LEGAL
Privacy Policy
Effective August 5, 2026
This Privacy Policy explains how Faintest Ink, LLC, doing business as Handler (“Handler,” “we,” “us,” or “our”), collects, uses, shares, retains, and deletes information in connection with the Handler Shopify application, the websites at handlerapp.io and app.handlerapp.io, and related support communications.
Handler is a business application intended for Shopify merchants and their authorized staff. It is not intended for consumers acting in their personal capacity.
1. Information Handler processes
Shop and authentication information
When Handler is installed or accessed, we process information needed to identify and authenticate the Shopify store, including:
- The store’s myshopify.com domain and Shopify shop ID.
- Shopify installation, OAuth, session, access-token, and refresh-token information.
- The scopes and permissions granted to Handler.
- Installation, authentication, subscription, and uninstall status.
Authorized Shopify user information
When available through Shopify’s authenticated session, Handler may process information about the staff member using the app, including:
- Shopify user ID.
- First and last name or display name.
- Email address.
- Locale and account-role indicators.
Handler records a limited snapshot of this information with applicable operations so merchants can see which authorized staff member made a change.
Product and redirect information
To provide its handle-auditing, redirect-management, history, and undo features, Handler processes Shopify store information such as:
- Product IDs, titles, handles, images, and publication status.
- Product tags, collections, vendors, and product types.
- URL redirect IDs, paths, targets, and redirect relationships.
- Detected handle conflicts and redirect issues.
- Before-and-after values for changes performed through Handler.
- Pending redirect-review tasks, selected resolutions, and error information.
Activity, history, and recovery information
Handler retains operation and activity records so merchants can review changes, filter history, attribute actions to staff, export records, and restore eligible changes. These records can include product and redirect snapshots, operation summaries, timestamps, results, and associations between an original action and a later restore action.
Plan, catalog, and usage information
Handler processes information needed to administer access and billing, including:
- Selected plan and subscription state.
- Trial start, end, and usage information.
- Billing-period and cancellation status supplied by Shopify.
- Product-catalog count and whether the catalog is eligible for the selected plan.
- Reservation and settlement records used to enforce trial limits safely.
Payment-card and financial-account information is handled by Shopify. Handler does not receive or store merchants’ payment-card numbers.
Support communications
When you contact us, we process the information you provide, such as your name, email address, shop domain, message, screenshots, diagnostic information, and correspondence history.
Technical and diagnostic information
Handler and its service providers may automatically process limited technical information needed to operate and secure the service, including request timestamps, IP addresses, browser or user-agent information, webhook identifiers, API response status, application errors, and security events.
Website and App Store listing analytics
Handler uses Google Analytics 4 on handlerapp.io to understand how visitors find and use the website. Analytics information can include pages viewed, referring sources, campaign information, browser and device characteristics, approximate geographic region, interactions with the website, and first-party analytics identifiers.
Shopify may separately send analytics about Handler’s Shopify App Store listing to a different Google Analytics property. These events can include listing views, Install-button clicks, completed installations, discovery surfaces, search or campaign context, and Shopify shop identifiers associated with a completed installation when supplied by Shopify.
2. Information Handler does not request
Handler is not designed to request or store Shopify customer, order, payment, shipping-address, billing-address, or phone-number data. Handler does not use merchant or staff information for targeted advertising.
3. How we use information
We use the information described above to:
- Authenticate stores and authorized users.
- Audit and edit Shopify product handles.
- Create, update, review, flatten, or delete URL redirects.
- Detect handle collisions and redirect conflicts.
- Provide activity history, staff attribution, exports, and undo.
- Administer plans, trials, billing access, and catalog limits.
- Respond to support, privacy, legal, and security requests.
- Prevent abuse, diagnose errors, and protect the service.
- Measure website and Shopify App Store listing traffic, installations, and marketing performance.
- Comply with legal obligations and Shopify platform requirements.
- Improve the reliability and usability of Handler.
