Studio InkDrop

Privacy Policy

Last updated 26 August 2026

Studio InkDrop is a Shopify app made by Brilliant Fulfillment (“BFF”, “we”, “us”). It helps an online store design and personalize the printed cards that go into its packages, and it measures what happens when someone scans the QR code on one.

You run a store

You are deciding whether to install the app, or you already have. Start at section 6 — it covers what we do with your customers’ data on your behalf.

You got a card in a parcel

You scanned a QR code and want to know what was recorded. That is section 7, and it is short.

The short version

1. Who we are, and who decides what happens to your data

This is the most important thing on the page, so it comes first.

The store you bought from decides. When a merchant installs Studio InkDrop, they remain in charge of their customers’ personal data — in legal terms, the controller. We are the processor: we handle that data only to do the job the merchant asked us to do, only in the ways described here, and never for our own purposes.

What this policy does not cover. It does not describe what a merchant does with your data in their own systems, what Shopify does, or what any other app on their store does. Those are governed by their own policies. If you want your data removed from a store entirely, the store is who to ask — and their request reaches us automatically.

2. What do we collect, and why?

Three sources, and nothing outside them.

From the merchant’s Shopify store

Using the access the merchant grants when they install the app:

WhatWhy we need it
Order details — order number, items bought, fulfillment status To know a card is due, and when the parcel shipped
Customer name Printed on the card, so it is addressed to a person rather than to nobody
Email address To match the card to the right order, and to show the merchant their own order list
Shipping and billing address To match the printed card to the correct parcel at the packing bench
Purchase history summary — how many previous orders, total spent, tags To choose which card design someone gets: a first-time buyer and a regular should not receive the same message
Product information — titles, images, tags So a merchant can put their own products on a card
Discount codes we create, and whether they were used To put a working offer on a card and tell the merchant if it worked
Published theme colours and fonts To pre-fill a new store’s branding. This is shop configuration, not personal data.

From people who scan a card

When someone scans the QR code, they reach a landing page on the store’s own domain. We record the scan, which buttons were followed, whether a discount was claimed, and the IP address, browser user-agent and referring page of that request. That is the complete list.

From the merchant’s own staff

Name and email address for the people who sign in to use the app, so we know who did what.

3. How long do we keep it?

Retention is tied to events rather than to fixed clocks, because the events are what actually matter.

When this happensThis is what we do
Normal operation Order and card records are kept as a production record while the app is installed, so a merchant can see what was printed, for whom, and what happened next.
A customer asks to be deleted
Shopify sends us the request directly
We strip that person’s name, email, phone and addresses from the order, and delete the scan records tied to their card — including the IP address. The order stays, de-identified, as a record that a card was printed, and is marked as redacted.
The merchant uninstalls the app Our access credential for that store is destroyed immediately. From that moment we cannot read anything from it.
48 hours after uninstall
Shopify’s standard deletion window
We delete that store’s orders, scan records, links, discount code records and the connection itself.
A merchant asks us to delete We delete their data on request. Uninstalling the app does this without asking: our access is destroyed at once, and everything is erased 48 hours later.

4. Do we share this data?

Information about a merchant’s customers is not something we are in the business of selling or trading. We share it only in the circumstances set out below.

Service providers. We employ other companies to perform functions on our behalf. Examples include hosting the application, storing the card files we produce, and passing order references to the warehouse and shipping systems that put the right card into the right parcel. These providers receive only the information needed to perform those functions, are bound by contract, and may not use it for any other purpose.

At the merchant’s direction. The store you bought from decides what happens to its customers’ data. Where a merchant asks us to send information somewhere on their behalf, we do so on their instruction and under their responsibility.

Legal requests and safety. We may disclose information where the law requires it — a court order, or a lawful request from an authority — or where it is necessary to investigate fraud, enforce our agreements, or protect the rights and safety of merchants, their customers, or others.

If our business changes. Data may transfer with the business if BFF is sold, merged or reorganised. See section 11.

