Privacy Policy
Upload Box · last updated 2026-09-30 · Terms of Service
What this app stores
Upload Box adds a file upload button to your product pages. Shoppers' files are saved to your own store's Files in Shopify, and a link to each file is added to the cart item, so it shows on the order. The app itself keeps the following, keyed to your shop domain:
- A list of uploads: the file name, its type and size, the ID and link of the file in your store's Files, the product and variant it was uploaded on, when it was uploaded, — if the shopper was logged in to your store — their customer ID, and, once the file is on an order, that order's ID and number.
- Your plan, the price you signed up at, and how many uploads were added to orders each month.
- An access token issued by Shopify when you install the app, used to create and delete files in your store's Files.
Where the files are
The files themselves are not stored on our servers. The shopper's browser sends each file directly to Shopify, and the app then adds it to your store's Files (Content → Files in your Shopify admin). Files there are served from Shopify's content delivery network at addresses that are hard to guess, which is how the link on the order can be opened by you and your staff.
Because the files are in your store, they stay there if you remove the app. You can delete them at any time from Content → Files.
What this app does not collect
We only receive what a shopper chooses to upload. We do not track shoppers who do not upload, and we set no cookies.
To slow down abuse, uploads are rate-limited by the sender's network address. That address is kept only in the app's memory, is cleared within a minute after a ten-minute window ends, and is never written to the database.
When an order is placed, the app reads only which uploads are on it (the order ID, the order number, and the upload references on each item). It does not read or store the customer's name, email, address, or phone number from the order.
We do not receive payment information.
We do not use your data or your shoppers' files to train models, and we do not sell or share them.
Who receives it
Shopify, which stores the files in your store's Files and attaches the links to your orders. From then on the files are part of your Shopify store data.
Railway (railway.com), which hosts the app and its PostgreSQL database in the Netherlands. Railway processes data only to host the service. It does not receive the files.
There are no other processors. No email service, analytics service, advertising network, or error-reporting service receives your data or your shoppers' files.
How long it is kept
The upload list stays while the app is installed, so you can see which files arrived and which orders they belong to.
When you uninstall the app, Shopify sends a shop/redact request 48 hours later. On that request we delete everything we hold for your shop. The files in your store's Files are not deleted by us — the app no longer has access to your store at that point, and the files are part of your store.
You can ask for deletion sooner by emailing us.
Requests from shoppers
If a shopper asks your store for their data, their files are visible to you on their orders and in your store's Files.
If a shopper asks to be deleted, Shopify forwards a customers/redact request. We find their uploads by their customer ID and by the orders listed in the request, delete those files from your store's Files, and clear the file name, link, and customer ID from our list. If the app has already been removed from your store, we can no longer delete files there; you can delete them from Content → Files.
Changes
If what we store changes, this page changes with it before the change ships. The date at the top of this page is the last time that happened.
Contact
Questions, or a deletion request: beobjoong@gmail.com