Policy

Privacy, plainly written.

Ten sections. No jargon beyond what the law requires. If anything here is unclear, write to yp-privacy@allthe.com and we'll explain it.

Last updated · August 2026
§ 01

Who we are

YesPersonalized ("we", "our", "us") provides a Shopify application that enables Print-on-Demand merchants to offer personalized products to their customers. Our app URL is yespersonalized.com.

For the purposes of data protection law, we act as a data processoron behalf of merchants (data controllers) when processing their customers' personal data.

§ 02

Personal data we process

We process the minimum personal data required to deliver our service:

Merchant data — collected when you install the app

  • Shop domain — to identify your store and route requests
  • Shopify access token — stored AES-256-GCM encrypted; used to call the Shopify API on your behalf
  • Billing plan status — to enforce subscription limits

Customer data — collected when your customers personalise a product

  • Personalisation inputs — text entered by customers (names, messages) and images uploaded by customers
  • Shopify Product & Variant GIDs — to link the personalisation to the correct product
  • Shopify Order ID / Line Item ID — received via webhook when an order is placed, used solely to generate and deliver the print-ready artwork file
  • IP address — seen by our servers on every request. Used only for rate limiting, abuse prevention, and security logging. It is not linked to a personalisation session or an order, and is discarded on the schedule in §06.

We do notcollect customer names, email addresses, postal addresses, payment details, or any other identifiers beyond what is listed above. A customer's name reaches us only if the customer chooses to type it into a personalisation field, in which case we treat it as personalisation content, not as an account identifier.

§ 03

Purposes and legal basis

DataPurposeLegal basis
Shop domain & access tokenAuthenticate API calls, deliver core app functionalityContract performance (merchant ToS)
Customer personalisation inputs & uploadsGenerate print-ready artwork files per orderContract performance (merchant–customer sale)
Order / line-item IDsMatch artwork to the correct order for fulfilmentContract performance (merchant ToS)
Customer-uploaded imagesAutomated content moderation before the image enters the personalisation flowLegitimate interests (preventing illegal and abusive content on merchant storefronts)
Customer-uploaded imagesAI background removal, when a merchant invokes the featureContract performance (merchant–customer sale)
Billing plan statusEnforce subscription entitlementsContract performance (merchant ToS)
IP addressRate limiting, abuse prevention, security loggingLegitimate interests (keeping the service available and secure)

We do not use personal data for any purpose other than those listed above.

Optional manual review by merchants. Merchants can enable a manual review step in their app settings. When enabled, every personalised order is parked for the merchant to approve or reject before the print artwork renders. This gives merchants final oversight on the content their customers submit. The merchant sees the same data described in this section — personalisation inputs and uploaded images — and acts as the data controller for that review decision. We do not perform manual review on behalf of merchants.

§ 04

Data sharing and sub-processors

We share personal data only with the sub-processors listed below, and only to the extent necessary. This list is complete: no other third party receives personal data from us.

Infrastructure — always in the path

  • Shopify Inc. — the platform the app runs on. We receive webhook events containing order and shop data, and call the Shopify Admin API on the merchant's behalf.
  • Vercel Inc. — application hosting and edge delivery. Processes every request in transit, including personalisation inputs on their way to storage.
  • Supabase (Postgres, hosted on AWS) — the primary database. Stores merchant account records, personalisation session data, and order/artwork references.
  • Cloudflare R2 — object storage for customer-uploaded images and generated artwork files (Cloudflare DPA).
  • Inngest Inc. — background job orchestration. Artwork rendering runs as a queued job; job payloads carry session, order and line-item identifiers.
  • Upstash (Redis) — rate limiting and abuse prevention. Stores short-lived counters keyed on IP address and shop domain. No personalisation content is stored.

Content moderation — mandatory, every upload

  • Amazon Web Services — Amazon Rekognition — every customer-uploaded image is scanned for prohibited content (illegal material, violence, hate symbols) before it enters the personalisation flow. Images are processed in the AWS region we operate in and are not retained by AWS after the scan. This is mandatory and cannot be disabled by merchants. If the scanning service is unavailable, uploads are refused rather than passed through unchecked.

