Privacy Policy
Last updated: April 10, 2026
This Privacy Policy describes how Brand Studio ("we", "us", "the App") collects, uses, and protects information when you install and use our Shopify app.
1. Who we are
Brand Studio is a Shopify app developed and operated by [Legal Entity Name], registered in [Country]. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the information described in this policy. You can contact us at any time at privacy@dreamstate.dk.
2. What we collect
From your Shopify store
When you install the App, we receive the following information from Shopify via OAuth:
- Shop domain - your
*.myshopify.comaddress - Access token - used to call the Shopify Admin API on your behalf, scoped to the permissions you granted at install
- Product data - product titles, descriptions, and existing image URLs that you choose to work with inside the App
That you provide directly
- Uploaded images - any product photo you upload for generation
- Prompts - text you write describing the desired output
- Custom API keys (optional) - if you opt into the Bring Your Own Key feature, API keys for supported external AI providers
- Support messages - anything you send us through the in-app chat
That we generate ourselves
- Generated images - the AI output produced from your uploads and prompts
- Usage records - date, time, generation settings, success or failure status, and current monthly count for plan enforcement
- Subscription state - your current plan, billing status, and renewal date as reported by Shopify Billing
What we do NOT collect
- We do not collect data about your end customers (their names, emails, addresses, orders, or any personal data). The App only interacts with product data and your merchant account.
- We do not use cookies, fingerprinting, or any browser tracking technology beyond what Shopify itself uses to authenticate the embedded app session.
- We do not sell or rent any data to third parties, ever.
3. How we use your data
We process the data described above for the following purposes:
- To provide the service - generating images, saving them to your products, enforcing plan limits
- To bill you - Shopify handles payment processing; we receive notifications about subscription state via Shopify webhooks
- To support you - responding to your messages in the in-app chat
- To prevent abuse - rate limiting and content moderation to protect the service and other merchants
- To improve the service- aggregate, non-identifying metrics like "X% of generations succeeded this week". We never inspect individual prompts or images for product development.
4. Service providers
We share necessary data with trusted service providers in the categories below. We choose them carefully and use them only as needed to operate the App:
- Cloud database, file storage, and authentication providers - host the App backend and store merchant data in EU regions where possible.
- AI generation providers - receive uploaded images, prompts, and related generation settings to create requested outputs. We do not allow these providers to use merchant content to train public models where our provider terms give us that control.
- Shopify - receives subscription events and serves generated images you save to your products. shopify.com/legal/privacy
- Error tracking and performance monitoring providers - help us diagnose failures. We strip personal data before sending diagnostic events where possible.
- Hosting and infrastructure providers - serve the App frontend and backend. Standard request logs only.
5. Where your data lives
Our primary database and file storage is hosted in EU regions where possible. Generated images may be processed temporarily by AI generation providers, which may operate servers globally. Standard contractual clauses are in place where required for cross-border data transfers under GDPR.
6. How long we keep it
- Source uploads and generated image files - purged from storage automatically after 30 days. The metadata row (prompt, generation settings, status, timestamps) is kept for audit purposes.
- Merchant record + usage history - kept while you have the App installed.
- After uninstall - we delete your merchant record, all custom keys, support messages, and usage history within 48 hours via Shopify's mandatory
shop/redactwebhook. - Support messages - kept for the duration of the conversation thread, deleted with the merchant record on uninstall.
- Error logs - automatically expire after 30 days.
7. Security
We take security seriously. Specifically:
- All traffic is encrypted in transit using TLS 1.2 or higher.
- All data is encrypted at rest in our database.
- API keys you provide for Bring Your Own Key are stored encrypted and only decrypted in memory at the moment a generation request runs.
- Image storage uses signed URLs that expire after 1 hour, so even if a URL leaks it can't be reused.
- Access to production systems is restricted to a small number of authorized administrators with multi-factor authentication.
8. Your rights under GDPR
If you are based in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:
- Right of access - request a copy of all data we hold about you
- Right to rectification - correct inaccurate data
- Right to erasure - request that we delete your data (uninstalling the App also triggers automatic deletion)
- Right to restriction of processing
- Right to data portability - receive your data in a machine-readable format
- Right to object to processing
- Right to lodge a complaint with your local data protection authority
To exercise any of these rights, email privacy@dreamstate.dk. We will respond within 30 days. We do not require any specific form or formality - a plain email is sufficient.
9. Shopify GDPR webhooks
Shopify requires every app to handle three mandatory compliance webhooks. We implement all of them:
- customers/data_request - received when a customer asks Shopify for their data. Since we do not store any customer data, we acknowledge the webhook and report no data held.
- customers/redact - received when a customer asks for their data to be deleted. Same as above: no customer data to delete.
- shop/redact - received 48 hours after a merchant uninstalls our app. Triggers full deletion of the merchant record, all generation history, all support messages, and all stored API keys.
10. Children
Our service is intended for use by Shopify merchants, not by children. We do not knowingly collect personal data from anyone under 16. Our content policy expressly prohibits generating images of identifiable minors.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced inside the App and via email to merchants on a paid plan. The "Last updated" date at the top of this page always reflects the most recent revision.
12. Contact
Questions, concerns, or requests about this policy or your data:
- Email: privacy@dreamstate.dk
- Postal: [Legal Entity Name], [Address], [Country]
For data protection concerns specifically, you can also contact your local supervisory authority. A list of EU/EEA authorities is available at edpb.europa.eu.