Privacy policy
Effective date: 4 September 2026
StatusClerk (statusclerk.com) is an app for Shopify stores that make things to order. It turns each open line item into a production job, collects the customer's approval of a proof where the merchant asks for one, and shows the customer the stage and expected date of each item. It is operated by MB Croppick, company code 308104331, registered office Krivių g. 5, LT-01204 Vilnius, Lithuania ("StatusClerk", "we", "us"). Questions and requests: privacy@statusclerk.com.
The short version
- We read your store's open orders, their line items and the personalisation your customers typed at checkout, your products and fulfilments — to run your production queue and show your customers where their items are.
- We write to your store only what you switch on: an order tag and metafield per stage change, an optional fulfilment hold while a proof is pending, and an optional fulfilment when you mark a job done.
- We store the customer's first name and surname initial (the queue's "Priya N.") and never the customer's email address, postal address or phone number. The email is read from Shopify at the moment an email is sent, used for that send, and not kept; the lookup form checks it against a keyed hash that cannot be turned back into the address.
- We store the proofs you send, the customer's decisions and change requests, and the photos you post for them, so there is a record of who approved what.
- No artificial-intelligence processing of any kind. A text proof is rendered from your own template; nothing is generated.
- Everything runs on Cloudflare's platform; the database and file storage are in Cloudflare's Eastern Europe region.
- We never sell data, never use it for marketing, and show no ads.
- Uninstall the app and everything is deleted, automatically, on Shopify's standard schedule.
Who this policy covers
- Merchants — the store that installs StatusClerk. For your account data, we are the data controller.
- Customers — the people who ordered from your store and receive the proof, status and stage emails, and see the status block on their order page. For customer data, you (the merchant) are the controller and StatusClerk is your processor: we handle it only to run the queue and the customer communication you configured, on your instructions as expressed through the app. The data processing agreement sets out that relationship in full and forms part of the terms.
Why we may process it (legal basis)
For your merchant account data, the basis is the performance of our contract with you (GDPR Article 6(1)(b)). For usage metrics, security logs and abuse prevention, it is our legitimate interest in running a reliable, secure service (Article 6(1)(f)). For plan and billing records, it is our legal obligation under accounting law (Article 6(1)(c)). Customer data we process on your instructions as your processor, so the legal basis for it is yours to establish, not ours.
What we collect, why, where, and for how long
| What | Why | Where it is stored | How long |
|---|---|---|---|
| Merchant account — store domain, store name, store contact email, currency, timezone, storefront domain, app settings (stages, lead times, closures, property mapping, proof rules, customer-facing sentences, branding, the names of your makers), plan and billing status, encrypted Shopify API tokens | To run the app for your store and bill through Shopify | Cloudflare D1 database (Eastern Europe region) | While the app is installed; deleted after uninstall (see "Uninstalling") |
| Products — the Shopify identifier and title of each product that appears on a job, its lead time and proof rule, and a text-proof template you set up (a product photo and font files you upload) | To compute expected dates, decide which items need a proof, and render text proofs | Cloudflare D1; photos and fonts in Cloudflare R2 file storage (Eastern Europe region) | While installed; deleted on uninstall |
| Orders and jobs — order number, order date, the customer's first name and surname initial, the customer's Shopify identifier, a keyed hash of the customer's email (not the address), the order note and tags, and for each line item: product, variant, quantity, the line-item properties exactly as the customer typed them (engraving text, font, colour, an uploaded artwork's address, an occasion date), the stage, the proof state, expected and needed-by dates, batch and assignee | To run the production queue, print run sheets, compute dates, and show the customer the state of each item | Cloudflare D1 | While installed; a job finished or cancelled more than 180 days ago is deleted with everything attached to it, and an order once all its jobs are gone; everything is deleted on uninstall |
| Proofs, approvals and change requests — each proof image you upload or the app renders, when it was sent, viewed, approved or declined and from which link, the customer's change-request note and the file they attached, a customer's request to change a typed value | So the customer can check the spelling before you make the item, and so there is a record of who approved what and when | Files in Cloudflare R2; the rest in Cloudflare D1 | Until the job is deleted, 180 days after it is done or cancelled; everything is deleted on uninstall |
| Customer updates — a note and a photo you post from the bench, a new expected date and its reason | To tell the customer what changed | Cloudflare D1; photos in Cloudflare R2 | Until the job is deleted, 180 days after it is done or cancelled; everything is deleted on uninstall |
| Delivery log — per email: when it was sent, what it was about, the outcome (sent, bounced, refused), and how many recipients it went to. Never the addresses | To show you what went out and surface bounces | Cloudflare D1 | 180 days; everything is deleted on uninstall |
| Audit log — operational events, including a record each time the app reads a customer's email from Shopify to send an email (order and count, not the address) | Support, and the access log required for Shopify's protected customer data | Cloudflare D1 | While installed; deleted on uninstall |
| Usage counters — daily counts of status-page and proof-page views, jobs finished, finished on time, and remakes, keyed to your store | The insights on your plan page; service quality and plan limits | Cloudflare D1 and Cloudflare Analytics Engine | Counters while installed (deleted on uninstall); Analytics Engine about three months (Cloudflare's retention), then expires |
| Feedback — messages you send through the in-app or site feedback form, with an optional email address | To read and answer your feedback | Cloudflare D1 | Until handled; deleted on uninstall |
We do not collect payment card details (Shopify handles all billing) and we place no advertising or cross-site tracking cookies. The embedded app uses Shopify session tokens for sign-in; the website uses no analytics that identify you. The public proof-approval page, the order lookup form and the feedback form are protected by Cloudflare Turnstile, a privacy-preserving check that blocks automated submissions.
