Flowpack — Privacy Policy

Last updated: 2026-07-26

Flowpack stores just your studio configuration — the design settings you choose (so your storefront keeps the look you picked), plus a couple of small preferences you set, like a greeting name and a brand colour. Nothing else. Flowpack never accesses, stores, or transmits your shoppers' personal data, your orders, or your customer records — the App holds no Shopify Admin API scope, so it cannot read them even in principle. Everything the shopper sees is rendered in their own browser.

1. What the App reads on your storefront (client-side only, never transmitted)

Inside the shopper's browser, to render the effects:

2. What Flowpack stores on its own servers

Your studio configuration. All requests below are signed by Shopify's app proxy, so they are verifiably from your store.

That is the complete list. There is no analytics database, no usage log, and no record of how you use the studio.

2.1 The feedback box is a mailto relay — we store nothing

The studio has a box where you can send us feedback. Choosing to send opens your own email client with a message addressed to us — exactly as if you emailed us yourself. Flowpack's servers do not receive, process, or store anything from that box; whatever you send lives only in your sent mail and our inbox, like any ordinary email. It is not a data-collection feature.

3. What Flowpack does not collect

4. Shopify-mandated compliance webhooks

Webhook requests are HMAC-verified (HMAC-SHA256, constant-time comparison) and rejected with 401 if the signature is invalid. The webhook handler verifies the signature, performs the deletion or acknowledgement, and returns — it keeps no application-level webhook log or payload.

5. Third parties who process data for us

We use no other processors, and no advertising or analytics networks.

6. Retention

There are no other records to retain — no webhook logs, no analytics, no feedback store, no usage history.

7. Data location

Flowpack's backend runs on Cloudflare's global edge network; your configuration may be stored and replicated in more than one region. Shopify hosts your store and serves the App's assets from its own CDN.

8. Your choices

9. Contact

Email: flowpackplugin@gmail.com — please include "Flowpack Privacy" in the subject line. We aim to respond within 1–2 business days.

Data controller: Kim Sun Hong (김선홍).
Postal address: 504-2204, Moa Miraedo Elga Apartment, 273 Gimpo Hanggang 2-ro, Gimpo-si, Gyeonggi-do, Republic of Korea (경기도 김포시 김포항강2로273 모아미래도엘가아파트 504동 2204호).

10. Children's privacy

The App is not directed to children under 13 (or the equivalent minimum age in any jurisdiction) and does not knowingly collect personal data from any user.

11. Changes to this policy

Updates are posted at the URL where you first read this policy; material changes are reflected in the "Last updated" date. If a change materially expands what we store, we will surface it in the App as well.

12. Your rights (GDPR / UK GDPR / CCPA / PIPEDA)

As a merchant, the configuration described in §2 relates to you and your store, and you may exercise these rights with us directly (§9): access, rectification, erasure, portability, restriction, and objection to processing.

As a shopper, Flowpack holds no personal data about you. Any personal data about you lives with the merchant whose store you visited, and those rights are exercised with that merchant. Email us if you need help identifying the right party and we will assist with attribution.