Version: 1.1.3 - Last Updated: June 2, 2025
1. Introduction
Upload Center ("we", "our", or "Application") is an application operating on the Shopify platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal data.
This policy has been prepared in accordance with various international data protection laws, including the European Union General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Brazil's General Data Protection Law (LGPD), Australian Privacy Principles (APP), Japan's Act on the Protection of Personal Information (APPI), India's Digital Personal Data Protection Act (DPDP), China's Personal Information Protection Law (PIPL), and Quebec's Law 25.
By using Upload Center, you accept the practices described in this Privacy Policy. If you do not accept our policy, please discontinue using our Application.
2. Data Controller and Contact Information
Upload Center is the data controller for the processing of your personal data. If you have any questions or concerns about our privacy practices or this policy, please contact us using the following information:
3. Personal Data We Collect
Upload Center collects and processes the following personal data to provide our services:
3.1 Store Owner Data
•Email address: The email address associated with the store owner's Shopify account.
•Name and surname: The name and surname information associated with the store owner's Shopify account.
This information is used for promotional and informational purposes and is not shared with third parties.
3.2 Customer Data
•Customer ID numbers: Only customer identification numbers provided by Shopify.
This information is necessary for the core functionality of our Application and is not shared or sold to third parties.
3.3 Order Data
•Order information: The store owner's order data.
This information is necessary for the core functionality of our Application, is not processed in any way, and is not shared or sold to third parties.
3.4 Uploaded Files
•Customer files: Files uploaded by customers to orders.
These files are stored on secure servers provided by Google Cloud Platform (GCP). The security of these files is a shared responsibility between us and Google LLC. Google is responsible for the security *of* the cloud, which includes the physical infrastructure and the integrity of their storage service. We are responsible for security *in* the cloud, which includes correctly configuring access controls (IAM), ensuring secure data transmission protocols (HTTPS), and managing the overall security of how our application interacts with the storage service. We are committed to implementing best practices to protect the security and integrity of these files. These files are not shared or sold to third parties.
Upload Center uses Google Cloud Platform (GCP) services provided by Google LLC as a sub-processor for the purpose of storing customer files.
Currently, all customer data is physically stored exclusively in Google Cloud Platform data centers located in Frankfurt, Germany.
Our company reserves the right to change the location of the data center where customer files are stored in the future for reasons such as operational requirements, performance improvements, disaster recovery scenarios, or legal obligations. In the event of any change in the data storage location, this Privacy Policy will be updated and/or you will be notified in advance via your registered contact information.
Regardless of the storage location, our company commits to continuing to take the most up-to-date technical and administrative measures to ensure the security and confidentiality of your data.
4. Purposes and Legal Bases for Processing Personal Data
4.1 Store Owner Data
We process the store owner's email address and name-surname information for the following purposes and legal bases:
•Purpose: To provide promotional and informational communications.
•Under GDPR: Explicit consent and legitimate interest.
•Under CCPA: Business purpose.
•Under LGPD: Explicit consent and legitimate interest.
•Under Quebec Law 25: Explicit consent.
•Under PIPL: Explicit consent.
•Under APPI: Explicit consent.
•Under APP: Explicit consent.
•Under DPDP: Explicit consent.
4.2 Customer ID Numbers
We process customer ID numbers for the following purposes and legal bases:
•Purpose: To provide application functionality.
•Under GDPR: Performance of a contract.
•Under CCPA: Business purpose.
•Under LGPD: Performance of a contract.
•Under Quebec Law 25: Performance of a contract.
•Under PIPL: Performance of a contract.
•Under APPI: Business purpose.
•Under APP: Business purpose.
•Under DPDP: Performance of a contract.
4.3 Order Data
We process order data for the following purposes and legal bases:
•Purpose: To provide application functionality.
•Under GDPR: Performance of a contract.
•Under CCPA: Business purpose.
•Under LGPD: Performance of a contract.
•Under Quebec Law 25: Performance of a contract.
•Under PIPL: Performance of a contract.
•Under APPI: Business purpose.
•Under APP: Business purpose.
•Under DPDP: Performance of a contract.
4.4 Uploaded Files
We process files uploaded by customers for the following purposes and legal bases:
•Purpose: To provide application functionality.
