Privacy policy
Last updated September 29, 2026
Mint Upload is a Shopify app made by Mint Labs ("we", "us"). It lets a Shopify merchant add a file upload field to their product pages. This policy explains what information the app handles, for merchants who install it and for shoppers who upload files on a merchant's store, how it's used, and how it's deleted.
The short version
- We store the files shoppers upload on a merchant's product pages, so the merchant can use them to fulfil the order.
- We don't collect shoppers' names, email addresses, postal addresses or payment details, and we don't store IP addresses.
- Files are deleted automatically after the period the merchant chooses (90 days by default), when the merchant deletes them, or when the app is uninstalled.
- We never sell or share data, and we don't use it for advertising or to train AI models.
Permissions we ask Shopify for
| Permission | Why |
|---|---|
| Read products | So the merchant can pick the products and collections that show the upload field. We save only the IDs and titles they pick. |
We can't see or change the store's orders, customers, inventory, themes or payments.
What we store
| Information | Why |
|---|---|
| The store's domain and a Shopify access token | To connect to the store when the merchant uses the app. |
| Upload setups: labels, accepted file types, size and count limits, and the products and collections chosen | To show the upload field on the right products. A copy is saved in a metafield owned by the app in the merchant's Shopify store, where the theme reads it. |
| Uploaded files, with the file name, type, size, upload time and the product it was uploaded for | So the merchant can open the file from the order and the app's Files page, and to enforce plan limits. |
| Monthly upload counts and settings (retention period, styling) | To apply the merchant's plan limits and settings. |
| Short-lived rate-limit counters keyed by a one-way hash of the uploader's IP address | To stop abuse (too many uploads from one device). The IP address itself is never stored; counters expire after 10 minutes. |
| The merchant's plan and subscription status | Read from Shopify to decide which limits apply. Payments are handled entirely by Shopify. |
Files uploaded by shoppers
Files may contain personal information, for example a photo of a person. The merchant decides what to ask shoppers to upload and is responsible for that information; we store and serve files only on the merchant's behalf. Each file is reachable at a long, random link that can't be guessed and is saved on the shopper's cart item, so it appears on their order for the merchant. Anyone who has the link can open the file, and links are marked so search engines don't index them. We don't link files to a customer account, name or email address.
Shoppers who want a file deleted should contact the store they uploaded it to; the merchant can delete any file from the Files page immediately. You can also email us with the store name and the file link and we'll delete it. We respond to Shopify's customer data request and deletion webhooks; because we hold no customer identifiers, we can't match those requests to files ourselves, so we rely on the merchant or the file link to find them.
Where data is stored
The app runs on Cloudflare: Workers (hosting), D1 (database) and R2 (file storage). Data is encrypted in transit and at rest by Cloudflare. We don't use any other third-party services, analytics, cookies or trackers, on the storefront or in the app.
Retention and deletion
- Uploaded files are deleted automatically once they're older than the merchant's retention setting (7 to 365 days; 90 by default), or kept until the merchant deletes them if they choose that option.
- Merchants can delete any file at any time from the Files page. Deleted files can't be recovered.
- When the app is uninstalled the access token is deleted immediately. Shopify then asks us to erase the store's data 48 hours later, when every file and record for the store is permanently deleted.
Your rights
Depending on where you are, you may have the right to access, correct or delete information about you. Merchants can contact us directly; shoppers should contact the store first, or us. We'll respond within 30 days.
Changes
If we change this policy we'll update the date above and, for significant changes, notify merchants in the app.
Contact
Mint Labs — support@stickermint.com