Customers — how the customer's data is handled
Shopify holds your customer's name, email and address. When StatusClerk syncs an order it keeps the customer's first name and the initial of their surname, so your queue can say which order is whose, and a keyed hash of their email so the lookup form can check an email against an order without our storing the address. When an email is due — a proof to approve, a reminder, a stage change, a new expected date — StatusClerk reads the customer's email address from Shopify, hands the message to Cloudflare Email Sending for delivery, and records only that a send happened and to how many addresses. The address itself is not written to our database or files.
The email is your communication to your customer, not ours: it shows your store's name as the sender (the sending address is ours, mail.statusclerk.com, so that delivery and bounces work), carries your store's email address as the reply address, and mentions StatusClerk only in a one-line "Sent with StatusClerk" note. Cloudflare keeps delivery events — including the recipient address — in its email analytics for about 31 days, so that bounces can be reported back to you; after that they expire.
The status block on the customer's order page and the hosted status page show the customer their own items: the stage in your words, the expected date, the personalisation they typed, the proof to approve. A customer who approves a proof or requests a change from those pages is telling you, not us; we record the decision on your behalf.
Where your data lives
StatusClerk runs entirely on Cloudflare's platform. The database (Cloudflare D1) and file storage (Cloudflare R2) that hold the data above are located in Cloudflare's Eastern Europe region. Requests are processed by Cloudflare's global edge network in transit, as with any Cloudflare-hosted service. Emails are sent through Cloudflare Email Sending from mail.statusclerk.com, in your store's name, with replies going to your store's email address. Run-sheet PDFs and rendered text proofs are produced by Cloudflare Browser Rendering from HTML we generate; nothing leaves the page during rendering.
Who we share data with (subprocessors)
| Subprocessor | What they process | Why |
|---|---|---|
| Cloudflare (hosting, storage, email, rendering) | All data in the table above, encrypted in transit; the run-sheet and proof HTML during rendering; recipient addresses during delivery | Runs the entire service |
| Shopify | Your store identity and subscription/billing events; the tags, metafields, fulfilment holds and fulfilments the app writes to your store | The platform the app runs on |
| Google (Gmail) | The content of email you send to support@ or privacy@statusclerk.com — those addresses forward to a Gmail mailbox — and our replies | Reading and answering your email |
That is the whole list. There is no AI provider. We do not sell personal data, share it with data brokers or advertisers, or use customer data for any marketing.
Changes to this list. Before a new subprocessor starts processing your data we update this table and notify you in the app or by email, in advance and with time to object. If you object, you may uninstall before it takes effect, and your data is deleted as described below.
How long we keep data (summary)
- While installed: everything above stays so the queue, the proof record and the customer's status page keep working, with two exceptions. A job that is done or cancelled stays in the app as history for 180 days, then is deleted with everything attached to it — its proofs, change requests, updates and their files — and its order goes once no job is left on it. A delivery-log entry is deleted after the same 180 days.
- Customer redaction: on a customer data-erasure request relayed by Shopify, we remove the customer's name initials and identifier from their orders; there is no stored email or address to erase.
- Uninstalling: uninstalling revokes our access token immediately. Shopify sends the shop-deletion signal about 48 hours later, and on it we delete everything — every file and every database record for the store. If, at the moment you uninstall, orders still carry a fulfilment hold the app placed for a pending proof, we send one email to your store's contact address (or the reply-to you set) listing those orders, because the app can no longer release them itself; the email contains order numbers and item titles, nothing about your customers.
Your rights
Merchants can see and change their data in the app (settings, stages, jobs, proofs) or write to privacy@statusclerk.com to access, correct, export, or delete anything, or to object to or restrict processing. If you are in the EU/EEA or UK, you also have the right to complain to a supervisory authority. Ours is the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, LT-10312 Vilnius, vdai.lrv.lt); you may equally complain to the authority in your own EU/EEA or UK country.
Customers should direct requests to the merchant they ordered from — the merchant is the controller. StatusClerk supports the merchant's obligations automatically through Shopify's mandatory privacy webhooks:
customers/data_request— logged and surfaced so the merchant can respond; we assist on request.customers/redact— the customer's initials and identifier are removed from their orders.shop/redact— the store's complete data is erased after uninstall.
Security
- Shopify access tokens are stored encrypted (AES-GCM) and never leave the server side.
- All traffic is TLS; webhooks are verified with Shopify's HMAC signatures before anything is processed; the customer's order page talks to us with Shopify's own session token.
- The app requests read access to orders, products, customers and fulfilments, and write access only for what it does: order tags and metafields, fulfilment holds, and the fulfilment you choose to create when a job is done. It never edits an order, a product or a price, and never takes a payment.
- The app holds Shopify's protected customer data approval for the customer's name and email. The name is reduced to a first name and an initial at sync; the email is read only at the moment an email is sent, and is never stored.
- Every account behind the service (Cloudflare, GitHub, Shopify Partners, the domain registrar) is protected by two-factor authentication, and access is limited to the operator.
- Proof images, photos and PDFs are stored under per-store keys and served only through signed links.
International transfers
Primary storage is in Cloudflare's Eastern Europe region. Cloudflare processing is covered by Cloudflare's data-processing addendum, which incorporates the EU standard contractual clauses. Email you send us is read in Gmail; Google LLC participates in the EU–U.S. Data Privacy Framework, which covers any processing of that correspondence in the United States.
Children
StatusClerk is a business tool for merchants and is not directed at children.
Changes to this policy
If this policy changes materially, we will note it here with a new effective date and flag it in the app.
Contact
privacy@statusclerk.com — or support@statusclerk.com for anything else.