Fullbleed Commerce merchant agreement and data-processing terms¶
Version 2026-10-04.
Privacy notice · Contact Fullbleed
Parties and service¶
This agreement is between the business operating the Shopify store that accepts it (the merchant, or you) and Keenan Finkelstein, operating Fullbleed in the United States. Contact keenan@fullbleed.dev for support or privacy matters. The person accepting confirms that they can make this agreement for the merchant.
Fullbleed Commerce formats authorized Shopify order data into order summaries and packing slips. It provides saved branding, editable templates, document activity, plan allowances and merchant-enabled Shopify Flow actions with temporary download links. You control which documents are requested, your templates, your workflows and who receives a link. Review documents before relying on them; the service does not calculate taxes, determine legal invoice requirements or supply legal advice.
This agreement covers the hosted Shopify app. It does not change the licenses of the Fullbleed engine, the free local WooCommerce plugin or other separately licensed software.
Current preview and plan approval¶
The current hosted service is a development preview for synthetic test stores. Production merchant admission is closed. Use fictional orders only. The preview can be stopped between attended tests, so it is unsuitable for a live store or time-critical workflow. Accepting this agreement does not enable production access.
Agreement acceptance does not purchase a plan or authorize a charge. Paid plan prices, allowance, billing period and any trial are shown and separately approved in Shopify. Shopify manages payment and plan changes. Fullbleed counts each successfully processed order once in its billing period, including previews, automation and downloads; failures do not count. Reprints in the same period share that unit. Unused units do not roll over and Fullbleed does not add overage charges.
You can manage your plan in Shopify and end use by uninstalling the app. Contact support about service or billing problems. Refunds or other remedies required by applicable law remain available. Production availability and any additional commitments must be established before production admission opens.
Instructions and responsibility for store data¶
Your authorized document requests, saved settings, enabled Flow actions and privacy instructions direct the processing described here. Where data-protection law uses these roles, you are the controller of customer data and Fullbleed acts as your processor for this service. If you act for another controller, obtain its authority for these instructions and the providers described below.
You remain responsible for the store’s notices, lawful grounds, any required customer permissions, accuracy of source data and permitted recipients. Provide only data needed for the document. Do not paste customer details into saved templates or branding; use the app’s data fields. Fullbleed will flag an instruction it believes is unlawful and suspend the affected processing while it is resolved. If law requires different processing, Fullbleed will tell you beforehand unless that disclosure is legally prohibited.
Processing covered by this agreement¶
The people concerned are store customers and document recipients, plus staff who authorize and operate the app. Processing includes retrieving selected orders, assembling and rendering documents in memory, serving authorized downloads, recording limited workflow and access metadata, and carrying out access and deletion requests.
Document processing uses order identifiers, line items, prices, totals, timestamps, and billing and shipping names and addresses. Order contents and generated PDFs are not stored in the application database. Saved data consists of Shopify authorization sessions, branding and templates, automation metadata, billing-period usage, customer privacy-request records, access history and the latest agreement receipt. The receipt contains the store, agreement version and document hash, acceptance time and verified staff ID; it does not include an IP address or order details.
Fullbleed uses this data to deliver and secure the stated service, manage access and allowances, and handle privacy requests. It does not sell the data, use it for advertising, build customer profiles or train AI models with it. Support messages and the operator’s own business records are handled for their stated support or administration purpose; avoid sending customer data, access tokens or complete private links by email.
Providers and locations¶
Railway provides the preview’s hosting, private application volume and independent encrypted recovery bucket in the United States. You authorize that processing for this service. Shopify supplies your authorized order data and runs app authentication, Flow and billing under its own agreements with you.
Before a new or replacement provider processes your data, Fullbleed will identify its role and location, provide notice and an opportunity to object on data-protection grounds, and arrange equivalent protection in its provider agreement. An unresolved objection permits you to stop the affected service and request deletion. Fullbleed remains responsible to you for its providers’ performance of these processing duties.
