Flowpack — Privacy Policy
Last updated: 2026-07-26
Flowpack stores just your studio configuration — the design settings you choose (so your storefront
keeps the look you picked), plus a couple of small preferences you set, like a greeting name and a brand colour.
Nothing else. Flowpack never accesses, stores, or transmits your shoppers' personal data,
your orders, or your customer records — the App holds no Shopify Admin API scope, so it cannot read them even in
principle. Everything the shopper sees is rendered in their own browser.
1. What the App reads on your storefront (client-side only, never transmitted)
Inside the shopper's browser, to render the effects:
- Your theme's own elements — Add-to-Cart buttons, cart icon, product images, variant pickers — read
to compose motion on top of them. Nothing is sent anywhere.
- Product availability shown on the page (e.g. a variant's stock state) — used to decide whether an
honest "Only N left" or "Sold out" treatment may render. Read live in the browser, never transmitted or stored by us.
- Browser preferences —
prefers-reduced-motion, viewport size, pointer type — read
locally to gate which effects play. Never transmitted.
2. What Flowpack stores on its own servers
Your studio configuration. All requests below are signed by Shopify's app proxy, so they
are verifiably from your store.
- What: the design choices you make (for example: button hover style, badge style and position,
colour values you pick, free-shipping threshold, tap-to-add shape/texture, seasonal overlay) — including any custom text
you type into a badge, free-shipping bar, or shipping-cutoff bar, a shipping-cutoff time if you set one, an optional
greeting name you set so the studio can greet you by it on your next visit, and a saved
brand colour (a hex value). None of these are shopper data; all are deleted on uninstall (see §4
shop/redact).
- Identifier: your store's
myshopify.com domain.
- Where: Cloudflare Workers KV (see §5).
- Why: so the look you chose persists and renders for shoppers after you close the studio.
- Also stored: a staged (not-yet-published) copy of that configuration while you are still editing,
and short-lived one-time tokens used to prevent replay of admin requests.
That is the complete list. There is no analytics database, no usage log, and no record of how you use the studio.
2.1 The feedback box is a mailto relay — we store nothing
The studio has a box where you can send us feedback. Choosing to send opens your own email client with
a message addressed to us — exactly as if you emailed us yourself. Flowpack's servers do not receive, process, or store
anything from that box; whatever you send lives only in your sent mail and our inbox, like any ordinary email. It is not
a data-collection feature.
3. What Flowpack does not collect
- ❌ No shopper (end-customer) personal data of any kind — names, emails, addresses, payment data.
- ❌ No order, customer, or catalogue data — the App requests no Shopify Admin API scope.
- ❌ No usage analytics, no feedback records, no behavioural logging — the App keeps no record of
which designs you pick or how you use the studio.
- ❌ No cookies set by the App; no browser fingerprinting.
- ❌ No third-party analytics, advertising SDKs, or trackers.
- ❌ No selling or sharing of any data, ever.
- ℹ️ We do not use IP addresses as a product feature or keep them in our application records. Our infrastructure
providers necessarily process connection metadata to deliver the service (see §5).
4. Shopify-mandated compliance webhooks
customers/data_request — Flowpack holds no customer-specific data, so there is nothing to export; we
respond with that acknowledgement.
customers/redact — nothing to delete; Flowpack stores no customer data.
shop/redact — We delete the shop's stored configuration (live and staged). That is the
only shop-scoped data we hold, so a successful shop/redact leaves nothing behind. Requests are HMAC-verified
and rejected with 401 if unsigned.
Webhook requests are HMAC-verified (HMAC-SHA256, constant-time comparison) and rejected with 401 if the signature is
invalid. The webhook handler verifies the signature, performs the deletion or acknowledgement, and returns — it keeps no
application-level webhook log or payload.
5. Third parties who process data for us
- Shopify — hosts your store, serves the App's static assets from its CDN, and signs the app-proxy
requests.
- Cloudflare — runs the App's backend (Workers) and stores your configuration (Workers KV).
Cloudflare processes connection metadata as part of delivering the service.
We use no other processors, and no advertising or analytics networks.
6. Retention
- Studio configuration — kept while the App is installed, so your storefront keeps working. Deleted
when we receive
shop/redact (i.e. on uninstall). You can also ask us to delete it sooner (see §9).
There are no other records to retain — no webhook logs, no analytics, no feedback store, no usage history.
7. Data location
Flowpack's backend runs on Cloudflare's global edge network; your configuration may be stored and replicated in more
than one region. Shopify hosts your store and serves the App's assets from its own CDN.
8. Your choices
- Custom text is yours. Anything you type into a badge or bar — and the optional greeting name — is stored as part of your configuration,
as described in §2 — if you would rather it not be, avoid putting sensitive or identifying information in those fields.
- Deletion. Uninstalling triggers
shop/redact, which erases your configuration; you can
also email us to have it removed sooner.
9. Contact
Email: flowpackplugin@gmail.com — please include
"Flowpack Privacy" in the subject line. We aim to respond within 1–2 business days.
Data controller: Kim Sun Hong (김선홍).
Postal address: 504-2204, Moa Miraedo Elga Apartment, 273 Gimpo Hanggang 2-ro, Gimpo-si,
Gyeonggi-do, Republic of Korea (경기도 김포시 김포항강2로273 모아미래도엘가아파트 504동 2204호).
10. Children's privacy
The App is not directed to children under 13 (or the equivalent minimum age in any jurisdiction) and does not
knowingly collect personal data from any user.
11. Changes to this policy
Updates are posted at the URL where you first read this policy; material changes are reflected in the "Last updated"
date. If a change materially expands what we store, we will surface it in the App as well.
12. Your rights (GDPR / UK GDPR / CCPA / PIPEDA)
As a merchant, the configuration described in §2 relates to you and your store, and you may exercise
these rights with us directly (§9): access, rectification, erasure, portability, restriction, and objection to
processing.
As a shopper, Flowpack holds no personal data about you. Any personal data about you lives with the
merchant whose store you visited, and those rights are exercised with that merchant. Email us if you need help
identifying the right party and we will assist with attribution.