Privacy policy
Last updated: October 10, 2026
ProofBolt Studios is a Shopify app made by Proofbolt LLC ("we", "us"). It adds custom-patch designers (Patch Studio, a patch gang sheet and a leatherette sheet designer) to a Shopify store. This policy explains what data the app processes, why, where it is kept, and the choices merchants and their customers have. Questions: email admin@proofbolt.com.
Who is responsible for what
- For data about a store's customers, the merchant (the store owner) is the controller and we act as their processor, under our Data processing agreement. We only process customer data on the merchant's instructions, to provide the app.
- For data about the merchant (the store and its staff using the app), we are the controller.
What we process and why
Merchant data - Store details: shop domain, store name, currency and primary domain. Used to run the app for that store. - App settings: builders, materials, colors, prices, plan and billing status. - Access token: the Shopify access token the app uses to act for the store. Stored encrypted (AES-256-GCM); never shown or logged. - Staff user id: the Shopify staff user id in the admin session, recorded in our access log when staff view order data (see "Security").
Customer data (on behalf of the merchant) - Designs and uploaded artwork: the logos and images customers upload and the designs they make, plus the print and cut files we produce. Needed to make the order. - Shopify customer id and order ids/line details: to file each design under the customer's "My patches" so they can reorder it. - Email (guest orders only): we do not store a guest's email. We store a one-way SHA-256 hash of it as a key, so their designs can be moved to their account when they sign in. When a signed-in customer opens "My patches", the app reads their email from Shopify once to do that move; it isn't stored. - Name: the store's order list in the app shows the customer's name, read live from Shopify. We don't store it. - Name, email and addresses in new-order notifications: Shopify includes these in the order webhook the app receives. We only read the line items and the customer id from it; the rest is not stored, logged or used. - We do not collect phone numbers, payment details, or anything not listed here.
Storefront visitors - The designer sets no cookies and no tracking or analytics. A visitor's IP address is used briefly to rate-limit uploads and is not stored.
What we never do
- We never use customer data for marketing, advertising, profiling or analytics, never sell or rent it, and never combine it with data from other stores.
- We never send customers emails or messages. Only the merchant's own Shopify store does that, under the merchant's own consent settings, which we don't change.
- Customer data is used only to provide the designers, fulfill orders and let customers reorder (and for legal compliance and support the merchant asks for).
Where data is kept, and for how long
- Data is stored with Amazon Web Services in the United States (us-east-1), encrypted at rest (DynamoDB with AWS KMS, S3 with AES-256) and in transit (TLS only).
- Each store's data is kept separate (per-store keys and storage folders).
- Saved designs are kept while the app is installed so customers can reorder. Deleted copies and database backups expire within 35 days.
- Uninstalling: Shopify tells us 48 hours after an uninstall (shop/redact) and we then delete the store's data: settings, access token, saved designs and files.
- Customer deletion requests (customers/redact): we delete that customer's saved designs and files.
- Customer data requests (customers/data_request): we export everything we hold about that customer to the merchant.
- Access logs are kept for about a year, then deleted.
Who else processes data (subprocessors)
- Shopify: the platform the app runs on.
- Amazon Web Services: hosting, database and file storage (US).
- Image tools (OpenAI, fal.ai, Replicate, Photoroom) are not used by the public app today. If we turn one on for an optional feature (for example AI pattern generation or background removal), only the artwork image is sent, never customer details, and we will update this list first.
Your rights
Customers should contact the store they ordered from: the merchant controls their data and can ask us to access, export or delete it, which we do through Shopify's privacy requests. Merchants can email admin@proofbolt.com for any request about their own data. Residents of the EU/UK, California and other places with privacy laws have the rights those laws give, including access, correction, deletion and objection.
Security
We use least-privilege access, encryption, logging of access to personal data, and a written incident response plan. If a breach affects a store's data, we tell the merchant without undue delay, and within 72 hours of confirming it.
Changes
We'll post changes here and update the date above. For significant changes we'll tell merchants in the app first.