Privacy Policy

GrabFlow is a Shopify app that delivers digital files to customers automatically after checkout. To do that, it handles a small amount of personal data — a buyer's name and email address, their order reference, and a log of their downloads. This page explains exactly what we hold, why, who else touches it, how long it stays, and how to get it removed. Nothing else is collected.

Effective date: [Effective date]
Applies to: the Shopify app "Digital Downloads – GrabFlow", the merchant app at app.grabflow.app, the customer download pages it serves, and the website at grabflow.app.


1. Who we are, and what this policy covers

GrabFlow ("GrabFlow", "we", "us") is operated by [Legal entity name], [Business address]. GrabFlow is run by a solo developer; there is no wider staff with access to production systems.

You can reach us at support@grabflow.app for anything in this policy, including privacy requests.

This policy is written for two audiences:

It covers only GrabFlow. It does not cover the merchant's own store, which has its own privacy policy, and it does not cover Shopify itself — see Shopify's Privacy Policy. GrabFlow is an independent app and is not endorsed by or affiliated with Shopify Inc.

2. Who is responsible for buyer data: controller and processor

This distinction decides who you should contact about your data, so it is worth stating plainly.

Buyer data — the merchant is the controller, GrabFlow is the processor

For personal data about a merchant's customers (buyer name, email, order reference, download activity), the merchant is the data controller. The merchant decides that the data is collected, why, and for how long. GrabFlow is a processor: we process that data only to run the features the merchant has turned on, and never for our own purposes.

Two consequences:

Merchant and installation data — GrabFlow is the controller

For data about the merchant and the installation itself — the shop domain, the Shopify session access token, the shop's settings, and the files the merchant uploads — GrabFlow acts as the controller, because we decide how that data is used to operate, secure and support the app.

3. What we collect, where it comes from, and why

The tables below are exhaustive. If it is not listed here, GrabFlow does not collect it.

Buyer personal data (merchant is controller)

DataWhere it comes fromWhy we have it
Customer email addressShopify orders/paid webhookTo email the buyer their download links, and to locate their order when the merchant re-sends access or handles a support question
Customer nameShopify orders/paid webhookTo address the delivery email and the download page to the buyer
Shopify order id and order name (the order number)Shopify orders/paid webhookTo tie the download entitlement to the right order, so the merchant can re-send it, revoke it after a refund, and see what was delivered
Download event log: IP address and user agent, recorded when a download link is usedGenerated by the download itselfTo enforce the per-order download limit, and to show whether and when a delivery was actually collected — which is what settles "I never got my file" disputes and flags shared links

We never receive or store: payment or card details, bank details, billing or shipping addresses, phone numbers, dates of birth, government identifiers, or any special-category data. Payment is handled entirely inside Shopify's checkout; GrabFlow only ever sees that an order was paid. We do not build buyer profiles and we do no profiling or automated decision-making.

Merchant and store data (GrabFlow is controller)

DataWhere it comes fromWhy we have it
Shop domainThe Shopify install (OAuth) flowTo identify the store and keep its data separate from every other store's
Shopify session access tokenThe Shopify install (OAuth) flowTo authenticate the app and call the Shopify API on the store's behalf
Shop settings, including brandingEntered by the merchant in the appTo run the app the way the merchant configured it, and to brand the delivery email and download page
Uploaded filesUploaded by the merchantTo store the digital products and serve them to the buyers who paid for them

About uploaded files. These are the merchant's content. We store and serve them to fulfil orders; we do not open, inspect, index or analyse them. Because we have no visibility into what a file contains, merchants must not upload files containing other people's personal data unless they have a lawful basis to do so.

About billing. GrabFlow's paid plans are billed through Shopify's own billing system and appear on the merchant's Shopify invoice. GrabFlow never sees or handles card details.

4. Legal bases for processing

Buyer data. As processor, GrabFlow relies on the merchant's legal basis. In practice a merchant will typically rely on:

Merchants remain responsible for confirming the correct basis for their own circumstances.

Merchant data. As controller, GrabFlow relies on performance of a contract (providing the app to the store that installed it), legitimate interests (securing the service, preventing abuse, providing support), and legal obligation where we are required to retain records or respond to a lawful request.

5. Who else touches the data (sub-processors)

We use three infrastructure providers, all of which process data on our behalf under contract. There are no others.

Sub-processorWhat it does for GrabFlowWhat it processes
Amazon Web Services (Lightsail)Runs the application and the PostgreSQL databaseAll application data: buyer name and email, order id and order name, download event logs, shop domain, session tokens and shop settings
Cloudflare R2Stores the merchant's uploaded filesMerchant-uploaded files only
ResendDelivers the transactional download emailsThe recipient's email address and name, the order reference, and the download links in the message

Beyond these three, personal data leaves GrabFlow only where we are legally required to disclose it, or where it is needed to establish, exercise or defend a legal claim. We will tell the affected merchant unless we are legally prohibited from doing so.

