Legal
Privacy Policy
Customix is a Shopify app that lets merchants offer product personalization. This policy explains what data the app processes, why, and how long it is kept.
In this document, “merchant” means the store owner who installs the app, and “shopper” means a customer buying from that store.
1. Controller and processor
For shopper data, the merchant is the data controller. Customix acts as a processor, working on the merchant’s behalf and instructions. We do not use shopper data for our own purposes, we do not sell it, and we do not process it for marketing.
2. What we process
From the merchant
- Store domain and Shopify access token (the session record)
- The configuration you create: personalization forms, price rules, preview templates, your design library
- Subscription plan (read live from Shopify at request time, not stored)
From the shopper
- Personalization input — the text they type, the choices they make, the design they select, and where they positioned and sized their artwork
- Uploaded files — their own images or documents (JPEG, PNG, WebP, SVG, PDF)
- Order identifiers — the order number plus the name and email on the order, solely so the merchant can tell which order they are producing
We do not access shopper payment details, shipping or billing addresses, phone numbers, or Shopify accounts. We do not run behavioural tracking, advertising cookies or profiling.
3. Why we process it
- To render the personalization form and carry the input to the order
- To show the shopper a live preview of what they are buying
- To calculate personalization surcharges reliably on the server
- To produce a print-ready file and an order record for the merchant
The lawful basis is performance of the contract between the merchant and the shopper — a personalized product cannot be made without this data.
4. Where it is stored
Application data is held in a PostgreSQL database on our servers in Germany. Files uploaded by shoppers are stored in a private Cloudflare R2 bucket and are reachable only through short-lived signed links. All traffic is encrypted with TLS.
5. How long we keep it
| Data | Retention |
|---|---|
| Store configuration (forms, templates, library) | For as long as the app is installed |
| Order and personalization records | Until the merchant deletes them or uninstalls the app — they are the production and accounting record |
| Shopper-uploaded files | The same, and immediately on a deletion request |
| Session record | Deleted when the app is uninstalled |
| Encrypted database backups | 30 days, then automatically destroyed |
6. Deletion and data requests
We implement the three privacy webhooks Shopify requires, and respond to them automatically:
- Data request — when a shopper asks for their data, we assemble every record we hold about them and hand it to the merchant.
- Customer redaction — their uploaded files are deleted outright, from object storage first and the database afterwards. The order record is not deleted but anonymised: the name and email are removed, and the order remains in the merchant’s production history without identifying anyone.
- Shop redaction — after uninstall, everything belonging to that store is deleted: configuration, order records, uploaded files and sessions.
If you are a shopper with a question about your data, contact the store you bought from — they are the controller. Merchants can reach us at info@34devs.com.
7. Sub-processors
We share data only with the services needed to run the app:
- Shopify — source of store, product and order data; authentication and billing
- Cloudflare R2 — storage for uploaded files
There are no other recipients. No advertising networks, no analytics trackers, no sale of data.
8. Security
- TLS in transit; database reachable only from localhost
- Uploads in a private bucket, served via short-lived signed URLs
- Daily database backups, encrypted with AES-256
- Access to personal data is logged
- Access to production systems is limited and key-based
9. Your rights
Depending on where you live (GDPR, CCPA and similar laws), you may have the right to access, correct, delete or restrict processing of your data. Merchants can contact us at the address above; shopper requests are handled through the merchant as controller.
10. Changes
If this policy changes, the date at the top is updated. We notify merchants in-app about material changes.
11. Contact
Questions: info@34devs.com