Privacy Policy

Upload Box · last updated 2026-09-30 · Terms of Service

What this app stores

Upload Box adds a file upload button to your product pages. Shoppers' files are saved to your own store's Files in Shopify, and a link to each file is added to the cart item, so it shows on the order. The app itself keeps the following, keyed to your shop domain:

Where the files are

The files themselves are not stored on our servers. The shopper's browser sends each file directly to Shopify, and the app then adds it to your store's Files (Content → Files in your Shopify admin). Files there are served from Shopify's content delivery network at addresses that are hard to guess, which is how the link on the order can be opened by you and your staff.

Because the files are in your store, they stay there if you remove the app. You can delete them at any time from Content → Files.

What this app does not collect

We only receive what a shopper chooses to upload. We do not track shoppers who do not upload, and we set no cookies.

To slow down abuse, uploads are rate-limited by the sender's network address. That address is kept only in the app's memory, is cleared within a minute after a ten-minute window ends, and is never written to the database.

When an order is placed, the app reads only which uploads are on it (the order ID, the order number, and the upload references on each item). It does not read or store the customer's name, email, address, or phone number from the order.

We do not receive payment information.

We do not use your data or your shoppers' files to train models, and we do not sell or share them.

Who receives it

Shopify, which stores the files in your store's Files and attaches the links to your orders. From then on the files are part of your Shopify store data.

Railway (railway.com), which hosts the app and its PostgreSQL database in the Netherlands. Railway processes data only to host the service. It does not receive the files.

There are no other processors. No email service, analytics service, advertising network, or error-reporting service receives your data or your shoppers' files.

How long it is kept

The upload list stays while the app is installed, so you can see which files arrived and which orders they belong to.

When you uninstall the app, Shopify sends a shop/redact request 48 hours later. On that request we delete everything we hold for your shop. The files in your store's Files are not deleted by us — the app no longer has access to your store at that point, and the files are part of your store.

You can ask for deletion sooner by emailing us.

Requests from shoppers

If a shopper asks your store for their data, their files are visible to you on their orders and in your store's Files.

If a shopper asks to be deleted, Shopify forwards a customers/redact request. We find their uploads by their customer ID and by the orders listed in the request, delete those files from your store's Files, and clear the file name, link, and customer ID from our list. If the app has already been removed from your store, we can no longer delete files there; you can delete them from Content → Files.

Changes

If what we store changes, this page changes with it before the change ships. The date at the top of this page is the last time that happened.

Contact

Questions, or a deletion request: beobjoong@gmail.com