller — send the request to them. We support the merchant in answering it, including through Shopify’s built-in privacy requests.
We implement all three of Shopify’s mandatory privacy webhooks:
- customers/data_request
- A shopper asks a merchant for their data; we supply what we hold.
- customers/redact
- A shopper asks a merchant to erase their data; we erase it.
- shop/redact
- A merchant uninstalls; we erase the shop’s data.
You also have the right to lodge a complaint with the supervisory authority in the EU or UK country where you live or work. We do not make any automated decisions about you that have legal or similarly significant effects.
California residents (CCPA/CPRA)
You have the right to know what personal information is collected, to have it deleted, to correct it, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising. With respect to shopper data we act as a service provider to the merchant: we process it only to perform the service, and we do not retain, use, or disclose it for any other purpose. Requests about a store’s data should go to that store.
The categories of personal information we collect, and why, are set out under what we process on behalf of merchants and what we process as controller; the retention period for each is under how long we keep things. We do not collect sensitive personal information as defined by the CPRA. Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” link. We will not discriminate against you for exercising any of these rights.
Merchants
For your own account, billing and audit data, contact us at support@stickerfi.app and we will respond. EU and UK merchants also have the right to lodge a complaint with their local supervisory authority.
Security
- All image processing runs on infrastructure we control. Artwork is not sent to third-party APIs.
- Access to production data is restricted to the people who need it to operate the service.
- Data in transit is protected with TLS. Stored files are held in access-controlled storage on our server. The app database is a managed database hosted by DigitalOcean, with encryption at rest and in transit, access restricted to the app server and authorised personnel, and automated backups managed by the provider.
- We maintain an internal audit log of privileged actions, recording the identity of the person who took each action.
- We have a written security incident response policy. If a personal data breach affects a merchant’s data, we notify that merchant without undue delay, targeting within 72 hours of becoming aware, with the information they need to meet their own notification obligations.
- Data is retained for the short windows described above precisely so that there is less to lose.
No system is perfectly secure, and we do not claim otherwise. We describe what we do, not a guarantee of outcome.
International transfers
Eyespike Corporation is a United States company, and all data that Stickerfi handles is stored and processed in the United States — on our server at netcup in Manassas, Virginia, in our database at DigitalOcean, and by our own staff in Florida. Shopper data is not sent to any third party or country beyond those listed under who else touches the data and Shopify. Where Shopify moves data internationally, it does so under its own data protection terms and transfer safeguards.
If you are in the EEA or UK, this means your personal data is transferred to the United States. For shopper data, the merchant is the data exporter and we are the data importer, and the transfer is made under the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), with the UK International Data Transfer Addendum for UK transfers, as incorporated in the Data Processing Agreement every merchant accepts by installing the app. The Standard Contractual Clauses are governed by the law of Ireland. Where an adequacy decision covers a transfer, we rely on it instead. We have assessed the laws and practices of the United States as they affect this data, and will provide a summary of that assessment to a merchant on request.
Cookies and browser storage
We do not use advertising cookies, analytics that track you across sites, or any cross-site tracking on stickerfi.app or in the editor.
Cloudflare Turnstile sets what it needs to tell a person from a bot when you submit our contact form. The editor uses your browser’s own storage to hold your in-progress design so you do not lose it while designing — that stays in your browser. In the merchant admin, the app uses Shopify’s session token to keep you signed in; this is strictly necessary for the app to work and is not used for tracking.
Children
Stickerfi is a tool for merchants and their shoppers and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has submitted personal data through a store’s editor, contact the merchant, or us at support@stickerfi.app, and it will be deleted.
Changes to this policy
We will update this policy when the app changes, when we add or replace a sub-processor, or when the law requires it. The effective date at the top always reflects the current version.
For changes that materially affect how we handle merchant or shopper data, we will notify merchants — by email to the address on the Shopify account, or in the app — at least 30 days before the change takes effect, so a merchant who does not accept it has time to object or uninstall. Sub-processor changes follow the notice and objection mechanism in the Data Processing Agreement.
Contact
Eyespike Corporation
156 SW Kelliche Gln, Lake City, Florida 32024
Email: support@stickerfi.app
For data protection questions, use the same address and mark the message for the attention of the data protection contact.
Shopify is a trademark of Shopify Inc. Stickerfi is an independent app and is not endorsed by or affiliated with Shopify.
