Craftbench
Privacy policy
Last updated 17 September 2026
Who this covers
Craftbench is an app for Shopify merchants. This policy explains what data the app reads from a merchant's store, what it keeps, and for how long. It applies to every store with Craftbench installed.
What the app reads from your store
Craftbench requests two Shopify permissions and no others: read_orders and read_products. It never requests permission to modify anything in your store.
From your unfulfilled orders, the app reads:
- Order number and the date the order was placed
- Product title, SKU, quantity, and product image
- The customisation properties a buyer entered at checkout (line item properties)
What the app deliberately does not read
Craftbench does not request, display, or store customer names, shipping or billing addresses, email addresses, or phone numbers. These fields are excluded from the app's queries by design, which is why the app cannot produce packing slips, shipping labels, or fulfilments.
Buyer-entered customisation text is shown as the buyer wrote it. If a buyer types personal information into a customisation field, that text will appear on the production board, because it is part of the instruction needed to make the item.
What the app stores
Kept in Craftbench's own database:
- Your store's domain
- The access token Shopify issues at installation, used to read orders on your behalf
- The production status you set for each item (pending, in progress, or done), and any deadline you set by hand, stored against Shopify's internal order and line item identifiers
- If you use the Proofs feature: the line item details and customisation values you chose to include in a proof, any note you wrote for the customer, and the proof's current status
Order contents are otherwise not stored or cached. Every time you open the production board, the app reads the current orders from Shopify and discards them when the page is rendered.
Proof approval links
Proofs lets you generate a link for one order's personalised items, so your customer can approve them or request changes without creating an account. We do not ask the customer for their name, email, or any other identifying detail to do this.
If a customer chooses to type a note when requesting changes, that text is stored so you can see it in the app. We do not ask for personal information there either, but nothing stops a customer writing some into free text they control — the same way it could end up in a customisation field, described above.
The link itself is a long random value. Only a one-way hash of it is stored in our database, never the link a customer can actually use, so a copy of our database on its own could not be used to open anyone's proof.
Sharing
Craftbench does not sell data, does not share it with advertisers or analytics providers, and does not transfer it to any third party. The only parties involved are Shopify and the hosting and database providers that run the app.
Security
All traffic between your store, your browser, and Craftbench is encrypted in transit using HTTPS. Stored data is encrypted at rest by the database provider. Access to production systems is limited to the app's developer.
Retention and deletion
When you uninstall Craftbench, your session is removed immediately. Shopify then sends a shop redaction request, normally 48 hours after uninstall, and at that point every record belonging to your store — production statuses, deadlines, and Proofs — is deleted. The delay exists so that reinstalling within two days does not lose your work.
Craftbench also handles Shopify's customer data request and customer redaction webhooks. The app stores no customer identity, so there is no personal data to return in response to a data request. For a redaction request, if a customer's order has an associated proof, we clear that proof's change-request note; everything else about the order is unaffected.
Your rights
Depending on where you are located, you may have the right to access, correct, export, or delete personal data held about you. Uninstalling the app triggers deletion as described above. For anything else, contact us at the address below.
Changes
If this policy changes, the updated version will be published on this page with a new date at the top.
Contact
Questions about this policy or about the data Craftbench handles: teamomo.apps@gmail.com