Privacy Policy, Gangify
Last updated: 15 August 2026
This is the source text. Publish it at https://gangify.net/privacy and link it from the app listing and the app's Help page. Shopify requires a reachable privacy URL before the protected customer data request can be approved.
Who this covers
Gangify is a Shopify app that lets a merchant's customers design DTF gang sheets and order them. There are two groups of people involved, and they are treated differently:
- Merchants, Shopify store owners who install Gangify.
- Customers, shoppers who use the gang sheet builder on a merchant's storefront.
For customer data, the merchant is the data controller and Gangify is a data processor: the merchant decides what happens to their shoppers' information, and Gangify only handles it to provide the service the merchant asked for.
What Gangify stores
Artwork and designs
- Images customers upload, and the layout describing where each one sits on the sheet.
- Both are stored on Cloudflare R2 and are needed to produce the print file the merchant prints.
Order records
- The Shopify order ID, line item ID, the price charged, the sheet dimensions, and the result of the internal price check.
Customers
- The Shopify customer ID only. Gangify does not store names, email addresses, phone numbers, shipping addresses, or payment details.
- Customer names shown in the merchant's print queue are read from Shopify each time the page loads and are never written to Gangify's database.
- Shoppers who are not signed in are identified by a random identifier stored in their own browser. It is not linked to any person and cannot be used to identify them.
Merchants
- Store domain, the access token Shopify issues at install, and the settings configured in the app.
- If a merchant uses Contact the developer in the app, the message they write, the reply address they give and their store domain, plan and API version are emailed to the app developer. The message itself is not stored by Gangify; the app records only that the store sent a message and when, so it can limit how often the form is used. That record is deleted with the rest of the store's data on uninstall.
- The form tells merchants, on the page, not to include customer details, and no order or customer information is attached to it by the app.
Free-text notes
- Customers may add a note to an order. Whatever they type is stored and shown to the merchant. Customers should not put sensitive personal information in it.
What Gangify does NOT do
- No advertising, no ad networks, no analytics or tracking of shoppers across sites.
- Customer data is never sold, rented, or shared for anyone else's marketing.
- No profiling, and no automated decisions with legal or similarly significant effects.
Why each thing is kept
| Data | Purpose |
|---|---|
| Uploaded artwork and layouts | Producing the print file the merchant ordered |
| Order records and price checks | Detecting incorrect or manipulated pricing, and supporting the merchant's fulfilment |
| Shopify customer ID | Letting a signed-in shopper find their own saved sheets |
| Merchant settings and token | Operating the app on that store |
How long it is kept
- Unfinished designs by a shopper who has not ordered: deleted automatically after a set period configured by the merchant (7 days by default).
- Designs attached to an order: kept while the merchant may still need them to print or reprint, up to the retention period set in the app (24 months by default).
- Order records: kept as long as the app is installed, as a record of what was sold.
- On uninstall: the merchant's access token and session are deleted immediately, and the shop's stored data is removed on the schedule below.
Customers can delete their own saved sheets at any time from the builder. Sheets attached to an order are removed from the customer's list, while the merchant keeps the copy they need to fulfil the order they were paid for.
Sub-processors
Gangify runs entirely on infrastructure provided by:
- Cloudflare, Inc., application hosting (Workers), database (D1), and file storage (R2).
- Shopify Inc., the platform the app runs on and the source of order and customer data.
No other third party receives customer data.
Where data is stored
Cloudflare's global network. Data may be processed in any region Cloudflare operates in, including outside the customer's own country. Cloudflare's data processing terms apply.
Security
- All traffic is encrypted in transit (HTTPS).
- Requests from a merchant's storefront are cryptographically verified before any data is returned, so one store can never read another's.
- Links to artwork are individually signed and expire after one hour.
- Uploaded files are verified by inspecting their actual contents, not their filename, and document formats that can carry executable content are not accepted.
No system is perfectly secure, and this policy does not promise otherwise.
Rights of shoppers
Shoppers should contact the merchant they ordered from, the merchant is the controller of their data, and Shopify routes those requests to Gangify automatically. Gangify honours Shopify's mandatory privacy webhooks:
- Data request, a copy of what Gangify holds for that customer.
- Customer redaction, deletion of that customer's designs and artwork.
- Shop redaction, deletion of everything for a store, 48 hours after uninstall.
Depending on where they live, shoppers may have rights to access, correct, delete, or export their data, and to object to or restrict its processing (GDPR), or to know about and delete their data and to opt out of its sale (CCPA/CPRA). Gangify does not sell personal information.
Children
Gangify is not intended for children and does not knowingly collect their data.
Changes
Material changes will be reflected in the date at the top of this page, and merchants will be notified in the app before a change takes effect.
Contact
Gangify, support@gangify.net
Include your store domain, and the order number if the question is about a specific order.