Legal
Privacy Policy
Last updated
FlowPrinter runs online storefronts for independent shipping stores and print shops. This policy explains what information passes through the service, what we do with it, and what you can ask of us.
It covers two kinds of people. Store owners open an account with us directly. Customers buy from a store that runs on FlowPrinter; their relationship is with that store, and we handle their information on the store’s behalf. Where the two differ, this policy says so.
What we collect from store owners
- Account: your store name, web address, work email and password. Passwords are stored only as a hash by our sign-in provider; we cannot read them.
- Store details: address, phone, contact email, logo, colors, About text, products, options and prices, fulfilment settings, and anything else you enter in your dashboard. Much of this is shown publicly on your storefront because that is what it is for.
- Payments setup: your Stripe account ID and whether it can take charges. Your bank details and Stripe login never pass through us.
- Subscription: your plan, billing cycle, status and period dates, plus the Stripe customer and subscription IDs that link them. Your card is held by Stripe.
- Integrations: if you connect PrintJobFlow, the API key you paste. It is kept in a table only your store’s admins and platform administrators can read.
What we collect from customers
- Account: an email, password and name, created when you first check out. This is a FlowPrinter account: the same sign-in works at any store on the platform, and each store sees only the orders you placed with it.
- Orders: what you ordered and the options you chose, the price, your phone number, a shipping or delivery address when the order is not for pickup, any coupon you used, and special instructions you wrote.
- Artwork: the files you upload for printing, and any previews made from them.
- Payment: your card details go straight from your browser to Stripe. We receive a confirmation that the payment succeeded and an identifier for it, never the card number.
What is collected automatically
- Sign-in cookies. When you sign in, a cookie keeps you signed in. It is the only cookie the service sets itself; there are no advertising or tracking cookies.
- Your cart is kept in your browser’s local storage so it survives a page reload. It is not sent to us until you check out.
- Page-view analytics from Vercel: which pages are visited and roughly from where, aggregated and without cookies or a per-person identifier.
- Server logs at our hosting and database providers record requests — IP address, browser, time — for a limited period, for security and debugging.
What we do with it
We use this information to run the service and for nothing else:
- to show a store, take an order, and get the artwork to whoever prints it;
- to send the emails the service is built around — order confirmations and ready-for-pickup notices to customers, new-order alerts and quote requests to stores, and trial and billing notices to store owners;
- to bill store subscriptions and to help Stripe pay stores;
- to answer support requests;
- to keep the service secure — spotting abuse, retrying failed steps, investigating problems;
- to understand, in aggregate, how the service is used so we can improve it.
We do not sell personal information, use it for advertising, or share it with anyone except as this policy says.
How long we keep it
- Store accounts stay while the store is active, and for a reasonable period after it closes so the owner can come back. Deleted on request.
- Orders are business records of the store that took them and are kept for as long as the store keeps them.
- Artwork is kept so an order can be checked, reprinted or reordered. There is no automatic deletion at present; you can ask the store, or us, to remove a file once the order is complete.
- Server logs are kept briefly by our providers and then discarded.
How it is protected
Everything travels over encrypted connections. Each store’s data is separated from every other store’s by access rules enforced in the database itself, not only in the app. Artwork is stored in a private bucket and handed out through short-lived links only to the customer who uploaded it, the store that took the order, a store the job was routed to for production, and platform administrators — who must use two-factor authentication.
No service can promise perfect security. If we learn of a breach affecting your information, we will tell the affected store or customer without undue delay.
Your choices and rights
You can see and change your account details by signing in. Customers can see their orders at any store under My Orders. Store owners can edit or remove anything in their dashboard.
You can ask us to give you a copy of your information, correct it, or delete it. Customers should ask the store they bought from first, since the store holds the order; we will help either of you. Where a law such as the GDPR or the California Consumer Privacy Act gives you further rights, you have them here too, and we will not treat you differently for using them.
The emails the service sends are about your orders and your account rather than marketing, so there is nothing to unsubscribe from; if you no longer want an account, ask and we will close it.
Children
FlowPrinter is for businesses and their customers and is not directed at children. We do not knowingly collect information from anyone under 16; if you believe we have, tell us and we will delete it.
Where it is stored
The service is hosted in the United States, and the providers named above process information there. If you use it from elsewhere, your information is transferred to and handled in the United States.
Changes and contact
When this policy changes in a way that matters, we will email store owners before it takes effect and update the date at the top of this page. The Terms of Service govern your use of FlowPrinter.
Questions, requests, or concerns about privacy: hello@flowprinter.com.