Privacy Policy
Last updated: August 21, 2026
1. Who We Are and Our Roles
DTF Checkout (dtfcheckout.com) is operated by [DTF Checkout legal entity] ("we", "us"). We provide hosted storefront, checkout and order-management software to DTF print shops ("shops"). This policy explains what personal information we handle and why. Which role we play depends on who you are:
- Shop owners and staff who sign up for the Service: we decide how your account and billing information is used, so we are the controller (or "business") for it.
- Customers of a shop — you placed an order on a storefront that runs on DTF Checkout: the shop is the business you bought from and it decides how your information is used. We process your information on the shop's behalf as a processor (or "service provider"), under our agreement with the shop. Contact the shop first with any question about your order or your data; its contact details are in its storefront footer. We help shops answer requests and forward any request we receive directly.
- Visitors to dtfcheckout.com: we are the controller for the little we collect about you (section 2).
2. Information We Collect
- Shop accounts: the owner's and each staff user's name, email address and password (stored as a bcrypt hash, never in plain text), and role.
- Shop settings and branding: shop name, subdomain or custom domain, logo, colours, business address, timezone, prices, tax and shipping settings, policies and email settings.
- Billing: your subscription status and Stripe customer and subscription identifiers, plus the card brand and last four digits Stripe gives us. Your card number goes to Stripe; it never touches our servers.
- Credentials you give us: your Stripe keys and the keys or OAuth tokens for integrations you connect. They are stored encrypted.
- Shop customers' information (processed on the shop's behalf): name, company, email, phone, billing and shipping addresses, password hash, account type and discount, order history and the notes a shop keeps about a customer.
- Artwork and files: the artwork customers upload, the thumbnails and checks we derive from it, and the production files we build from it.
- Technical data: IP address, browser and device information, the pages and actions requested, and error reports. These logs are kept for about 14 days.
- Messages you send us, for example to our support mailbox.
3. How We Use Information
- to provide the Service: run storefronts, process uploads and orders, build production files, and give shops their admin;
- to bill shops for their subscription and handle trials, tier changes, failed payments and cancellations;
- to send transactional email — order confirmations and status updates, password-reset links, billing and security notices;
- to keep the Service secure: sign-in, rate limiting, abuse and fraud prevention, and investigating incidents;
- to give support and fix problems, including diagnosing errors;
- to comply with law and enforce our Terms; and
- to understand how the Service is used so we can improve it.
We do not sell personal information, we do not build advertising profiles, and we do not show ads. The only AI use in the Service is the optional "Match my site with AI" button on a shop's branding tab, which sends the shop's own public website to Anthropic to suggest brand colours; no customer data is sent.
4. Legal Bases (EU and UK)
If you are in the European Economic Area or the United Kingdom, we rely on: performance of our contract with you (providing and billing the Service); our legitimate interests (security, preventing abuse, support, improving the Service) where they are not overridden by your rights; compliance with legal obligations (tax and accounting records); and your consent where the law requires it, which you can withdraw at any time. For a shop's customers, the shop is responsible for its own legal basis.
5. Cookies
We set only strictly necessary cookies: a session cookie so you stay signed in (on a storefront it also keeps your cart) and a CSRF token that protects forms. They are set per host, so a cookie for one shop is not visible to another. We set no advertising or analytics cookies of our own, and blocking ours may stop parts of the Service from working.
A shop may add its own analytics and advertising pixels (Google Analytics and Ads, Meta, TikTok) and custom scripts to its storefront. Those are the shop's, are governed by the shop's and the provider's policies, and may set their own cookies — check the shop's privacy policy. Some forms are protected by Cloudflare Turnstile, which uses technical signals to tell people from bots.
6. Sharing and Sub-processors
We share information only with the providers below, who process it for us under contract, and otherwise only when the law requires it, to protect the Service and its users, or if our business is sold or merged (in which case this policy continues to apply). Our sub-processors are:
- Stripe — subscription billing on our account; and the checkout on each shop's storefront, which runs on the shop's own Stripe account;
- Cloudflare — R2 object storage for uploaded files, and Turnstile bot protection on forms;
- Resend — transactional email;
- our hosting provider — the servers and database, in a United States data centre;
- Anthropic — only the shop's own public website, and only when a shop clicks "Match my site with AI"; no customer data is sent.
7. Integrations a Shop Connects
A shop can connect its own accounts with ShipStation, Dropbox, Google Drive, Mailchimp, Klaviyo, QuickBooks, Slack and Twilio (SMS), and can point its own webhooks at order events. When it does, we send order and customer data to that service at the shop's direction — for example a shipping address to ShipStation, or artwork files to Dropbox. Each of those services is chosen by the shop, holds the data under its own terms, and is outside our control. Ask the shop which integrations it uses.
8. Data Retention
- Artwork that is uploaded but never attached to an order is removed after about 48 hours.
- Artwork on a placed order is kept for 60 days from the order date so the order can be reordered. After that it is eligible for deletion: it may be deleted at any time after the 60 days, and is deleted on request.
- Order records stay with the shop for its business and tax records.
- Shop account and billing records are kept for the life of the account plus 60 days after the subscription ends, so the shop can reactivate, and longer where the law requires. After that the shop's data is eligible for deletion.
- Technical logs are kept for about 14 days.
9. Security
All traffic is encrypted in transit with TLS. Stripe keys and integration credentials are encrypted at rest. Passwords are stored as bcrypt hashes. Uploaded files live in private storage and are served only through short-lived signed links. Every shop's data is isolated from every other shop's by design. Our staff can sign in to a shop's admin to give support; every such sign-in is logged. No system is perfectly secure — if you believe you have found a security problem, email us at the address in section 14.
10. Your Rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict some processing, and to opt out of sale (we do not sell). How to exercise them, what deletion means for a shop, and notes for California, EU and UK residents are on our Your Data Rights page. If you are a shop's customer, start with the shop.
11. Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect information from them; if we learn that we have, we delete it.
12. International Transfers
We are based in the United States and the Service is hosted there. If you use it from elsewhere, your information is transferred to and processed in the United States, where privacy law may differ from your country's. Where the law requires a transfer mechanism, we rely on one it recognises [counsel to confirm which — e.g. standard contractual clauses].
13. Changes to This Policy
We may update this policy from time to time. When we do, we change the date at the top of this page, and we email shop owners before a material change takes effect.
14. Contact
Privacy questions and data requests go to info@dtfcheckout.com. The Service is operated by [DTF Checkout legal entity].