Privacy policy
Last updated 4 August 2026
Who we are
Downlio is a Shopify app that delivers digital files to customers after they buy. We act as a data processor for the merchant who installs us; the merchant is the data controller for their customers’ data.
What we collect from merchants
- Your Shopify store domain, store name, contact email, currency, timezone, country and Shopify plan — read once at install and refreshed periodically.
- An offline access token for your store, encrypted at rest with AES-256-GCM.
- The files you upload, and the settings you configure.
What we collect about your customers
Only what is needed to deliver a file and prove it arrived:
- Name and email address from the order.
- Order number, line items and financial status.
- Email delivery events from our sending provider — sent, delivered, bounced, complained.
- Download events: timestamp, IP address, country and browser user agent. These enforce your download limits and device caps, and give you the evidence trail when a customer says a file never arrived.
We do not collect payment details, and we never sell or share personal data with third parties for their own purposes.
Sub-processors
- Supabase (United States) — database hosting.
- Cloudflare R2 — file storage.
- Resend — transactional email delivery.
- Vercel — application hosting.
How long we keep it
- While installed: for as long as you need the delivery history.
- After uninstall: 30 days, then everything — database rows and stored files — is deleted. This grace period exists so an accidental uninstall and reinstall doesn’t lose your library.
- Personalised file copies: 90 days, then removed and regenerated on demand.
GDPR and CCPA requests
We implement Shopify’s mandatory compliance webhooks. When a customer asks a merchant for their data, we compile everything we hold for that email and send it to the merchant’s contact address. When a redaction is requested, we remove the customer’s name, email and IP addresses and revoke their download links. When a shop is redacted, we delete the store entirely, including every stored file.
You can also reach us directly at privacy@downlio.app.
Security
- Shopify access tokens and buyer download links are encrypted at rest with per-purpose derived keys.
- Download links carry a hashed secret. The database stores only the hash, so a database copy alone yields no working links.
- Every database table denies public access; all reads go through our server with a service credential.
- All traffic is TLS-encrypted, and file downloads use short-lived URLs.
Changes
If we change this policy in a way that affects what we collect, we’ll email the contact address on your store before it takes effect.