UploadDrop Privacy Policy

Last updated: April 22, 2026

This Privacy Policy explains how UploadDrop (“UploadDrop”, “we”, “us”) collects, uses, stores, and shares personal data when merchants install and use the UploadDrop Shopify app. UploadDrop lets Shopify merchants collect customer image uploads from their storefront and link those uploads to Shopify orders.

UploadDrop is operated by Innovation Institute of Sweden AB, established in Sweden (European Union). For the purposes of the EU General Data Protection Regulation (GDPR), UploadDrop typically acts as a data processor on behalf of the merchant (the controller) with respect to customer personal data that flows through the app, and as a data controller for account-level data about the merchant and the shop.

Who this policy applies to

This policy applies to:

What information we collect through Shopify’s APIs

When a merchant installs UploadDrop, we receive and store the following categories of data from Shopify:

What information we collect directly from merchants

What information we collect from merchants’ customers

When an end customer uses the UploadDrop storefront widget to submit an image, UploadDrop processes:

UploadDrop does not set marketing or analytics cookies on storefront visitors, does not operate tracking pixels, and does not build advertising profiles about individual customers. Uploaded images may themselves contain personal data (for example, a photograph of a person) depending on what the customer chooses to upload; the merchant is responsible for determining the lawful basis for collecting such content.

How we use this information

UploadDrop uses personal data only to:

Under the GDPR, the legal bases we rely on are: performance of a contract (operating the app for the merchant), compliance with a legal obligation (responding to privacy webhooks and lawful requests), and our legitimate interests in securing, operating, and improving the service.

Data retention

Sub-processors and international data transfers

UploadDrop is established in Sweden (EU) and relies on the following sub-processors to operate the service:

Depending on the merchant’s Cloudflare R2 region setting, uploaded customer files are stored either in Eastern North America (via a Cloudflare location hint, best-effort placement) or in the European Union (via Cloudflare’s eu Jurisdictional Restriction, which guarantees EU-only storage and processing for those objects). Application data held by our other sub-processors (Fly.io, Supabase, Shopify) may be stored or processed outside the European Economic Area (EEA), including in North America. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework, or equivalent transfer mechanisms required by GDPR Chapter V.

How we share data

UploadDrop does not sell personal data and does not share personal data with third parties for advertising purposes. We share data only with:

Your data rights

Depending on where you live, you may have rights under laws such as GDPR, the UK GDPR, the California Privacy Rights Act (CPRA), the Colorado Privacy Act, and Virginia’s Consumer Data Protection Act, including the right to:

End customers who uploaded images through a merchant’s storefront should contact that merchant first, since the merchant is the controller of that data. We will support the merchant in responding to such requests, including through Shopify’s mandatory privacy webhooks. Merchants and other individuals can also contact us directly using the details in the Contact section below.

Shopify mandatory privacy webhooks

UploadDrop implements the three mandatory Shopify compliance webhooks:

Security

UploadDrop serves all traffic over HTTPS and relies on managed infrastructure providers with strong, industry-standard security controls for compute, database, and object storage. Access to production data is restricted to authorized personnel who need it to operate, maintain, and support the service. No online service can be guaranteed to be 100% secure, but we work to protect personal data from unauthorized access, alteration, disclosure, and destruction.

Merchant responsibilities and acceptable content

UploadDrop is a tool that enables a merchant to collect images from their own customers. The merchant, as the data controller and the operator of their storefront, is solely responsible for what is uploaded through their store and for how that content is used. In particular, the merchant is responsible for:

UploadDrop does not review or moderate uploaded content and does not control what customers choose to upload. UploadDrop may, however, remove content or suspend access where we believe in good faith that it is necessary to comply with law, to protect the rights and safety of others, or to address a violation of our terms.

Children’s data

UploadDrop is not directed at children and is not intended for the collection of personal data from children. Merchants using the app to collect content from minors must have an appropriate legal basis (for example, verifiable parental consent where required) and should not use UploadDrop otherwise.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and post the updated version at this URL. Material changes will also be communicated to installed merchants where reasonably practical.

Contact

For privacy questions, data subject requests, or other concerns about how UploadDrop handles personal data, contact us at:

Email: support@uploaddropapp.com

Innovation Institute of Sweden AB
Box 2062
116 74 Stockholm
Sweden