Studio InkDrop
Last updated 26 August 2026
Studio InkDrop is a Shopify app made by Brilliant Fulfillment (“BFF”, “we”, “us”). It helps an online store design and personalize the printed cards that go into its packages, and it measures what happens when someone scans the QR code on one.
You are deciding whether to install the app, or you already have. Start at section 6 — it covers what we do with your customers’ data on your behalf.
You scanned a QR code and want to know what was recorded. That is section 7, and it is short.
{{customer.firstName}}. (Section 5)
This is the most important thing on the page, so it comes first.
The store you bought from decides. When a merchant installs Studio InkDrop, they remain in charge of their customers’ personal data — in legal terms, the controller. We are the processor: we handle that data only to do the job the merchant asked us to do, only in the ways described here, and never for our own purposes.
What this policy does not cover. It does not describe what a merchant does with your data in their own systems, what Shopify does, or what any other app on their store does. Those are governed by their own policies. If you want your data removed from a store entirely, the store is who to ask — and their request reaches us automatically.
Three sources, and nothing outside them.
Using the access the merchant grants when they install the app:
| What | Why we need it |
|---|---|
| Order details — order number, items bought, fulfillment status | To know a card is due, and when the parcel shipped |
| Customer name | Printed on the card, so it is addressed to a person rather than to nobody |
| Email address | To match the card to the right order, and to show the merchant their own order list |
| Shipping and billing address | To match the printed card to the correct parcel at the packing bench |
| Purchase history summary — how many previous orders, total spent, tags | To choose which card design someone gets: a first-time buyer and a regular should not receive the same message |
| Product information — titles, images, tags | So a merchant can put their own products on a card |
| Discount codes we create, and whether they were used | To put a working offer on a card and tell the merchant if it worked |
| Published theme colours and fonts | To pre-fill a new store’s branding. This is shop configuration, not personal data. |
When someone scans the QR code, they reach a landing page on the store’s own domain. We record the scan, which buttons were followed, whether a discount was claimed, and the IP address, browser user-agent and referring page of that request. That is the complete list.
Name and email address for the people who sign in to use the app, so we know who did what.
Retention is tied to events rather than to fixed clocks, because the events are what actually matter.
| When this happens | This is what we do |
|---|---|
| Normal operation | Order and card records are kept as a production record while the app is installed, so a merchant can see what was printed, for whom, and what happened next. |
| A customer asks to be deleted Shopify sends us the request directly |
We strip that person’s name, email, phone and addresses from the order, and delete the scan records tied to their card — including the IP address. The order stays, de-identified, as a record that a card was printed, and is marked as redacted. |
| The merchant uninstalls the app | Our access credential for that store is destroyed immediately. From that moment we cannot read anything from it. |
| 48 hours after uninstall Shopify’s standard deletion window |
We delete that store’s orders, scan records, links, discount code records and the connection itself. |
| A merchant asks us to delete | We delete their data on request. Uninstalling the app does this without asking: our access is destroyed at once, and everything is erased 48 hours later. |
Information about a merchant’s customers is not something we are in the business of selling or trading. We share it only in the circumstances set out below.
Service providers. We employ other companies to perform functions on our behalf. Examples include hosting the application, storing the card files we produce, and passing order references to the warehouse and shipping systems that put the right card into the right parcel. These providers receive only the information needed to perform those functions, are bound by contract, and may not use it for any other purpose.
At the merchant’s direction. The store you bought from decides what happens to its customers’ data. Where a merchant asks us to send information somewhere on their behalf, we do so on their instruction and under their responsibility.
Legal requests and safety. We may disclose information where the law requires it — a court order, or a lawful request from an authority — or where it is necessary to investigate fraud, enforce our agreements, or protect the rights and safety of merchants, their customers, or others.
If our business changes. Data may transfer with the business if BFF is sold, merged or reorganised. See section 11.
Merchants can ask for the details. If you run a store using Studio InkDrop and need the specific providers behind these categories — for your own privacy notice, a vendor review, or a data processing agreement — ask us and we will give you the current list. We will tell merchants before adding a new provider that handles personal data.
Stated plainly, because these are the questions people actually have.
You are the controller of your customers’ personal data and we are your processor. We act on your instructions, we do not use your customers’ data for our own purposes, and we do not share it with other merchants.
Telling your own customers that you use a service like ours, and having a lawful basis for the personalized card in the first place. We give you the tools; the relationship with your customer is yours.
The service providers described in section 4 are our sub-processors. Ask us for the named list — we will give it to any merchant who wants it, and we will tell merchants before adding a new provider that handles personal data.
You do not need to forward these to us. Shopify’s customer deletion and data requests are delivered to us automatically and we act on them as described in section 3. If you need something outside that flow, ask us.
You bought something, a card came in the parcel, and you scanned the code on it. Here is the whole of what happened.
That is used to tell the store whether their card worked. We did not set a cookie, and we are not tracking you anywhere else. The page you landed on was served on the store’s own web address, which is why it did not look like it came from us.
To have this removed: ask the store you bought from to delete your data. Their request reaches us automatically and we act on it. You can also contact us and we will help them do it.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your data we will notify the affected merchants and the relevant regulators as the law requires.
Depending on where you live, you may have the right to access the data held about you, correct it, delete it, object to how it is used, or receive a copy of it.
Ask the store you bought from. They are the controller, and their request reaches us automatically. If that is difficult, write to us and we will help.
The order and card records we hold for you are visible in the app itself. To have them deleted, uninstall — that erases everything, on the schedule in section 3, without you having to ask. If you need something outside that, write to us.
Where the UK or EU GDPR applies, we process personal data as a processor on the merchant’s instructions, under the lawful basis the merchant relies on with their own customers — usually performing the purchase contract, or their legitimate interest in communicating with someone about an order they placed. Where US state privacy laws such as the CCPA apply, we act as a service provider: we do not sell personal information and do not share it for cross-context behavioural advertising.
Our systems and the providers in section 4 operate in the United States and the European Union. If you are in the UK or the EEA, your data may be transferred outside your region. Where it is, those transfers are covered by the safeguards the law requires, such as Standard Contractual Clauses with the provider concerned.
Studio InkDrop is a tool for businesses and is not directed at children. We do not knowingly collect data about children. If you believe we hold data about a child, tell us and we will delete it.
If BFF is ever sold, merged, or reorganised, data may transfer with the business. It would remain subject to this policy, and merchants would be told before anything changed.
We will update this page when what we do changes, and revise the date at the top. If a change materially affects merchants, we will tell them directly rather than relying on them to re-read this page.
{{customer.firstName}}, replaced with a real value when the card is made. Our design assistant only ever sees the marker.Brilliant Fulfillment — privacy enquiries: support@bful.co
If you are asking about data held because you bought something, it helps to tell us which store you bought from, since they decide what happens to it.