Diagram: EXIF metadata removed, files kept in the merchant's own Shopify Files, GDPR ready

Privacy Policy

Last updated: July 27, 2026

File Upload Pro ("we," "our," "the app") is a Shopify application that lets a merchant's customers attach a file to their order. This policy explains what data the app processes, where it's stored, and how it's protected — for both the merchants who install File Upload Pro and their customers.

What we collect

When a customer uses the upload widget, we process:

  • The file itself (e.g. an image or PDF) and its name, type, and size
  • The cart token and, if the customer is logged in, their Shopify customer ID
  • An optional text note, if the merchant has enabled a note field
  • The order the file ends up attached to, once checkout completes

From the merchant's Shopify store, we access order, product, and customer data only as needed to attach files to orders and evaluate upload rules — for example, product tags, types, vendors, and collections, and order totals for refund actions the merchant initiates.

Where files are stored

Uploaded files are stored in the merchant's own Shopify Files library, inside their Shopify account. We do not copy them to any storage of ours and we do not use a third-party storage provider. The file is the merchant's data, held in the merchant's store.

Our own database stores only a reference to the file (its Shopify file ID and URL) plus metadata such as the original filename, type, size and the order it belongs to — never the raw file content.

Please be aware: Shopify serves files from its public content delivery network. That means the file's URL is not access-controlled — anyone who obtains the link can open it, whether or not they work for the store. To limit the risk, we store every upload under a randomly generated name, so the URL cannot be guessed and reveals nothing about the customer or the type of document. Merchants should still treat these links as confidential and avoid forwarding them.

Deleting an upload from the app deletes the underlying file from Shopify Files, which invalidates its URL.

Privacy-first image handling

Every image is automatically re-encoded on upload, which strips EXIF and GPS metadata (camera model, capture location, timestamps) before the file is stored. This happens for every upload — there's no setting to disable it.

Where data is processed

The app's infrastructure runs in the United States:

  • Shopify — stores the files themselves and all order/customer data, under Shopify's own privacy and security practices
  • Render — hosts the application server
  • Neon — hosts the Postgres database holding upload metadata, merchant settings, and session tokens

None of these providers is used for advertising or resold customer data.

Cookies & tracking

The storefront upload widget does not set cookies and does not include any third-party analytics or advertising trackers.

Data retention

Upload records and files persist until deleted — either by the merchant (from the app's Uploads page), automatically as part of a GDPR redaction request (see below), or when the merchant uninstalls the app (shop data is purged within 48 hours). We're adding merchant-configurable automatic expiry for files that are never attached to an order; until then, retention is indefinite.

Your rights (GDPR)

File Upload Pro implements Shopify's mandatory privacy webhooks:

  • Data request — when a customer asks a merchant what data is held about them, we compile the relevant upload records for the merchant
  • Customer redaction — deletes a specific customer's upload records and files
  • Shop redaction — deletes all data for a store, fired automatically after uninstall

To exercise these rights, contact the merchant's store directly, or reach us at [email protected] and we'll assist.

Payments

Subscription billing is handled entirely by Shopify's billing system. We never see or store payment card details.

Children's privacy

File Upload Pro is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect data from children.

Changes to this policy

If this policy changes materially, we'll update the "Last updated" date above. Continued use of the app after a change constitutes acceptance of the update.

Contact

Questions about this policy or your data? Email [email protected].