Privacy Policy
How PlainKits (Craftheon, LLC) handles your data — what each Shopify app accesses, where it is processed, how long it is kept, and your rights.
Last updated: August 16, 2026
PlainKits is operated by Craftheon, LLC ("Craftheon," "we," "us," or "our"). This Privacy Policy explains how we handle information across plainkits.com and the PlainKits family of Shopify apps (each, an "App"), including PlainKits Image Export.
Information We Collect
On plainkits.com. This site does not require an account and does not use tracking cookies. We use privacy-respecting analytics (Google Analytics and Umami) to understand aggregate traffic — page views, referrers, and general device/location information. Where a measurement ID isn't configured for a given deployment, that analytics provider is not loaded at all.
Inside a PlainKits App. Each App runs embedded inside your Shopify admin and only accesses what its listed permissions cover. For PlainKits Image Export, that means:
- Product, variant, image, and collection data needed to build an export, requested under the
read_productsscope you grant during installation. - Your shop's domain and basic shop information, used to identify your store and enforce plan limits. This includes the store name and the store owner's contact email as recorded in Shopify.
- Basic account details of the staff members who open the App — name, email address, and locale, provided to us by Shopify when you sign in. We use these to tell you which exports are yours and to email you when a long-running export finishes or fails. We do not use them for marketing.
- Export job metadata (filters used, file counts, timestamps, status) needed to show your export history and calculate usage against your plan's monthly allowance.
- Billing status from Shopify's Billing API — we do not collect or store payment card details ourselves; Shopify handles all billing.
We do not access your customer data, orders, or store data beyond what a specific App's listed scopes require.
How We Use Your Information
We use this information to operate the Apps (build exports, enforce plan limits, show history and logs), to send transactional email about exports you started, to respond to support requests, and to improve reliability and features. We do not sell personal data, we do not send marketing email to staff addresses collected through an App, and we do not use App data to serve ads.
Where Data Is Processed
We rely on two infrastructure providers to run PlainKits:
- Shopify hosts the embedded App interface, handles authentication (OAuth) and merchant billing, and is the source of the store data an App reads.
- Cloudflare runs our application servers (Workers) and stores App data — export job records, generated files, and account/shop identifiers — in Cloudflare's database and storage products.
Both providers may process data outside your own country as part of their global infrastructure. Shopify's and Cloudflare's own privacy practices govern the parts of the process they control; see Shopify's Privacy Policy and Cloudflare's Privacy Policy for details.
Data Retention
Export job records and logs are retained for as long as your shop has the App installed, so your history stays visible. Generated files (for example, an export's ZIP archive) have a shorter retention window tied to your plan — see the App's own documentation or in-app messaging for current retention periods. Uninstalling an App does not immediately delete existing records: your access tokens are revoked at once, and the remaining store and staff records are erased when Shopify sends us the shop redaction request that follows an uninstall. Contact us if you'd like your data removed sooner.
Your Rights
Depending on your location, you may have rights to access, correct, or delete your personal data. To request this, uninstall the relevant App from your Shopify admin and/or email us at the address below — most store-level data is also visible and manageable directly from within the App while it's installed.
Children's Privacy
PlainKits Apps are business tools intended for use by Shopify merchants and their staff. We do not knowingly collect information from children.
Changes to This Policy
We may update this policy as PlainKits changes. Material changes will be reflected by updating the "Last updated" date above.
Contact
Questions about this policy? Email privacy@plainkits.com.