Legal

Privacy Policy

Last updated August 2026. Applies to Gangly.app and the Gangly Shopify app.

Overview

Gangly ("we", "us") provides a DTF gang sheet builder for merchants and their customers. This policy explains what data we process when you use gangly.app or install the Gangly Shopify app.

Purpose of processing

We process personal data only to operate the gang sheet builder and help merchants fulfil print orders: save designs, attach them to Shopify cart lines, render print-ready files, and show sheet previews. Contact and shipping details stay in Shopify Admin. We do not sell personal data or use it for advertising.

Shopify merchants

When you install the Gangly Shopify app, we store:

  • Your shop domain and app access token (for API calls)
  • Branding and sheet settings you configure in the app admin
  • Paid order records needed for print fulfilment (order id, line snapshots, rendered PNG references, printed status)

Access tokens are revoked when you uninstall the app. Shop data — including orders and settings — is deleted after Shopify's mandatory shop/redact webhook (typically 48 hours after uninstall).

Store customers (builder + order fulfilment)

Customers using the builder on a merchant's storefront do not create Gangly accounts. Depending on checkout and fulfilment, we may store:

  • Uploaded artwork and saved gang sheet projects
  • Shopify customer ID when the buyer is logged in (for merging guest work)
  • Preview links so customers can re-open their sheet from order status / account pages

Customer data is scoped to the merchant's shop. On Shopify customers/redact, we delete that customer's builder projects and clear personal fields on related order records. On customers/data_request, we assemble the stored project and order personal data for the merchant/Shopify response process.

Retention

  • Paid order print records (order id, sheet snapshots, PNG references): until GDPR redact / shop uninstall redact, or 24 months for any residual personal fields
  • Builder projects: until customer redact, shop redact, or merchant deletion
  • Personal-data access audit logs: 12 months (resource ids only — not raw email or address)

Security

  • HTTPS / TLS in transit for gangly.app
  • Access to merchant admin APIs requires Shopify session authentication
  • Staff access to production systems is limited to named operators; production secrets are not shared with test environments
  • Backups of application data are encrypted at rest when the encrypted backup procedure is used

Mandatory Shopify compliance webhooks

We implement Shopify's required GDPR webhooks: customers/data_request, customers/redact, and shop/redact.

Contact

Privacy questions and incident reports: privacy@gangly.app

← Back to Gangly

Privacy Policy - Gangly.app