AI background removal — only when a merchant uses the feature

Background removal runs through a provider chain: the first configured provider handles the request, and the next is tried only if that provider fails or cannot process the image. Any of the three below may therefore receive a given image. The feature is available on Silver plans and above, and no image is sent to any of them unless a merchant explicitly invokes it.

  • Replicate Inc. — primary provider, running the 851-labs/background-remover model. Customer-uploaded images are sent for processing and are not used to train models.
  • Amazon Web Services — Amazon Bedrock (Amazon Nova Canvas model) — second in the chain. Images are processed in the AWS region we operate in and are not retained by AWS after processing.
  • remove.bg (Kaleido AI GmbH) — final fallback, used only when both providers above are unavailable or unable to process the image.

Operations

  • Resend — transactional email (support replies, account and billing notices). Receives the recipient address and message content. Customer personalisation inputs are never included.
  • Sentry — application error reporting. Stack traces and request metadata may be transmitted; customer personalisation inputs and uploaded images are excluded from error reports.

We do not sell personal data to third parties, and we do not send personal data to any advertising, analytics, or profiling service.

International transfers

Several of the providers above operate in the United States. Where personal data originating in the UK or EEA is transferred outside it, that transfer is covered by the provider's Standard Contractual Clauses (and the UK Addendum where applicable), incorporated through the data processing agreement we hold with each of them.

§ 06

Data retention

We retain personal data only as long as necessary for the stated purpose:

  • Personalisation sessions that never became an order — deleted once the session expires, 30 days after the customer created it (long enough to honour a saved cart that is checked out later)
  • Order personalisation inputs, uploaded images & generated artwork — retained for 90 days from the date the personalised order was received, then permanently deleted. Regenerating the artwork in the app extends this by 30 days from the regeneration, because the point of regenerating a file is to download it and a file deleted immediately afterwards would be useless to the merchant. Repeated regeneration extends it repeatedly.
  • Merchant account data (shop domain, encrypted token, billing status) — retained for the duration of the merchant's subscription, then deleted within 30 days of app uninstallation
  • Order IDs — retained only as long as the associated artwork file exists
  • IP addresses — rate-limit counters expire within minutes; security logs are retained for up to 30 days, then discarded

Images sent to our moderation and background-removal providers are processed and returned, not stored by them for their own purposes. Deleting data on our side therefore removes it everywhere it was held.

§ 07

Security

  • Encryption in transit — all communication between our app, Shopify, and end users is over HTTPS/TLS
  • Encryption at rest — Shopify access tokens are encrypted using AES-256-GCM before storage; uploaded files and artwork are stored in encrypted object storage
  • Access control — all data is partitioned by shop ID; no merchant can access another merchant's data
  • HMAC verification — all incoming Shopify webhooks are verified using HMAC-SHA256 before processing
  • Connection logs — standard server logs (IP address, request path, timestamp) are retained for up to 30 days for security, abuse prevention, and rate-limiting. They are not used for any other purpose and are not linked to customer identities.
§ 08

GDPR — merchant and customer rights

We support Shopify's mandatory GDPR webhook topics. When Shopify sends us a data request or erasure request on behalf of a customer, we process it as follows:

  • customers/data_request — we provide merchants with an export of any personal data we hold linked to the identified customer
  • customers/redact — we permanently delete all personal data linked to the identified customer within 30 days
  • shop/redact — we permanently delete all data associated with the merchant's shop within 30 days of receiving this request

If you are a merchant and wish to exercise your own rights (access, rectification, erasure, portability), contact us at yp-privacy@allthe.com.

§ 09

Changes to this policy

We may update this policy from time to time. We will notify merchants of material changes via email or an in-app notice at least 14 days before the changes take effect. Continued use of the app after that date constitutes acceptance of the updated policy.

§ 10

Contact

For any privacy-related questions or requests, contact us at yp-privacy@allthe.com.

— That's the policy, in full. Anything unclear? The address above gets a reply from a human.