Legal
Privacy Policy
Last updated August 2026. Applies to Gangly.app and the Gangly Shopify app.
Overview
Gangly ("we", "us") provides a DTF gang sheet builder for merchants and their customers. This policy explains what data we process when you use gangly.app or install the Gangly Shopify app.
Purpose of processing
We process personal data only to operate the gang sheet builder and help merchants fulfil print orders: save designs, attach them to Shopify cart lines, render print-ready files, and show sheet previews. Contact and shipping details stay in Shopify Admin. We do not sell personal data or use it for advertising.
Shopify merchants
When you install the Gangly Shopify app, we store:
- your shop domain and app access token, for API calls;
- branding and sheet settings you configure in the app admin; and
- paid order records needed for print fulfilment — order id, line snapshots, rendered PNG references, printed status.
Access tokens are revoked when you uninstall the app. Shop data, including orders and settings, is deleted after Shopify's mandatory shop/redact webhook — typically 48 hours after uninstall.
Store customers
Customers using the builder on a merchant's storefront do not create Gangly accounts. Depending on checkout and fulfilment, we may store:
- uploaded artwork and saved gang sheet projects;
- the Shopify customer ID when the buyer is logged in, so guest work can be merged; and
- preview links, so customers can re-open their sheet from order status and account pages.
Customer data is scoped to the merchant's shop. On Shopify customers/redact we delete that customer's builder projects and clear personal fields on related order records. On customers/data_request we assemble the stored project and order personal data for the merchant and Shopify response process.
Retention
- Paid order print records — order id, sheet snapshots, PNG references: until GDPR redact or shop uninstall redact, or 24 months for any residual personal fields.
- Builder projects: until customer redact, shop redact, or merchant deletion.
- Personal-data access audit logs: 12 months, holding resource ids only — not raw email or address.
Where your data is stored
The hosted service runs on servers provided by Hetzner Online GmbH in the European Union. Uploaded artwork, saved projects and order records are stored there.
The desktop app processes files on your own computer and does not send artwork to us. If you run Gangly on your own server, your data stays on that server.
Sub-processors
We share data with these providers, only to the extent each one needs to do its job:
- Shopify — the platform the app runs on. Shop, order and customer data reaches us through Shopify's APIs.
- fal.ai — artwork repair. When you use that feature, and only then, the image is uploaded to fal.ai to be processed and the result returned to us.
- Stripe — payments for Gangly Pro subscriptions. We do not store card details.
- Resend — transactional email, such as sign-in links.
Upscaling and background removal run on our own servers. Artwork is not sent anywhere for those features.
Security
- HTTPS and TLS in transit for gangly.app.
- Access to merchant admin APIs requires Shopify session authentication.
- Staff access to production systems is limited to named operators; production secrets are not shared with test environments.
- Backups of application data are encrypted at rest when the encrypted backup procedure is used.
Mandatory Shopify compliance webhooks
We implement Shopify's required GDPR webhooks: customers/data_request, customers/redact, and shop/redact.
Privacy questions and incident reports: privacy@gangly.app.
See also our Terms of Service.