Privacy Policy
How PlainKits (Craftheon, LLC) handles your data — what each Shopify app accesses, where it is processed, how long it is kept, and your rights.
Last updated: October 7, 2026
PlainKits is operated by Craftheon, LLC ("Craftheon," "we," "us," or "our"). This Privacy Policy covers plainkits.com and our Shopify apps, including PlainKits Image Export and PlainKits Image Upload.
Information We Collect
On plainkits.com. You do not need an account to browse our website. When configured, Google Analytics and Umami collect website activity such as page views, referrers, device information, and approximate location. Google Analytics and our support chat may use cookies or similar browser storage. Providers that are not configured are not loaded.
In our Shopify apps. We receive your shop domain, store name, owner name, owner and contact email addresses, currency, and timezone. Shopify also supplies basic details of staff members who open an app, including their name, email, locale, account role, and app authorization information. We store authentication sessions and access tokens to operate the app and authorize requests. These tokens are not sent to analytics services.
Each app accesses the store data needed for its function:
- Image Export: Product, variant, image, and collection data under
read_products, to generate the exports you request. - Image Upload: Product and variant identifiers, titles, SKUs, barcodes, image references, and related catalog information under
read_products;write_productsandwrite_filesallow the app to upload images and apply the product image changes you confirm. Users are authenticated through Shopify. Product operations and background tasks use the store-level authorization granted to the app. Store owners should manage which staff members can access the app in Shopify, because app access allows them to initiate these store-level operations. - Upload files: The ZIP archive you choose, its image files, file names and paths, and any optional CSV mapping. Archive inspection and thumbnail generation occur in your browser. To execute an upload, we temporarily store the ZIP in Cloudflare R2; our processing service retrieves it, extracts the required images, and sends them to Shopify. A CSV may contain product identifiers, SKUs, or barcodes and takes priority when matching images. Please include only files needed for the upload, without customer information or unrelated personal data.
- Task and billing records: Task IDs, selected options, matching decisions, image counts, timestamps, status, errors, logs, plan information, and usage reporting records. Shopify processes merchant payments; we do not collect or store payment card details.
Our image apps do not request customer or order access scopes. Any personal information you voluntarily include in an archive, support message, or attachment is nevertheless processed as part of that submission.
How We Use Your Information
We use information to generate exports, match and upload images, apply your chosen image settings, display task history, authenticate users, enforce plan limits, and report billable usage to Shopify. Depending on the app and its notification settings, we may send transactional task emails. Support messages are used to answer your questions and troubleshoot problems.
We also use product analytics to understand app activity and improve reliability and features. We do not sell personal data, use app data to serve advertisements, or send marketing email to staff addresses collected through Shopify authentication.
Service Providers and Processing Locations
We use the following services where configured:
- Shopify: Authentication, store APIs, storage of images successfully uploaded to your store, and merchant billing. Our interfaces are displayed within Shopify admin, while our infrastructure serves the app.
- Cloudflare: Website and app hosting, databases, queues, and file storage, including temporary upload archives and generated exports. Our processing services retrieve files from storage to perform the tasks you request.
- Mixpanel: App usage events and shop profiles. These may include your shop domain, store name, owner name, owner/contact email, currency, timezone, app identifier, plan, task/source IDs, image counts, status, and timing. We do not intentionally send ZIP archives, image contents, CSV contents, access tokens, or payment card details to Mixpanel. Analytics profiles may identify the same shop across multiple PlainKits apps.
- Resend: Delivery of transactional emails, including the recipient address and the task information contained in the email.
- Crisp: Support chat, including messages, attachments, contact details you provide, and technical information needed to operate the chat.
- Google Analytics and Umami: Website analytics as described above.
These services and our infrastructure may process information outside your country. See the privacy policies of Shopify, Cloudflare, Mixpanel, Resend, Crisp, Google, and Umami. Service providers receive information for the purposes described in this policy.
Data Retention and Deletion
Task history, logs, account details, and billing/usage records are kept while the app is installed to provide history, support, and billing reconciliation. Generated export files have the retention period displayed in the app or your plan.
For Image Upload, ZIP archives, matching file indexes, and catalog snapshots are temporary processing data. When a task finishes, fails, or is cancelled, cleanup is scheduled to remove these temporary records and archives. Cleanup runs asynchronously and is retried when necessary, so deletion is not instantaneous. Sources without a completed task may remain until source expiration cleanup or a store deletion request is processed. Task history and usage records are separate from these temporary files. Images uploaded successfully remain in Shopify until you remove them or authorize another change.
Uninstalling an app revokes its Shopify authorization. Remaining store and staff records are removed through Shopify's shop redaction process. Information required for outstanding billing, legal obligations, or dispute resolution may need to be retained until those obligations are resolved. Uninstalling an app does not itself erase support correspondence or provider-held analytics. Contact us to request deletion of those records as well. If you use multiple PlainKits apps, specify which app's data you want removed, because some shop information is shared across app analytics profiles.
Your Rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal information, or object to certain uses. Email us with your shop domain and the relevant app name. We may need to verify that you are authorized to make the request. Requests can include analytics and support records as well as app data; uninstalling is not required to contact us.
Children's Privacy
PlainKits apps are business tools for Shopify merchants and their staff. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy as our services change. The "Last updated" date above identifies the latest revision.
Contact
For privacy questions or data requests, email privacy@plainkits.com.