Privacy
frontforge Shopify apps
This page is about the apps we list on the Shopify App Store, not about the marketing site. What the website itself collects is on the site privacy page.
This is a description of what the apps do, not legal advice. If you need advice about your own obligations as a merchant, that is a conversation with your counsel.
Who this covers
Every public Shopify app published by frontforge. Today that is one: Picksheet. When we add another, it gets its own section below rather than its own policy, unless its data practices genuinely differ.
Who is responsible for what
You are the controller of your shop's data: it is your store, your customers, and your decisions about what happens to their information. We are a processor — we handle that data only to do the job the app was installed for, only on your instruction, and never for our own purposes.
The formal terms for that are the data processing agreement, which applies from the moment you install and needs no signature to bind us. This page is the readable description of the same arrangement; where the two differ, the agreement governs. If your compliance process needs a countersigned copy, ask through the support form.
Words we use
- Personal data — information about an identifiable person. On a pick sheet, that is the recipient's name and shipping address.
- Controller — whoever decides why and how personal data is used. For your shop, that is you.
- Processor — whoever handles it for the controller. For Picksheet, that is us.
- Sub-processor — a company we use to run the service, listed under Where it is stored.
What we collect through Shopify's APIs
The apps read shop and order data that Shopify already holds, so they can do the job you installed them for. They do not ask your customers for anything, drop cookies on a storefront, or track how buyers move around a shop.
Picksheet
Picksheet reads orders — and the customer details those orders already carry, such as a name or a shipping address — so it can print a pick sheet or a pack slip. That data is read when you print, rendered into the sheet, and never written to our database as a customer record.
It asks for as little as the screen needs. The order list inside the app shows the recipient's name and nothing else, so that is the only customer detail it requests; the full shipping address is read only when you print a pack slip, because that is what gets addressed. Picksheet does not ask Shopify for customer email addresses or phone numbers at all.
Our server logs record which shop made a request and any error it hit. They do not record customer names or addresses. Logs rotate and are deleted after 30 days.
What we do keep is a print history: which shop printed, the Shopify order references it printed, how many, and when — no names, no addresses. It lets us answer a support question and gives us an audit trail of when order data was read. Those rows are deleted automatically after 90 days.
We do not sell this information, use it for advertising, or pass it to anyone else.
What we collect from you, the merchant
- Shopify session — that you installed the app, on which shop, and the staff account Shopify names when you open it.
- Support tickets — if you write to us, we keep the name, email, shop domain and message you sent, the same way we keep a contact-form enquiry. See the site privacy page for how long those stay and how to ask for them to be deleted.
Support tickets and sign-in
You can send a ticket from frontforge.com/support without an account. That form asks for a name, email, the app, a shop domain and a message. It also runs a Cloudflare Turnstile check so the queue is not filled by automated mail. Cloudflare sees the token and the address the request came from; we do not use that check for analytics.
To track a ticket you can sign in at myaccount.frontforge.com with Microsoft Entra External ID — Google, Microsoft, or an email one-time code. We never see or store a password. A ticket you sent as a guest is attached to that account when the email addresses match.
Where it is stored
- Railway — hosts Picksheet and its database.
- Amazon Web Services — hosts the support portal and the ticket database.
- Shopify — holds the shop and order data the app reads. Their terms and privacy policy govern that copy.
- Cloudflare — the human check on the public support form, and only then.
- Microsoft — sign-in for MyAccount, via Entra External ID.
- SMTP2GO — delivers mail when we reply to a ticket that has no portal account, and when we notify ourselves of a new one.
Processing happens outside Europe unless a later notice says otherwise. Where data leaves your region, the transfer runs under each provider's own data processing terms, which incorporate the European Commission's standard contractual clauses. We can point you at the current terms for any provider on this list if you need them for your own records.
How long we keep it
- Customer names and addresses — never stored. Read when you print, gone when the page finishes rendering.
- Print history — which shop printed which order references, and when. 90 days, then deleted automatically.
- Server logs — 30 days. No customer names or addresses in them.
- Your app session and shop record — kept while the app is installed. The session is deleted when you uninstall, and the shop record 48 hours later, when Shopify sends the shop redaction webhook.
- Support tickets — up to 24 months after last contact, or sooner if you ask.
- A MyAccount identity — while you use it, and removed on request.
The app database is backed up daily and those backups are kept for six days, with point-in-time recovery across the same window. Railway holds and encrypts them; we never take a copy out of the platform, so there is no dump on a laptop or in someone's cloud storage.
That does mean a deletion takes up to six days to become literal. It leaves the live database at once, and a copy can sit in a backup until that backup ages out. If we ever restore from one, we re-apply any deletion made in the meantime. None of those backups contain customer names or addresses, because the database never held them.
Your choices, and Shopify's webhooks
You can ask us for a copy of what we hold, or ask us to correct or delete it, through the support form.
Shopify also sends mandatory customer-data request and redaction webhooks when a shop or a customer asks. Those are handled inside the app, not on this website. Picksheet holds no buyer records, so a data request has nothing to return beyond which print jobs referenced those orders; a redaction strips those order references out of the print history, and a print job left with none is deleted. Uninstalling the app stops it reading the shop, and 48 hours later a shop redaction removes the print history, the session and the shop record.
Getting in touch
Questions about this page, or about a specific app, go to frontforge.com/support.