ITLOX product privacy
Total Print Hub Privacy Notice
This notice explains how Total Print Hub handles merchant setup data, customer design data, production resources, supplier handoffs, billing-entitlement evidence, and optional AI workflow evidence when a Shopify merchant installs and uses the app.
1. Who operates Total Print Hub
Total Print Hub is developed and operated by ITLOX LTD, incorporated in England and Wales, and ITLOX, Inc., incorporated in Delaware, USA. UK and European customers are served by ITLOX LTD; United States customers are served by ITLOX, Inc. Other customers are served by the ITLOX entity identified in the applicable Shopify listing, order, or written agreement. In this notice, both entities are referred to as ITLOX.
167–169 Great Portland Street
London W1W 5PF, United Kingdom ITLOX, Inc. · United States customers 1111B S Governors Ave #91881
Dover, Delaware 19904
United States
Privacy questions and rights requests can be sent to dpo@itlox.com. Security reports should be sent to security@itlox.com.
2. Our role and the merchant's role
For content and personal data that a merchant or its customers submit through the app, the merchant generally determines why the data is processed and acts as the controller or business; ITLOX generally acts as the processor or service provider and follows the merchant's documented instructions. ITLOX acts as an independent controller for merchant account administration, Shopify app billing evidence, security, fraud prevention, support, product operations, legal compliance, and the protection of ITLOX rights.
Customers of a Shopify merchant should normally direct requests about an order or design to that merchant. ITLOX supports the merchant and Shopify's mandatory privacy workflows when a verified request is received.
3. Information we process
Shopify and merchant account information
- Shop domain, Shopify shop and app-installation identifiers, installation status, approved scopes, locale, plan and subscription status, and Shopify OAuth/session validation metadata.
- Merchant-user contact and support information, role and access records, feature preferences, onboarding progress, and security or audit events.
Merchant configuration and content
- Product and supplier-catalog mappings, product images and mockups, print areas, sides, variants, colours, sizes, templates, artwork, fonts, pricing rules, gang-sheet sizes, storefront settings, export settings, and supplier profiles.
- Merchant-uploaded assets and merchant-specific derivatives of shared art or font packs. A merchant override remains private to that merchant; resetting or deleting the override can reveal the original shared asset again.
Customer design, cart, order, and production information
- Design documents, text, uploaded artwork, font references, previews, dimensions, placement data, saved-design identifiers, cart properties, order references, and the minimum customer or order identifiers supplied by Shopify to connect a design to fulfilment.
- Export jobs, downloadable design resources, production packages, validation results, approval records, supplier handoff status, and operational audit evidence.
Technical, support, and optional feature information
- IP address, device and browser information, request identifiers, timestamps, diagnostic logs, security events, rate-limit evidence, and support communications.
- Supplier connection metadata and restricted credentials when a merchant chooses to connect a supplier.
- Bounded design briefs, product context, generated draft plans, safety results, provider request identifiers, and usage metadata when an authorised merchant enables optional AI features.
- Contact enquiries and optional product-update subscriptions, including business contact details, the consent version and time, the source form, and an email hash used to honour unsubscribe choices.
Total Print Hub is not designed to collect payment-card data, government identification numbers, health information, or other special-category or highly sensitive personal data. Payment credentials remain with Shopify.
4. How and why we use information
- Provide the contracted service: install and authenticate the app; configure products; run the Studio and gang-sheet builder; calculate quotes; preserve designs; connect carts and orders; generate production resources; and complete merchant-requested supplier workflows.
- Protect the service and users: isolate tenants, validate uploads, detect malware or abuse, investigate incidents, enforce entitlements, prevent fraud, and maintain security and audit records.
- Operate and improve the product: troubleshoot failures, measure reliability, provide support, and improve workflows using data minimised for the purpose.
- Answer and communicate: respond to requested sales or support enquiries and, only after explicit signup, send Total Print Hub product, release, and launch updates with a working unsubscribe route.
- Comply with law and enforce agreements: answer verified privacy requests, preserve evidence subject to legal hold, resolve disputes, and protect ITLOX, merchants, customers, and third parties.
Where UK or EEA law applies, the legal bases are performance of a contract, compliance with legal obligations, legitimate interests in securely operating and improving the service, and consent where consent is legally required. ITLOX processes merchant-customer content primarily on the merchant's instructions.