US hosting is not itself an international-transfer safeguard. Production processing subject to restricted-transfer requirements must wait until the applicable transfer arrangement is documented with you. This agreement does not assert Data Privacy Framework certification, signed standard contractual clauses, or approval of an international transfer.
Security and confidentiality¶
Fullbleed will restrict access to authorized people and service processes, require confidentiality, use encrypted network connections, restrict the database volume and separately encrypt recovery copies. Operator accounts use unique passwords and two-factor authentication. Application access history and encrypted maintenance records support review and incident investigation. The privacy notice explains what these records contain.
Keep your Shopify staff access and downloaded files secure. Anyone holding a complete private document link can use it while valid. Revoking or expiring a link stops future access through that link; it cannot remove a copy already downloaded to another device. Fullbleed does not send documents to customers on your behalf; any sharing or messaging step you add to a workflow is your instruction to that service.
Access requests, incidents and assistance¶
The app makes customer-data exports and their response deadlines available in Privacy requests without a paid plan. You send the response through your store’s privacy process and mark it handled. Fullbleed will assist with applicable access, correction, deletion and other data rights within the data it holds, and with security assessments, impact assessments and regulator inquiries concerning this processing.
Fullbleed will notify the affected merchant without undue delay after becoming aware of a personal-data breach, provide available facts needed for the merchant’s response, contain and investigate it, and give further information as it becomes available. Fullbleed also follows Shopify’s incident-reporting requirements. These commitments do not imply that an incident has occurred or that the app has independent security certification.
On a reasonable request, Fullbleed will provide information needed to assess these processing commitments and cooperate with appropriate audits or inspections. Arrangements must protect other merchants’ data, credentials and confidential systems. Neither party’s direct duties under applicable data-protection law are removed by this agreement.
Retention and ending processing¶
Sessions, branding, templates and the latest agreement receipt remain while needed for the installed service, until replaced or deleted through the available controls, or until uninstall or shop erasure is processed. Automation and access history expire after 30 days. Plan-usage references last for the billing period plus 30 days. Customer erasure removes the related order references sooner. Completed privacy-request receipts last 30 days without the export, customer identity hashes or order references.
Outstanding customer-data exports remain until you mark the request handled or an erasure request clears them; overdue requests require action. On ending the service, you may request a machine-readable return of retained data before deletion. An authenticated uninstall or shop-erasure notification clears the store’s live application records. Fullbleed will remove remaining merchant data when it is no longer needed and within the applicable deletion deadline, except where law requires retention; any legally retained data stays restricted to that purpose.
Encrypted backups cannot be restored after seven days and are scheduled for deletion after eight. Erasure and completion instructions expire after eight days after their changes are applied. Restores preserve deletion decisions and clear sessions and active automation authorizations. Maintenance receipts expire after 30 days and contain no customer or order references. Dataset and recovery-policy markers contain no customer or order references.
Cleanup runs at startup and hourly while the service is running. Downtime delays physical removal, including during the stopped development preview. Hosting connection logs follow the provider’s policy, described in the privacy notice; seven days of visible logs is not a promise that older logs are physically deleted. Continuous cleanup, provider arrangements, independent key recovery and production monitoring must be verified before real merchant data is admitted.
Shopify’s role¶
Keenan Finkelstein is responsible for supplying, operating and supporting Fullbleed Commerce, including its handling of merchant data and liabilities arising from the app. Shopify does not take responsibility for app defects or losses caused by installing or using it. Unless Shopify expressly offers otherwise, seek app installation and usage help from Fullbleed. Your separate Shopify agreements continue to apply.
Changes and acceptance record¶
Published agreement versions are kept available at their versioned address. Changes requiring new agreement are presented for acceptance before document processing continues. Your Shopify pricing approval remains a separate step. You may decline and stop using the service; privacy-request access remains available while the app is installed.
The latest receipt records agreement for this store, not consent on behalf of individual customers. It is replaced when a later version is accepted and is removed with the store’s records after uninstall or shop erasure. Contact keenan@fullbleed.dev for a copy, correction, processing instructions or questions about these terms.