Privacy policy
Last updated 3 October 2026
Proofmark (the “App”) lets Shopify merchants, and the agencies and developers who build their stores, collect feedback on an unpublished theme. Invited reviewers pin comments directly onto a preview of the theme, and the team replies and resolves them from the Shopify admin. The App is operated by [Legal name of the business that runs the app] (“we”, “us”).
This policy explains what personal data the App handles, why, who it is shared with, and how long it is kept. It applies to merchants who install the App, their staff, and the reviewers they invite.
Our role
For data about a store's staff and reviewers, the merchant who installed the App decides who is invited and what is kept. The merchant is the controller of that data and we process it on their behalf to provide the App. If you are a reviewer and want to access or delete your data, you can contact the merchant or agency that invited you, or contact us directly and we will work with them.
What we collect
From Shopify, when a merchant installs the App
- The store's myshopify.com domain and store name, and the access token Shopify issues so the App can call the Shopify Admin API.
- For each staff member who opens the App in the Shopify admin: their name, email address and Shopify user ID, so their comments and replies can be attributed to them and they can receive notifications.
- The names, IDs and roles (published or unpublished) of the store's themes. The App uses these to make sure comments are only ever possible on unpublished themes.
The App does not access a store's products, orders, customers, payments or analytics.
About reviewers
- Contact details: the email address a reviewer is invited with, and their name if they give one.
- Access requests: if someone asks for access from the preview, the email address, name and message they enter.
- Sign-in records: when a reviewer signs in, the time, when the session was last active, when it expires, and the browser name reported by their device (the user agent), so the team can see and revoke active sessions.
- Shopify customer ID: if a reviewer is also signed in to the store as a customer when they first use a sign-in link, the App records that customer ID so it can recognise them on another device without another email. The App does not read anything else from the customer account.
Comments
- The text of each comment and reply, who wrote it, and when it was written, edited, resolved or reopened.
- Where it was placed: the page address and title, the position on the page, the element it was pinned to, and the screen width at the time.
- A screenshot of the part of the page the comment was pinned to. This is an image of the store's own theme, captured in the reviewer's browser. It is not a recording of the reviewer's screen.
- Which comments each person has read, and a log of activity (for example “thread resolved”) that the App uses to show the team how long feedback takes to resolve.
Store settings
If a merchant enters their storefront password in the App's settings, the App stores it and includes it in invitation emails so reviewers can get past the password page. Merchants should only enter it if they are happy for invited reviewers to receive it.
In the reviewer's browser
The App does not use any analytics, advertising or tracking tools. On the store's preview, it keeps a few values in the browser's local storage:
ctc_sid: the reviewer's sign-in token, so they stay signed in.ctc_auto_customer: whether to sign in automatically when the reviewer is recognised as a customer of the store.ctc_collapsedandctc_bar_pos: whether the comment toolbar is collapsed, and where it was dragged to.ctc_resume_tried(session storage, cleared when the tab closes): stops the sign-in step below from repeating.
The App sets one cookie, ctc_pending, on its own domain when someone opens a sign-in link or a link to a comment. It holds that link's single-use code or the comment's ID, so the link can still finish after the store's password page, and it expires after an hour, or as soon as it has been used. The App sets no cookies on the store's domain.
The App only runs on unpublished preview themes. It does not load for shoppers on a store's live theme and collects nothing about them.
How we use it
- To provide the App: showing comments, replies and screenshots to the team and the people they invited.
- To send email: invitations, single-use sign-in links, notifications of new comments, replies and resolutions, and access requests to the team.
- To keep the App secure: verifying requests come from Shopify, limiting how often sign-in links can be requested, and letting the team revoke sessions.
- To answer privacy requests and meet our legal obligations.
We do not sell personal data, use it for advertising, build profiles, or use it to train machine-learning models.
Who we share it with
Comments and screenshots are visible to the store's team and to the reviewers they invited to that store, and to no one else. We use the following service providers to run the App. Each only processes data to provide its service to us.
| Provider | Purpose |
|---|---|
| Shopify | App platform, sign-in to the admin, and theme information |
| [Hosting provider, e.g. Fly.io] | Runs the App's servers |
| Neon | Database that stores the data described above |
| [Screenshot storage, e.g. Cloudflare R2] | Stores comment screenshots ([Region, e.g. EU]) |
| Resend | Sends the App's emails |
Our hosting provider may keep request logs, which can include IP addresses, for security and troubleshooting. We may also disclose data if the law requires it.
How long we keep it
- Sign-in sessions last 30 days from the last activity and are deleted once they expire.
- Sign-in links expire after 7 days and stop working after one use. They are deleted when they expire, or 7 days after being used.
- Comments and screenshots stay until the team deletes the conversation. When a theme is published or deleted, its comments are archived and then deleted, screenshots included, after the store's retention period (180 days unless the merchant changes it).
- Reviewers: the team can remove a reviewer's access at any time, which ends their sessions immediately. Their comments stay in the conversations they belong to. To have a reviewer's data deleted, see Your rights below.
- When a merchant uninstalls the App, all reviewer sessions end at once, and all of the store's data is deleted 30 days later. If Shopify sends us its request to erase a store's data (48 hours after uninstalling), we delete everything immediately.
Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, and to object to or restrict how it is used. Shopify sends us data requests and erasure requests on behalf of stores and their customers, and we act on them:
- For a data request, we send the store owner everything the App holds about the person, so they can pass it on.
- For an erasure request, we delete the person's account, comments, access requests and sign-in records, and remove them from the activity log. Replies other people wrote in the same conversation are kept, credited to a “Deleted reviewer”.
You can also contact us at [privacy@yourdomain.com]. We respond within 30 days. If you are in the EU, UK or another region with a data protection authority, you have the right to complain to it.
Security
All traffic to the App is encrypted with HTTPS. Requests from the storefront are signed by Shopify and checked by the App. Sign-in links and session tokens are stored only as one-way hashes. Screenshots are never published at a public address: they are only shown to people signed in to that store. Each store's data is kept separate from every other store's.
International transfers
Our service providers may process data outside the country where you live. Where the law requires it, we rely on safeguards such as the European Commission's standard contractual clauses.
Children
The App is a business tool and is not intended for anyone under 16. We do not knowingly collect data about children.
Changes to this policy
If we change this policy, we will update the date at the top of this page. If a change is significant, we will also tell merchants who have the App installed.
Contact
[Legal name of the business that runs the app]
[Business postal address]
[privacy@yourdomain.com]