•Under GDPR: Performance of a contract.
•Under CCPA: Business purpose.
•Under LGPD: Performance of a contract.
•Under Quebec Law 25: Performance of a contract.
•Under PIPL: Performance of a contract.
•Under APPI: Business purpose.
•Under APP: Business purpose.
•Under DPDP: Performance of a contract.
5. Data Retention Periods
We retain your personal data only for as long as necessary for the purpose for which it was collected. The retention periods are as follows:
•Store owner data: Until the store owner terminates their Upload Center subscription or for 24 months from the last interaction (whichever is longer).
•Customer ID numbers: For 12 months from the completion of the relevant order.
•Order data: For 12 months from the completion of the relevant order.
•Uploaded files: For 1 month from the completion of the relevant order.
When these periods expire, your personal data will be securely deleted.
6. Data Security
Upload Center takes appropriate technical and organizational measures to ensure the security of your personal data. These measures include:
•Regular security assessments
•Staff training and access control
•Data breach detection and response procedures
The security and data integrity of uploaded files are the responsibility of Google LLC and are subject to Google LLC's security protocols.
7. Data Sharing and International Data Transfers
Upload Center does not share or sell the personal data it collects to third parties. However, we may share data in the following circumstances:
•Service providers: Service providers we use to support the functionality of our Application (e.g., Google Cloud Platform(GCP) servers).
•Legal requirements: When necessary to comply with a legal obligation, protect our legal rights, or respond to a legal process.
In the case of international data transfers, we take appropriate safeguards to ensure the security and privacy of the data. These safeguards may include Standard Contractual Clauses, Binding Corporate Rules, or other legal mechanisms.
8. Data Subject Rights
Under data protection laws, you have various rights regarding your personal data. These rights may vary depending on your location and applicable laws, but generally include:
8.1 Rights Under GDPR (European Union)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request erasure of your personal data ("right to be forgotten")
•Right to request restriction of processing of your personal data
•Right to data portability
•Right to object to processing
•Right not to be subject to automated decision-making and profiling
8.2 Rights Under CCPA (California)
•Right to access your personal data
•Right to request deletion of your personal data
•Right to opt-out of the sale of your personal data
•Right to non-discrimination
8.3 Rights Under LGPD (Brazil)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request deletion of your personal data
•Right to data portability
•Right to object to processing
8.4 Rights Under Quebec Law 25 (Quebec, Canada)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request deletion of your personal data ("right to be forgotten")
•Right to data portability
•Right to object to processing
8.5 Rights Under PIPL (China)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request deletion of your personal data
•Right to request explanation of data processing activities
•Right to object to automated decision-making
8.6 Rights Under APPI (Japan)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request cessation of processing of your personal data
8.7 Rights Under APP (Australia)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to lodge a privacy complaint
8.8 Rights Under DPDP (India)
•Right to access your personal data
•Right to request rectification of your personal data
•Right to request erasure of your personal data
•Right to object to processing
To exercise these rights, please contact us using the contact information provided in Section 2. After receiving your request, we will verify your identity and respond within the legal timeframe (generally 30 days).
9. Children's Privacy
Upload Center does not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal data from a child under the age of 16, we will take steps to delete that data as soon as possible. If you believe we have collected personal data from a child under the age of 16, please contact us using the contact information provided in Section 2.
10. Cookies and Similar Technologies
Upload Center does not use cookies or similar tracking technologies.
11. Data Breach Notifications
In the event of a data breach involving your personal data, we will notify the relevant supervisory authorities and affected data subjects in accordance with applicable data protection laws. Under GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the data breach. Under other laws, we will notify within the timeframe required by the relevant law.
12. Changes to the Privacy Policy
We may update this Privacy Policy from time to time. In the event of significant changes to the policy, we will publish the updated policy and, if necessary, notify you by email. To see when this policy was last updated, please refer to the "Last Updated" date at the top of this page.
13. Complaints
If you have a complaint regarding the processing of your personal data, please first contact us using the contact information provided in Section 2. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your location.
14. Effective Date
This Privacy Policy is effective from the date of publication and applies to all users of Upload Center.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call or email us at contact@quaflow.com or contact us at Veskiposti 2, 1002, Tallinn, 10138, EE.