What we never do:

6. International transfers

GrabFlow's application and database are hosted on Amazon Web Services (Lightsail) in eu-west-2 (London, United Kingdom). Cloudflare and Resend are, like AWS, global providers, so personal data may be processed outside the country the buyer or merchant is in.

Where personal data originating in the UK or the EEA is transferred outside that jurisdiction, we rely on the data processing terms we have with each of the three sub-processors above, which incorporate the appropriate safeguards for such transfers — the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum — or on an adequacy decision where one applies. Merchants can ask us for details of the safeguards that apply to their store by emailing support@grabflow.app.

7. How long we keep data, and what deletes it

We keep personal data only as long as it is needed to deliver and support the purchase.

DataKept until
Buyer name and email, order id and order nameKept while the app is installed, so the merchant can re-send or revoke access. Removed on a customers/redact request, and deleted entirely when the shop's data is erased after uninstall.
Download event logs (IP address, user agent)Kept while the app is installed. The IP address and user agent are stripped on a customers/redact request, and the whole record is deleted when the shop's data is erased after uninstall.
Merchant-uploaded filesKept until the merchant deletes them, or until the shop's data is erased after uninstall.
Shop domain, session access token, shop settingsKept while the app is installed, then erased after uninstall.

Shopify's privacy webhooks — the deletion triggers

Shopify requires every app to implement three mandatory privacy webhooks. GrabFlow implements all three, and each one has a concrete effect on our data:

Request from ShopifyWhat GrabFlow does
customers/data_requestSurfaces the personal data we hold about that customer so it can be given to the store owner, who is responsible for passing it to the customer.
customers/redactStrips that customer's personal data from our records: their email address, their name, and the IP address and user agent on their download events.
shop/redactFires 48 hours after the app is uninstalled, and deletes all of that shop's data — every record in our database and every stored file.

Uninstalling GrabFlow is therefore the complete off-switch: two days later, nothing of that store remains. Merchants can also ask us to delete or redact data at any time by emailing us directly.

8. How we protect it

No system can be guaranteed completely secure, but the measures above are proportionate to the small amount of data GrabFlow holds.

9. Your rights, and how to use them

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive a portable copy, withdraw consent, and complain to a supervisory authority — and not to be treated differently for exercising those rights.

If you bought a digital product from a store using GrabFlow

The store you bought from is the controller of your data, so contact that merchant first. They can raise your request through Shopify, which reaches us as a customers/data_request or customers/redact webhook, and we act on it as described in section 7. You can also email us at support@grabflow.app and we will route your request to the relevant merchant and help them answer it.

To find your records we usually need the order number and the email address used at checkout. We may need to verify your identity before acting.

If you are a merchant

Email support@grabflow.app. We can export, redact or delete your store's data on request, and uninstalling triggers full deletion automatically after 48 hours.

We respond within the time applicable law requires — normally one month under the UK/EU GDPR, and within the timeframes Shopify sets for its privacy webhooks. We do not charge for this unless a request is manifestly unfounded or excessive. If you are in the UK or EEA and are unhappy with our response, you can complain to your local data protection supervisory authority.

10. Cookies and similar technologies

The merchant app. GrabFlow is embedded inside the Shopify admin and authenticates merchants using Shopify session tokens. It sets no third-party advertising, analytics or cross-site tracking cookies. Strictly necessary cookies or browser storage may be used to keep you signed in and to complete the Shopify install flow.

The download page. A download link identifies the entitlement by the token in the link itself. There is no advertising or tracking technology on the download page.

Shopify sets its own cookies in the Shopify admin and on merchants' storefronts; those are covered by Shopify's policy and the merchant's, not by this one.

11. Children's data

GrabFlow is a business tool sold to merchants and is not directed at children. We do not knowingly collect personal data from children. The only data we hold about a buyer is what their order gives us — a name and an email address — and we have no way to determine anyone's age. Merchants are responsible for the age-appropriateness of what they sell and for any age-verification rules that apply to them.

If you believe a child's personal data has reached us, email support@grabflow.app and we will delete it or refer the request to the merchant who controls it.

12. Changes to this policy

We may update this policy when the app changes, when our sub-processors change, or when the law does. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle personal data — including adding a sub-processor — we will notify merchants by email and in the app before it takes effect. Earlier versions are available on request.

13. Contact

For any privacy question, or to exercise a right described in section 9:

Buyers: please contact the store you purchased from first — they are the controller of your data, and they can usually resolve your request faster.