Merchants can ask for the details. If you run a store using Studio InkDrop and need the specific providers behind these categories — for your own privacy notice, a vendor review, or a data processing agreement — ask us and we will give you the current list. We will tell merchants before adding a new provider that handles personal data.

5. What we never do

Stated plainly, because these are the questions people actually have.

We do not:

6. If you run a store

Our role

You are the controller of your customers’ personal data and we are your processor. We act on your instructions, we do not use your customers’ data for our own purposes, and we do not share it with other merchants.

What you are responsible for

Telling your own customers that you use a service like ours, and having a lawful basis for the personalized card in the first place. We give you the tools; the relationship with your customer is yours.

Sub-processors

The service providers described in section 4 are our sub-processors. Ask us for the named list — we will give it to any merchant who wants it, and we will tell merchants before adding a new provider that handles personal data.

Deletion requests

You do not need to forward these to us. Shopify’s customer deletion and data requests are delivered to us automatically and we act on them as described in section 3. If you need something outside that flow, ask us.

7. If you received a card

You bought something, a card came in the parcel, and you scanned the code on it. Here is the whole of what happened.

That is used to tell the store whether their card worked. We did not set a cookie, and we are not tracking you anywhere else. The page you landed on was served on the store’s own web address, which is why it did not look like it came from us.

To have this removed: ask the store you bought from to delete your data. Their request reaches us automatically and we act on it. You can also contact us and we will help them do it.

8. How do we protect it?

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will notify the affected merchants and the relevant regulators as the law requires.

9. Your rights, and how to use them

Depending on where you live, you may have the right to access the data held about you, correct it, delete it, object to how it is used, or receive a copy of it.

If you are a shopper

Ask the store you bought from. They are the controller, and their request reaches us automatically. If that is difficult, write to us and we will help.

If you are a merchant

The order and card records we hold for you are visible in the app itself. To have them deleted, uninstall — that erases everything, on the schedule in section 3, without you having to ask. If you need something outside that, write to us.

Legal bases

Where the UK or EU GDPR applies, we process personal data as a processor on the merchant’s instructions, under the lawful basis the merchant relies on with their own customers — usually performing the purchase contract, or their legitimate interest in communicating with someone about an order they placed. Where US state privacy laws such as the CCPA apply, we act as a service provider: we do not sell personal information and do not share it for cross-context behavioural advertising.

10. Where does your data go?

Our systems and the providers in section 4 operate in the United States and the European Union. If you are in the UK or the EEA, your data may be transferred outside your region. Where it is, those transfers are covered by the safeguards the law requires, such as Standard Contractual Clauses with the provider concerned.

11. Children, and changes to our business

Children

Studio InkDrop is a tool for businesses and is not directed at children. We do not knowingly collect data about children. If you believe we hold data about a child, tell us and we will delete it.

If our business changes

If BFF is ever sold, merged, or reorganised, data may transfer with the business. It would remain subject to this policy, and merchants would be told before anything changed.

12. Changes to this policy

We will update this page when what we do changes, and revise the date at the top. If a change materially affects merchants, we will tell them directly rather than relying on them to re-read this page.

13. Key terms

Controller
The organisation that decides why and how personal data is used. For your order, that is the store you bought from.
Processor
An organisation that handles data on the controller’s behalf and on their instructions. That is us.
Sub-processor
A service we use to do part of the job, described in section 4. Merchants can ask us for the named list.
App Proxy
A Shopify feature that lets a page from our servers appear on the store’s own web address. It is why the landing page you scanned into shows the store’s domain, not ours. Shopify removes cookies from these requests in both directions.
Webhook
An automatic message from Shopify to us when something happens — an order is paid, or a customer asks to be deleted. It is how deletion requests reach us without anyone forwarding them.
Merge field / placeholder
A marker in a card design, like {{customer.firstName}}, replaced with a real value when the card is made. Our design assistant only ever sees the marker.
Redacted
An order whose personal details have been deleted on request, leaving only the record that a card was printed.

14. How to reach us

Brilliant Fulfillment — privacy enquiries: support@bful.co

If you are asking about data held because you bought something, it helps to tell us which store you bought from, since they decide what happens to it.