Privacy Policy
Last updated 8 August 2026
Emboss lets Shopify merchants offer personalized products. A shopper types a name or uploads a photo, sees it on the product instantly, and the merchant receives a print-ready file for production.
For personal data belonging to a merchant's shoppers, the merchant is the data controller and Emboss is a data processor. We process that data only to provide the app's functionality to that merchant.
What we collect
From shoppers, on the merchant's behalf
- Text entered into personalization fields — typically a name, initials or a short message
- Photos uploaded for printing, where the merchant's design allows it
- The order and line-item identifiers needed to attach the personalization to the right order
From merchants
- Shopify store domain and the OAuth access token that authorises the app
- Product, variant and design configuration created in the app
We do not collect shipping addresses, payment details, or shopper phone numbers. We do not read the Shopify customer record's name, email, phone or address fields. We do not use any of this data for advertising, and we do not sell it or share it with third parties for their own purposes.
Why we process it
Solely to deliver the app's function: render the shopper's preview, price the personalization, produce the print-ready file, and let the merchant fulfil the order. We also screen submitted text against a trademark word list so merchants can avoid printing infringing designs.
How long we keep it
| Data | Retention |
|---|---|
| Shopper photos and rendered print files | 90 days, then automatically deleted |
| Personalization text and order links | While the merchant keeps the app installed, so their order history stays complete |
| Encrypted database backups | 14 days |
Print files can be regenerated from the stored design if a merchant needs one again. When a merchant uninstalls, Shopify sends us a redaction request and we delete that merchant's data, including their stored files.
Where it is stored and how it is protected
- Hosted on a private server in the United Arab Emirates (Oracle Cloud, Dubai region).
- Files are stored in a private object store with no public URL. Every file is served through a short-lived signed link — files are never publicly linkable.
- Encrypted in transit (HTTPS) and at rest. Backups are encrypted before they leave the server, and a restore is tested weekly.
- All communication between the storefront and our servers is cryptographically signed and verified.
- Access to stored print files is logged.
Your rights
Shoppers should contact the merchant they bought from — that merchant is the controller and can request data or erasure on your behalf. We respond to those requests through Shopify's standard privacy webhooks.
Depending on where you live you may have rights to access, correct, delete, or restrict use of your personal data, and to complain to a data protection authority.
Merchants can contact us directly at yashmehtabiz@gmail.com.
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Application and database hosting | UAE (Dubai) |
| Cloudflare R2 | File storage for uploads and print files | Western Europe |
| Shopify | The platform the app runs on | Per Shopify's own policy |
Changes
We will update this page when the app changes and revise the date above. Material changes will be communicated to merchants.
Contact
Yash Mehta — yashmehtabiz@gmail.com