4. When we share information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
We disclose information only as reasonably necessary to operate Handler, including to the following categories of recipients:
- Shopify, which provides the platform, authentication, APIs, billing system, and embedded-app environment.
- Render, which hosts the Handler application and processes application requests and operational logs.
- Neon, which provides the PostgreSQL database used by Handler.
- Cloudflare, which provides domain, DNS, website, security, and email-routing services.
- Google and other email providers, which help us receive, organize, and respond to support and business communications.
- Google Analytics, which helps us measure website usage and Shopify App Store listing discovery and installation activity.
- Professional advisers, regulators, courts, or law-enforcement authorities when disclosure is legally required or reasonably necessary to protect rights, safety, and security.
- A successor or prospective successor in connection with a merger, acquisition, financing, reorganization, or sale of all or part of the business, subject to appropriate confidentiality protections.
Service providers may process information only for the services they provide to us and under their own contractual and legal obligations.
5. Cookies, local storage, and analytics
Handler uses authentication and session technologies that are necessary to provide the application. Shopify may also use technologies required to operate Shopify Admin and embedded applications.
Handler may use browser session storage as a best-effort convenience for preserving an in-progress workflow during same-tab navigation. Handler is designed to continue functioning when browser storage is unavailable.
The Handler website uses Google Analytics 4, which may set first-party analytics cookies or similar identifiers to distinguish visits and measure website activity. Google Signals and advertising personalization are disabled in Handler’s website configuration.
Analytics that Shopify sends from Handler’s Shopify App Store listing is collected on Shopify’s listing surface and is separate from website analytics collected on handlerapp.io.
Handler does not use advertising pixels or session-recording software, and does not use analytics information for targeted advertising or cross-context behavioral advertising.
Visitors can limit analytics collection through browser privacy controls, cookie blocking, or the Google Analytics opt-out browser add-on.
6. Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this policy.
- Shopify authentication sessions are deleted when Handler receives and processes a valid app-uninstall notification.
- Shop-linked activity, history, redirect-task, entitlement, and usage records are deleted when Handler receives and processes Shopify’s shop-redaction request following uninstall.
- Operational application logs are generally retained for no longer than 30 days.
- Support correspondence may be retained for up to 24 months after the last communication so we can maintain context, prevent abuse, and document the resolution of a request.
- Information may be retained longer when reasonably necessary to comply with law, enforce agreements, resolve disputes, investigate abuse, or protect the security of Handler and its users.
Deleted information can remain temporarily in encrypted backups or provider recovery systems until those systems are overwritten according to the provider’s normal retention schedule.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. These include authenticated Shopify sessions, webhook-signature verification, server-side access controls, shop-level data isolation, limited application permissions, encrypted network connections, and access restrictions.
No system can guarantee absolute security. You are responsible for protecting access to your Shopify account and for promptly removing access from staff members who are no longer authorized.
8. International processing
Handler is operated by a United States business. We and our service providers may process information in the United States and other countries where those providers operate. Those countries may have data protection laws that differ from the laws where you live.
9. Your privacy choices and rights
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, or portability relating to personal information about you.
Merchants may also uninstall Handler through Shopify Admin. Shopify’s mandatory privacy-request process remains available for applicable Shopify data.
To submit a request, email [email protected]. Please include the relevant Shopify shop domain and enough information for us to verify and respond to the request. We may need to verify your identity or authority before completing it.
You may also lodge a complaint with the data-protection authority responsible for your jurisdiction.
10. Children
Handler is a business service and is not directed to children. We do not knowingly collect personal information from children through the service.
11. Changes to this policy
We may update this policy as Handler, our providers, or applicable requirements change. We will post the updated policy on this page and revise the effective date above. Material changes may also be communicated through the app or by email when appropriate.
12. Contact us
Faintest Ink, LLC
Handler
United States
- Privacy: [email protected]
- Support: [email protected]
- Legal notices: [email protected]