HJS Catchall Tray Designer: Privacy Policy
1. What this app is
HJS Catchall Tray Designer ("the app") is an app for Shopify stores. It adds a designer to a merchant's product page so that a shopper can design a tray (size, shape, pockets, engraving, artwork) and add it to the cart. The merchant installs it; the merchant's shoppers use it.
2. Our role
For information about a merchant's shoppers and designs, the merchant decides why and how it is used, and we process it on the merchant's behalf to run the app. For the merchant's own account details (the shop domain and app access), we decide how they are used, as described here.
3. What we collect and hold
From the merchant's store (when the app is installed)
- The store's domain (in the form
your-store.myshopify.com). - An access token and refresh token that the platform issues so the app can act on the store. They are stored encrypted (AES-256-GCM); the encryption key is held separately from the database. The app does not request per-staff-member (online) tokens, so it does not store staff names or email addresses.
- The merchant's app settings (which products have the designer switched on, and the prices and options the merchant sets in the app).
- Product data the app needs to work: the product and variant identifiers and the product's base price, read from the store. The app reads and writes products, variants and their publication only.
From a shopper who uses the designer (only when they press "Add to cart")
- The design they made: width, length, shape, corners, wood and finish, every pocket's shape, position and size, engraving text, font and position, chosen artwork, size and rotation.
- The engraving text is typed by the shopper and can contain a name or any other text the shopper chooses. We store it with the design as typed. We do not look for or extract names.
- The price we calculated for the design, the currency, the product it belongs to, a random design reference, and the time it was made.
- The network address of the shopper's request is used only in memory to limit how many requests one visitor can make in a minute. It is not written to our database.
What we do NOT collect
- We do not read customers, orders, checkouts, payments, addresses, emails or phone numbers from the store, and the app has no access permission to do so. We do not use cookies or browser storage on the storefront.
- The app does not receive card details. Payment is handled entirely by the store's own checkout.
- We do not sell personal information, and we do not use it for advertising or profiling.
Fonts
By default the storefront block loads engraving fonts from Google Fonts, so the shopper's browser contacts Google when the designer loads. The merchant can switch this off in the block settings, and then no third-party request is made. Google's own privacy policy applies to that request.
4. Why we use it
- To run the designer: price the design, check it against the merchant's limits, create the product variant that carries the price into the cart, and let the merchant see the design (the design details also travel with the cart line to the order, through the store's checkout).
- To keep the app secure and working: rate limiting, error logs, fixing faults.
- To answer support requests sent to us.
We use it for nothing else.
5. What the app does to the merchant's product catalogue
To make sure a shopper pays exactly the price they were shown, the app creates a hidden product ("shadow product", status Unlisted, tagged hjs-design) and one variant on it for each design. Shoppers cannot browse to it. The variant title and SKU carry the design reference. The merchant can delete these hidden products at any time by filtering products by the tag hjs-design (do not delete one while a cart or an unmade order still needs it). If the merchant uninstalls the app we can no longer reach the store, so any remaining hidden products can be deleted by the merchant in the same way.
6. Where it is kept and who else handles it
- Hosting: the app server and its PostgreSQL database run on Railway (railway.com). Our application logs record events and errors (such as a failed request); they are not designed to record engraving text or personal details.
- The store platform provides the store, the checkout and the network the app runs on, under its own privacy terms.
- Google Fonts (optional, section 3).
- We do not share the data with anyone else.
- International transfers: our hosting provider's servers may be located outside the UK and the EU/EEA. Where data is transferred, we rely on the safeguards the law requires.
7. How long we keep it
| Data | Kept until |
|---|---|
| Access and refresh tokens | Deleted immediately when the app is uninstalled |
| Designs (including any engraving text), app settings, the list of hidden products | Kept after uninstall (a paid design may still need making), then deleted in full when we receive the "shop redact" request, which the platform sends 48 hours after uninstall. Each item is removed from our database |
| Webhook delivery ids (a technical record used to ignore duplicates: an id, a topic and the shop domain) | Removed by shop redact |
| Support emails | For as long as needed to help, then deleted |
8. Privacy requests from the platform
We implement the three mandatory privacy webhooks:
- customers/data_request and customers/redact: we hold no customer identity (no customer id, name, email, phone or address), so there is nothing to return or delete under these. We acknowledge and record the request. If you ask us about a particular design, we can find it by its design reference and delete it.
- shop/redact: deletes every record we hold for the store (section 7).
9. Deleting your data, and your rights
Merchants: uninstalling the app deletes your tokens straight away, and all remaining records for your store are deleted when the shop redact request arrives about 48 hours later. You can also email us at any time to ask for deletion sooner.
Shoppers: to get access to, or deletion of, a design you made, ask the merchant whose store you used; the merchant can ask us to find or delete it (they email us with the shop domain and the design reference).
Depending on where you live (such as under UK or EU GDPR, or California law) you may have rights to access, correct, delete or restrict your data, to object, and to complain to your data protection authority. We will respond within the time the law requires.
10. Security
Tokens are encrypted at rest; all traffic is over HTTPS; requests from the storefront are signature-checked by the platform's app proxy and re-checked by us; webhooks are verified before they are acted on; and the app asks for the smallest set of permissions it needs. No system is perfectly secure; if we find a breach that affects you we will tell the affected merchants and the authorities as the law requires.
11. Children
The app is a tool for merchants and is not aimed at children.
12. Changes
If we change this policy we will change the date above and, for a material change, tell merchants by email.
13. Contact
HJS Apps (HJS Solutions, 102 Fanshawe Crescent, Dagenham, RM9 5EB, United Kingdom), support@hjsapps24.store. Help and support: https://www.hjsapps24.store/apps/tray-designer/support.html