GrabFlow is a Shopify app that delivers digital files to customers automatically after checkout. To do that, it handles a small amount of personal data — a buyer's name and email address, their order reference, and a log of their downloads. This page explains exactly what we hold, why, who else touches it, how long it stays, and how to get it removed. Nothing else is collected.
Effective date: [Effective date]
Applies to: the Shopify app "Digital Downloads – GrabFlow", the merchant app at app.grabflow.app, the customer download pages it serves, and the website at grabflow.app.
GrabFlow ("GrabFlow", "we", "us") is operated by [Legal entity name], [Business address]. GrabFlow is run by a solo developer; there is no wider staff with access to production systems.
You can reach us at support@grabflow.app for anything in this policy, including privacy requests.
This policy is written for two audiences:
It covers only GrabFlow. It does not cover the merchant's own store, which has its own privacy policy, and it does not cover Shopify itself — see Shopify's Privacy Policy. GrabFlow is an independent app and is not endorsed by or affiliated with Shopify Inc.
This distinction decides who you should contact about your data, so it is worth stating plainly.
For personal data about a merchant's customers (buyer name, email, order reference, download activity), the merchant is the data controller. The merchant decides that the data is collected, why, and for how long. GrabFlow is a processor: we process that data only to run the features the merchant has turned on, and never for our own purposes.
Two consequences:
For data about the merchant and the installation itself — the shop domain, the Shopify session access token, the shop's settings, and the files the merchant uploads — GrabFlow acts as the controller, because we decide how that data is used to operate, secure and support the app.
The tables below are exhaustive. If it is not listed here, GrabFlow does not collect it.
| Data | Where it comes from | Why we have it |
|---|---|---|
| Customer email address | Shopify orders/paid webhook | To email the buyer their download links, and to locate their order when the merchant re-sends access or handles a support question |
| Customer name | Shopify orders/paid webhook | To address the delivery email and the download page to the buyer |
| Shopify order id and order name (the order number) | Shopify orders/paid webhook | To tie the download entitlement to the right order, so the merchant can re-send it, revoke it after a refund, and see what was delivered |
| Download event log: IP address and user agent, recorded when a download link is used | Generated by the download itself | To enforce the per-order download limit, and to show whether and when a delivery was actually collected — which is what settles "I never got my file" disputes and flags shared links |
We never receive or store: payment or card details, bank details, billing or shipping addresses, phone numbers, dates of birth, government identifiers, or any special-category data. Payment is handled entirely inside Shopify's checkout; GrabFlow only ever sees that an order was paid. We do not build buyer profiles and we do no profiling or automated decision-making.
| Data | Where it comes from | Why we have it |
|---|---|---|
| Shop domain | The Shopify install (OAuth) flow | To identify the store and keep its data separate from every other store's |
| Shopify session access token | The Shopify install (OAuth) flow | To authenticate the app and call the Shopify API on the store's behalf |
| Shop settings, including branding | Entered by the merchant in the app | To run the app the way the merchant configured it, and to brand the delivery email and download page |
| Uploaded files | Uploaded by the merchant | To store the digital products and serve them to the buyers who paid for them |
About uploaded files. These are the merchant's content. We store and serve them to fulfil orders; we do not open, inspect, index or analyse them. Because we have no visibility into what a file contains, merchants must not upload files containing other people's personal data unless they have a lawful basis to do so.
About billing. GrabFlow's paid plans are billed through Shopify's own billing system and appear on the merchant's Shopify invoice. GrabFlow never sees or handles card details.
Buyer data. As processor, GrabFlow relies on the merchant's legal basis. In practice a merchant will typically rely on:
Merchants remain responsible for confirming the correct basis for their own circumstances.
Merchant data. As controller, GrabFlow relies on performance of a contract (providing the app to the store that installed it), legitimate interests (securing the service, preventing abuse, providing support), and legal obligation where we are required to retain records or respond to a lawful request.
We use three infrastructure providers, all of which process data on our behalf under contract. There are no others.
| Sub-processor | What it does for GrabFlow | What it processes |
|---|---|---|
| Amazon Web Services (Lightsail) | Runs the application and the PostgreSQL database | All application data: buyer name and email, order id and order name, download event logs, shop domain, session tokens and shop settings |
| Cloudflare R2 | Stores the merchant's uploaded files | Merchant-uploaded files only |
| Resend | Delivers the transactional download emails | The recipient's email address and name, the order reference, and the download links in the message |
Beyond these three, personal data leaves GrabFlow only where we are legally required to disclose it, or where it is needed to establish, exercise or defend a legal claim. We will tell the affected merchant unless we are legally prohibited from doing so.
