ProofLock · Shopify app
Privacy Policy
This policy explains how personal information is handled when merchants and their customers use ProofLock to review artwork and manage approval workflows for Shopify orders.
01 · Who we are
ProofLock is provided under the 99AppStudio brand by GOCLICK – Desenvolvimento Interativo Ltda., registered in Brazil under CNPJ 10.564.752/0001-39 ("we", "us" or "our"). Our contact location is São Paulo, State of São Paulo (SP), Brazil, postal code 03134-002.
This policy covers the ProofLock app, customer artwork-approval pages and related support communications. It does not replace the privacy policy of the store where a customer places an order or Shopify's own privacy policy.
For customer information handled to provide the merchant's artwork-approval workflow, the merchant determines the purpose of processing and we act on its behalf. For information we use to manage our own business relationship and respond to direct inquiries, we determine the purposes of that processing.
For order-related processing, the store's privacy notice also applies. Our service terms and any applicable data processing agreement govern the contractual relationship with the merchant; this privacy notice explains processing and does not replace those agreements.
02 · Information processed
Information received through Shopify
- Store identifiers and domain, installation details and authentication/session information needed to connect the merchant's store. Session information can include the authorized staff member's identifier, name and email when supplied by Shopify.
- Order identifiers and numbers, relevant order statuses, item descriptions, quantities and personalization information associated with the artwork workflow.
- Customer identifiers, customer names when included in the order record used by ProofLock, and email addresses used to associate a proof with an order and send approval messages.
ProofLock's intended approval workflow does not require customer phone numbers, shipping or billing addresses, or full payment-card information. Merchants should not add these details to artwork or free-text instructions unless genuinely necessary for their request.
Information supplied through ProofLock
Merchants upload artwork files, proof versions and instructions. Customers submit approval decisions or requests for changes. The app records workflow statuses and related event timestamps. Uploaded artwork and free-text notes may contain personal information supplied by the merchant or customer.
Support inquiries can include contact details and information voluntarily provided to resolve a problem. Please avoid including unnecessary personal information in artwork, notes or support requests, and do not send passwords, API keys or complete payment-card details.
03 · How information is used
ProofLock uses order and customer information to:
- Create and manage artwork approval requests linked to Shopify orders and items.
- Deliver transactional approval links and reminders.
- Display proofs, collect approvals or change requests and maintain version and workflow history.
- Prepare production work orders and manage release-to-production status.
- Support merchants and handle applicable data-access and deletion requests.
Artwork-approval messages concern an existing order; they are not promotional campaigns. In the described workflow, customers choose whether to approve artwork and merchants choose whether to release it to production.
Our policy is to use customer information only for the disclosed service purposes and applicable obligations, not to sell or rent it, share it for cross-context behavioral advertising, or use it to train general-purpose AI models. ProofLock's approval workflow does not make automated decisions with legal or similarly significant effects on customers. Any future change in purpose requires a separate assessment and appropriate notice and legal basis before it begins.
Legal grounds and merchant instructions
Merchants are responsible for identifying a lawful basis and providing the notices or obtaining the consent required for the customer processing they instruct us to perform. We process that information on the merchant's documented instructions, subject to applicable law.
For processing we determine ourselves, such as managing merchant relationships and responding to support inquiries, the relevant grounds are performance of a contract or requested pre-contractual steps where the individual is a party; legitimate interests in administering business relationships and resolving inquiries where appropriate and balanced against individuals' rights; and compliance with applicable legal obligations. Where a specific activity requires consent, that activity must not begin without the required consent and an effective way to withdraw it. Installing the app is not treated as blanket customer consent.
05 · Retention & deletion
Our retention policy is to keep identifiable information only while necessary for the relevant service purpose, merchant instructions or a specific applicable obligation. The following criteria determine retention; they are not a promise of indefinite storage or an immediate purge of every copy:
| Category | Retention criteria |
|---|---|
| Orders, proof files, versions and workflow history | For the merchant's active approval, production and necessary order follow-up purposes. When those purposes end, or a valid deletion instruction applies, the relevant data must be removed unless a specific lawful retention exception applies. |
| Privacy requests and support records | While the request is being handled and for the limited follow-up or evidence needed to demonstrate its resolution or meet an applicable obligation. Unnecessary attachments and personal details must not be retained solely for convenience. |
| Technical and security records, where generated | For the period needed to diagnose an issue, investigate abuse or meet a specific applicable obligation. Records retained for an investigation must be reviewed when that investigation ends. |
| Backup copies, where maintained | According to a limited recovery and rotation schedule. Data deleted from active systems must not be returned to normal use through restoration; relevant deletion instructions must be reapplied. Backup expiry is separate from deletion in active systems. |
ProofLock includes workflows for receiving Shopify privacy requests. Customer data requests are recorded for merchant handling, and an authenticated merchant export is available. Uninstall handling deactivates the store's app lifecycle, cleans up sessions and prevents continued reminder and public-link access. Uninstallation should not be understood as immediate deletion of all stored information.
Shopify customer-deletion and shop-redaction requests must be handled through the corresponding privacy workflow. If some information must be kept to meet a legal obligation or establish, exercise or defend a claim, retention must be limited to that purpose and end when the justification expires. You can ask about the retention or deletion of a particular record through our privacy contact.
06 · Security
The described app includes authenticated merchant access, store-isolated exports and signed customer approval links. No transmission or storage system can guarantee absolute security.
Our security policy requires access to personal information to be limited to authorized people and services that need it for the disclosed purposes. Credentials and approval links must be kept confidential, and suspected incidents must be assessed and addressed. Where an incident creates a legal notification duty, the relevant merchant, authority or affected individual must be notified as required by applicable law.
This notice does not represent a third-party security certification or a guarantee that all risks can be prevented.
To report a suspected privacy or security issue, use the contact details in section 10. Do not include live approval links or credentials in public reports.
07 · Your rights & choices
Depending on applicable law and the circumstances, individuals may have rights to request access, correction, deletion or a portable copy of their information, restrict or object to processing, withdraw consent where processing relies on it, or complain to a competent data protection authority.
If you are a customer of a merchant using ProofLock, contact that store first about information associated with your order. The merchant controls the order relationship and can coordinate requests involving ProofLock. You may also contact us using section 10; we may need to verify identity and coordinate with the relevant merchant before disclosing or changing information.
Merchants can use the available privacy-request tools and contact us for assistance. Requests must be handled within the deadlines required by applicable law. Withdrawing consent, where relevant, does not affect the lawfulness of earlier consent-based processing.
Our request-handling policy is to ask only for information proportionate to verifying the request, explain any applicable refusal or limitation, and avoid charging a fee unless permitted by law. Exercising a privacy right must not result in unlawful discrimination. Individuals in Brazil may also contact the Autoridade Nacional de Proteção de Dados (ANPD); elsewhere, the competent local data protection authority may be appropriate. Contacting us does not prevent a complaint to an authority.
09 · Policy updates
We may update this policy to reflect changes in ProofLock or applicable requirements. The revision date identifies this version. Where required, we will provide additional notice or obtain consent before a relevant change takes effect.
10 · Contact
For privacy questions or requests concerning ProofLock:
Operator: GOCLICK – Desenvolvimento Interativo Ltda. (99AppStudio / ProofLock)
Brazilian company registration (CNPJ): 10.564.752/0001-39
Privacy contact: notifications@99appstudio.com
Postal code (CEP): 03134-002
City / State: São Paulo / São Paulo (SP), Brazil