5. Disclosure and subprocessors
ITLOX discloses information only as needed to operate the service, follow merchant instructions, protect the platform, or comply with law. Recipients can include:
- Shopify for installation, authentication, app billing, storefront, cart, checkout, order, and mandatory privacy-webhook workflows.
- Cloud and security providers, including Amazon Web Services for isolated application infrastructure, databases, private object storage, delivery, backup, monitoring, and security services.
- Merchant-selected suppliers when the merchant intentionally submits or synchronises a production workflow.
- OpenAI only for the optional server-side AI workflow described in the AI policy, and only after the merchant enables that workflow.
- Professional advisers, authorities, or transaction parties when reasonably necessary for legal compliance, claims, corporate transactions, or protection against harm.
ITLOX does not sell personal information, share it for cross-context behavioural advertising, or allow one merchant to access another merchant's private content.
6. International transfers
ITLOX operates through UK and US entities and uses service providers that may process data in the United Kingdom, United States, and other approved locations. Where a restricted transfer requires safeguards, ITLOX uses an applicable adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent lawful mechanism, together with technical and organisational safeguards.
7. Retention, deletion, and uninstall
ITLOX retains personal data only for as long as reasonably necessary for the purpose collected. Merchant configuration and active design resources are normally retained while the app is installed or until the merchant deletes them. Order and production records follow merchant-configured retention periods and may be retained longer where required for fulfilment, accounting, dispute resolution, fraud prevention, or legal hold. Security logs and backups are retained for bounded operational periods and removed or overwritten under the applicable retention schedule.
Total Print Hub implements Shopify's required GDPR webhooks and privacy requests: customers/data_request, customers/redact, and shop/redact. Verified deletion requests are completed unless law requires particular information to be retained. Uninstalling the app revokes active access but does not override a lawful retention obligation.
Marketing enquiries are retained only while reasonably needed to answer and manage the relationship. An update subscription remains active until withdrawn. Unsubscribing removes the address from the active subscription record and preserves only the minimum hashed suppression record needed to honour that choice. Subscription choices are not tenant content and are never shared with Shopify merchants.
8. Security
Controls include Shopify OAuth/session validation, webhook HMAC verification, least-privilege access, tenant-scoped database enforcement, private object storage, signed short-lived asset access, encryption in transit and at rest where supported, upload validation, malware scanning, SVG sanitisation, structured formula execution without eval, secret-management controls, and audit logging for sensitive workflows. No service can guarantee absolute security; merchants must protect Shopify, staff, supplier, and device credentials and promptly report suspected compromise.
9. Cookies and similar technology
The app uses strictly necessary session, authentication, security, and load-balancing mechanisms required to operate an embedded Shopify app and its storefront design tools. Total Print Hub does not use merchant or customer data for third-party advertising or cross-site tracking. If optional analytics or non-essential cookies are introduced, this notice and any required consent controls will be updated before use.
10. Privacy rights
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to processing, obtain portability, withdraw consent, and appeal or complain about a privacy decision. California residents may also have rights to know, correct, delete, limit certain uses of sensitive information, and receive equal service; ITLOX does not sell or share personal information as those terms are defined by California law.
Send a request to dpo@itlox.com. ITLOX may verify identity and authority before acting. A merchant's customer should identify the relevant Shopify store so the request can be coordinated with the merchant. UK individuals can complain to the Information Commissioner's Office; EEA individuals can complain to their local supervisory authority; others can contact their applicable regulator.
Product-update consent can also be withdrawn using the unsubscribe link included in each update. Withdrawing optional marketing consent does not affect essential security, billing, support, or service communications.
11. Children
Total Print Hub is a business application for Shopify merchants and is not directed to children. Merchants must configure and operate customer-facing experiences in accordance with applicable age, parental-consent, and consumer-protection requirements. ITLOX does not knowingly use children's data for advertising or profiling.
12. Changes and related terms
ITLOX may update this notice to reflect product, legal, or operational changes. Material changes will be identified by a new effective date and, where required, communicated through Shopify or the merchant's registered contact. Use of Total Print Hub is also governed by the Total Print Hub Terms and the public billing policy.