Draft — pending legal review before App Store submission.

Legal

Privacy Policy

Last updated: 21 September 2026

This policy explains what data the PrintFlex Shopify app ("PrintFlex", "the app") processes, why, and for how long. PrintFlex is made by MPC Trades, Phnom Penh, Cambodia ("we", "us").

Who is responsible for the data

When you install PrintFlex on your Shopify store, you, the merchant, are the data controller for your customers' order data. PrintFlex acts as a data processor: we process that data only on your instruction, which you give by installing the app, choosing which orders to print, and configuring templates and automatic emails. This website (printflex.mpctrades.com) itself sets no cookies and runs no analytics.

What data the app processes

To render the documents you ask for, the app reads the following from each order you select:

  • Order number, date, tags, fulfillment and financial status, shipping method, order notes.
  • Customer name, email address and phone number where present on the order.
  • Shipping and billing addresses.
  • Line items: product titles, variants, SKUs, quantities, prices, discounts, taxes and totals, in the order's presentment currency.
  • Store settings needed for the header: store name, address, logo you upload, and the template preferences you set in the app.

We use this data solely to render the invoices, packing slips and pick lists you request, to show print and packed status in the dashboard, and, if you switch it on, to email the PDF invoice to your customer. We do not sell it, share it with advertisers, or use it to build profiles.

PrintFlex never sees payment card data. Shopify does not expose card numbers to apps, and the app does not request access to payment details of any kind.

Shopify permissions requested

The app asks Shopify for two access scopes:

ScopeWhy
read_ordersTo list your orders in the dashboard and read the fields above when printing.
write_orders (used only to add and remove an order tag)To write the "packed" tag and timestamp when an order is marked packed from the scan page, so Shopify admin shows the same status as the bench.

We do not request access to products, inventory, customers outside of orders, discounts, payments or any other part of your store.

Scan mode and warehouse staff

Every QR code we print contains a signed link to one order's pack screen. Opening it requires the store PIN you set. Warehouse staff do not create accounts and we do not collect their personal details; each scan is logged with the device name the staff member enters, the order number and a timestamp, so that you can see who packed what. Those logs belong to your store and are deleted with it.

How long we keep data

  • Generated PDFs are cached so that reprints are instant, and automatically deleted 30 days after they were generated. After that a document is regenerated on demand from the order data in Shopify.
  • Order metadata (order number, print status, packed status, scan log) is kept while the app is installed so the dashboard can show history.
  • Template settings and your logo are kept while the app is installed.
  • Everything above is deleted when you uninstall the app, on the schedule described under "Shopify data requests" below.

Shopify data requests (GDPR webhooks)

PrintFlex subscribes to Shopify's three mandatory privacy webhooks and handles them as follows:

  • customers/data_request — we compile every document and log entry we hold that references the customer's orders and return it to you, the merchant, so you can pass it on. We respond within 30 days.
  • customers/redact — we delete the cached PDFs for that customer's orders, the scan log entries for those orders, and any stored order metadata containing their details. Deleting the cached documents, not only the database rows, is part of this step.
  • shop/redact — sent by Shopify 48 hours after uninstall. We delete all data for the store: cached PDFs, order metadata, scan logs, template settings, the uploaded logo and the store's PIN.

You can also email us at any time to ask for deletion sooner.

Where the data is stored

The app runs on a virtual private server. Generated PDFs and order metadata are stored on that server and are not replicated to other regions. Connections between your browser, Shopify and the app are encrypted with TLS.

Sub-processors

We use a small number of third parties to run the service:

  • Hosting — the VPS provider named above stores the app, its database and the cached PDFs.
  • Transactional email — when you enable the automatic invoice email, the PDF and the customer's email address are passed to an email delivery service to send the message. If the feature is off, no customer data reaches this provider.
  • Shopify — the platform your store runs on, which is the source of all order data and processes all billing.

We do not use analytics, advertising or session-recording services inside the app.

Billing data

All charges for paid plans are made through Shopify's Billing API and appear on your Shopify invoice. We receive from Shopify only the plan you are on and whether the charge is active. We never receive or store payment details.

Security

Access to the app's servers is restricted to the MPC Trades team, over encrypted connections with key-based authentication. Signed links in QR codes cannot be guessed or altered without the store's secret. We will notify you without undue delay if we become aware of a breach affecting your data.

Changes to this policy

If we change what data we process or how, we will update this page, change the date at the top, and tell merchants with the app installed through the app's dashboard before the change takes effect.

Contact

For any question, data request or complaint about how PrintFlex handles data, email team@mpctrades.com. We aim to reply within one business day and to resolve data requests within 30 days.