What we never do:
GrabFlow's application and database are hosted on Amazon Web Services (Lightsail) in eu-west-2 (London, United Kingdom). Cloudflare and Resend are, like AWS, global providers, so personal data may be processed outside the country the buyer or merchant is in.
Where personal data originating in the UK or the EEA is transferred outside that jurisdiction, we rely on the data processing terms we have with each of the three sub-processors above, which incorporate the appropriate safeguards for such transfers — the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — or on an adequacy decision where one applies. Merchants can ask us for details of the safeguards that apply to their store by emailing support@grabflow.app.
We keep personal data only as long as it is needed to deliver and support the purchase.
| Data | Kept until |
|---|---|
| Buyer name and email, order id and order name | Kept while the app is installed, so the merchant can re-send or revoke access. Removed on a customers/redact request, and deleted entirely when the shop's data is erased after uninstall. |
| Download event logs (IP address, user agent) | Kept while the app is installed. The IP address and user agent are stripped on a customers/redact request, and the whole record is deleted when the shop's data is erased after uninstall. |
| Merchant-uploaded files | Kept until the merchant deletes them, or until the shop's data is erased after uninstall. |
| Shop domain, session access token, shop settings | Kept while the app is installed, then erased after uninstall. |
Shopify requires every app to implement three mandatory privacy webhooks. GrabFlow implements all three, and each one has a concrete effect on our data:
| Request from Shopify | What GrabFlow does |
|---|---|
customers/data_request | Surfaces the personal data we hold about that customer so it can be given to the store owner, who is responsible for passing it to the customer. |
customers/redact | Strips that customer's personal data from our records: their email address, their name, and the IP address and user agent on their download events. |
shop/redact | Fires 48 hours after the app is uninstalled, and deletes all of that shop's data — every record in our database and every stored file. |
Uninstalling GrabFlow is therefore the complete off-switch: two days later, nothing of that store remains. Merchants can also ask us to delete or redact data at any time by emailing us directly.
No system can be guaranteed completely secure, but the measures above are proportionate to the small amount of data GrabFlow holds.
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive a portable copy, withdraw consent, and complain to a supervisory authority — and not to be treated differently for exercising those rights.
The store you bought from is the controller of your data, so contact that merchant first. They can raise your request through Shopify, which reaches us as a customers/data_request or customers/redact webhook, and we act on it as described in section 7. You can also email us at support@grabflow.app and we will route your request to the relevant merchant and help them answer it.
To find your records we usually need the order number and the email address used at checkout. We may need to verify your identity before acting.
Email support@grabflow.app. We can export, redact or delete your store's data on request, and uninstalling triggers full deletion automatically after 48 hours.
We respond within the time applicable law requires — normally one month under the UK/EU GDPR, and within the timeframes Shopify sets for its privacy webhooks. We do not charge for this unless a request is manifestly unfounded or excessive. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection supervisory authority.
The merchant app. GrabFlow is embedded inside the Shopify admin and authenticates merchants using Shopify session tokens. It sets no third-party advertising, analytics or cross-site tracking cookies. Strictly necessary cookies or browser storage may be used to keep you signed in and to complete the Shopify install flow.
The download page. A download link identifies the entitlement by the token in the link itself. There is no advertising or tracking technology on the download page.
Shopify sets its own cookies in the Shopify admin and on merchants' storefronts; those are covered by Shopify's policy and the merchant's, not by this one.
GrabFlow is a business tool sold to merchants and is not directed at children. We do not knowingly collect personal data from children. The only data we hold about a buyer is what their order gives us — a name and an email address — and we have no way to determine anyone's age. Merchants are responsible for the age-appropriateness of what they sell and for any age-verification rules that apply to them.
If you believe a child's personal data has reached us, email support@grabflow.app and we will delete it or refer the request to the merchant who controls it.
We may update this policy when the app changes, when our sub-processors change, or when the law does. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle personal data — including adding a sub-processor — we will notify merchants by email and in the app before it takes effect. Earlier versions are available on request.
For any privacy question, or to exercise a right described in section 9:
Buyers: please contact the store you purchased from first — they are the controller of your data, and they can usually resolve your request faster.