Simple Stencil Customizer Privacy Policy

Effective date: July 14, 2026
Controller for this policy: Dotarus, LLC, doing business as Dotarus
Privacy contact: hello@dotarus.com · 6811 E 127th St S, Bixby, OK 74008

This Privacy Policy explains how Dotarus handles personal data when operating Simple Stencil Customizer (the “App”). It applies to Merchant users of the App and to personal data the App processes for a Merchant in connection with that Merchant’s Shopify store.

1. Data we process

Depending on enabled features, the App may process:

  • Merchant account and store information supplied through Shopify, including store domain and authorized session information.
  • Merchant settings, such as material, font, pricing, branding, and email configuration. Merchant-provided third-party email credentials are encrypted at rest.
  • Customer-related identifiers received from Shopify, such as a Shopify customer ID, Shopify order ID, and, while a proof-email job is being processed, a customer email address and first name.
  • Customer design content, including text, notes, uploaded artwork, clip-art selections, dimensions, generated SVG/DXF/PNG/PDF assets, and order-linked design data.
  • Support messages, feature requests, and diagnostic information that a Merchant chooses to send.
  • Technical and security data necessary to authenticate requests, process webhooks, prevent abuse, and investigate errors.

The App does not sell personal data or use customer personal data for cross-context behavioral advertising.

2. Why we process data

We process data to provide the App: authenticate Merchants; display and save design configuration; generate previews and production files; calculate prices; create or support Shopify checkout and Draft Order workflows; send configured emails; provide support; secure the App; comply with law; and improve reliability.

When we process a Merchant’s customer data to provide the App, the Merchant is generally the controller/business and Dotarus acts as processor/service provider, as described in the Data Processing Addendum.

3. How data is shared

We share data only as needed to operate the App, including with:

  • Shopify, for store authentication, products, customers, orders, Draft Orders, webhooks, and Shopify Files.
  • Fly.io or another approved hosting provider, for application hosting and database infrastructure.
  • Resend, only when email delivery is enabled or a Merchant configures it for email features.
  • Anthropic, only when the optional AI support features are enabled and configured.

We may also disclose data if required by law or to protect the rights, security, or integrity of Dotarus, Merchants, customers, or the public. Maintain a current public subprocessor list before publishing this policy.

4. Retention and deletion

We retain App data while the App is installed and as needed to provide the service, resolve disputes, comply with legal obligations, and maintain security. A Merchant can remove identified App-created Shopify Files before uninstall through Settings → Backup & advanced → Prepare for uninstall.

After a Merchant uninstalls, Shopify sends a shop/redact request approximately 48 hours later. On that request, the App erases its shop-scoped database data, including designs, settings, queued proof-email details, delivery records, and associated support records. Shopify’s own orders, customers, and files remain under the Merchant’s control in Shopify. Third-party provider retention is governed by their own terms and settings.

5. Rights and requests

Individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, depending on applicable law. Customers should normally direct requests to the Merchant whose store collected the data. Merchants may contact us using the privacy contact above for assistance.

For Shopify App Store compliance, the App supports Shopify’s customers/data_requestcustomers/redact, and shop/redact privacy webhooks. We acknowledge requests and complete required actions within Shopify’s required period, subject to lawful retention obligations.

6. Security

We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data, including HTTPS/TLS in transit, access controls, authenticated Shopify requests, and encryption for merchant-supplied third-party secrets. No method of transmission or storage is completely secure.

7. International transfers

The App and its service providers may process data in countries other than the country where it was collected. Where required, we use appropriate safeguards for cross-border transfers. The DPA contains additional transfer terms for Merchant customer data.

8. Children

The App is a business service for Shopify Merchants and is not directed to children. We do not knowingly collect personal data from children in connection with the App.

9. Changes and contact

We may update this Policy as the App or applicable law changes. We will post the updated version and effective date, and provide additional notice for material changes where required.

Questions or requests: hello@dotarus.com or https://dotarus.com/contact/.