Privacy Policy
Last updated: May 29, 2026
This Privacy Policy explains how PrintReactor, LLC ("PrintReactor", "we", "us", or "our") collects, uses, discloses, and protects personal information. It covers our marketing website at printreactor.com, our product websites (including StickerFlow), and the software services we provide to merchants (collectively, the "Services").
PrintReactor is headquartered in Sacramento, California, USA. We operate internationally and this Policy is written to reflect our obligations under the EU and UK General Data Protection Regulations (GDPR / UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), other US state privacy laws, Canada's PIPEDA and Quebec's Law 25, Brazil's LGPD, and the Australian Privacy Act.
1. Our role: controller vs. processor
PrintReactor plays two different roles depending on whose data is involved:
- Controller: for data we collect directly, including information from merchants who sign up for our Services, prospective customers, website visitors, applicants, and our own marketing and billing records.
- Processor: for personal information that our merchant customers ("Merchants") submit to the Services about their own end-customers (for example, a shopper who places an order on a Merchant's storefront). In that relationship, the Merchant is the controller and we process the data on their documented instructions under our Data Processing Addendum. If you are an end-customer of a Merchant and have questions about your data, please contact that Merchant directly; they are the controller of that information.
2. Information we collect
2.1 Information you provide
- Account: name, business name, email, phone (optional), password hash, role.
- Billing: billing address, tax ID, and payment identifiers returned by our payment processor. We do not store full card numbers.
- Merchant configuration: store URLs, API credentials for connected platforms (Shopify, WooCommerce, Etsy, custom), material libraries, price lists, production settings.
- Content: artwork, designs, proofs, order files, and related metadata that you or your end-customers upload.
- Support and communications: messages you send to us, survey responses, beta feedback, and call recordings (with notice and where permitted).
- Beta application data: the information submitted through our beta application form, including store URL, sticker volume, sales channels, and open-text answers.
- Newsletter and marketing sign-ups: if you subscribe to our newsletter or tick a marketing opt-in, we record your email address, the fact and time of your consent, and your subscription status. You can unsubscribe at any time using the link in our emails.
2.2 Information collected automatically
- Product telemetry: feature usage, error logs, performance metrics tied to your Merchant account.
- Server logs: IP address, user agent, request timestamps, referer.
- Marketing-site analytics: with your consent, we use Google Analytics 4 (aggregate traffic) and Microsoft Clarity (heatmaps and anonymized session recordings). These load only after you opt in where consent is required, and you can change your choice from the "Cookie settings" link in the footer. See our Cookie Policy.
2.3 Information from third parties
- Connected platforms: when you authorize a connection to Shopify, WooCommerce, Etsy, or another platform, we receive the data scopes you grant (orders, products, customers, fulfillment).
- Payment processor: tokenized payment status and limited transaction metadata from Stripe.
- Identity & fraud: limited signals from anti-fraud vendors and email verification services.
3. Sensitive personal information
We do not knowingly collect "sensitive personal information" as defined under CCPA/CPRA or equivalent categories under GDPR Article 9 (such as precise geolocation, biometric identifiers, racial or ethnic origin, political opinions, health data, or union membership). We do not use or disclose any personal information we collect for purposes other than those described in this Policy, and we do not use sensitive personal information to infer characteristics about you. Accordingly, we are not required to offer a "Limit the Use of My Sensitive Personal Information" link; if our practices change, we will update this Policy and post that link on our homepage.
4. How we use information (purposes and legal bases)
| Purpose | GDPR legal basis |
|---|---|
| Provide, maintain, and operate the Services for you | Contract (Art. 6(1)(b)) |
| Process payments and prevent fraud | Contract; Legal obligation (Art. 6(1)(b), 6(1)(c)) |
| Respond to support requests and communicate service updates | Contract; Legitimate interest (Art. 6(1)(f)) |
| Improve the Services, debug, and measure performance | Legitimate interest (Art. 6(1)(f)) |
| Measure traffic and on-site behavior via cookie-based analytics (Google Analytics 4, Microsoft Clarity) | Consent (Art. 6(1)(a)) where required for cookies |
| Send marketing or newsletter emails about PrintReactor products | Consent or Legitimate interest, depending on jurisdiction (Art. 6(1)(a) or (f)) |
| Comply with law, respond to lawful requests, protect rights | Legal obligation; Legitimate interest (Art. 6(1)(c), (f)) |
We will not use your personal information for a materially different, unrelated, or incompatible purpose without providing you notice and, where required, obtaining your consent.
5. Automated decision-making and AI
The Services include features that use machine-learning models, for example automated cutline generation, artwork-quality scoring, and gang-sheet packing. These features assist and accelerate decisions made by you and your production staff. They do not produce legal or similarly significant effects about individual end-customers for the purposes of GDPR Article 22. Human review is always available: Merchants can override any automated output before production. We do not sell models that profile individuals, and we do not train third-party foundation models on your Content without your explicit written consent.
6. How we share information
We do not sell personal information. We disclose it only to the following categories of recipients:
- Service providers and processors under written agreements: cloud hosting and content delivery, form and email delivery, bot protection, and payment processing. A current list is published at /subprocessors.
- Analytics and session-behavior providers: Google LLC (Google Analytics 4) acts as our processor; Microsoft (Clarity) acts as an independent controller that may use the data for its own purposes, including advertising. Both process data in the United States, and these tools run only with your consent. See our Cookie Policy.
- Connected platforms you authorize (Shopify, WooCommerce, Etsy, custom), limited to what is necessary to provide the integration.
- Professional advisors (lawyers, accountants, auditors) under duties of confidentiality.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to customary confidentiality and to the survival of your rights under this Policy.
- Legal and safety: to comply with law, respond to valid legal process, enforce our agreements, and protect the rights, property, or safety of PrintReactor, our users, or others.
7. International data transfers
PrintReactor is based in the United States and our primary infrastructure is located in the United States. When we transfer personal information from the European Economic Area, United Kingdom, Switzerland, or other regions with data-transfer rules, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum. Where available, we rely on the EU-US Data Privacy Framework and the UK Extension. You may request a copy of the safeguards that apply to a specific transfer by contacting [email protected].
8. Retention
| Data type | Retention |
|---|---|
| Active account records | For the life of the account |
| Cancelled accounts (most data) | Deleted or anonymized within 90 days of cancellation |
| Billing and tax records | Up to 7 years, as required by applicable tax and accounting law |
| Support communications | Up to 3 years after your last interaction |
| Server and security logs | Up to 12 months |
| Encrypted backups | Rolling 35 days; personal information is purged from backups within that window after deletion requests |
| Marketing preferences | Until you opt out plus a reasonable suppression record |
9. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, least-privilege access controls, multi-factor authentication for administrative access, code review, and dependency scanning. As the Service matures we continue to expand these measures, including formal third-party penetration testing and a documented, tested incident-response program. No system is perfectly secure; please use a strong, unique password and notify us promptly if you suspect an account compromise at [email protected].
10. Your rights
Depending on where you live, you may have some or all of the following rights. We honor them regardless of where you reside, to the extent it is practical for us to do so:
- Know / access: what personal information we hold and how we use it.
- Correct: request rectification of inaccurate or incomplete information.
- Delete: request deletion of your personal information, subject to legal exceptions.
- Port: receive a copy of data you provided us in a structured, commonly used, machine-readable format.
- Object or restrict: object to certain processing based on legitimate interests, or restrict processing in specified circumstances.
- Withdraw consent: withdraw any consent you have given, without affecting processing before withdrawal.
- Non-discrimination: not be retaliated against for exercising your rights.
- Opt out of "sale" or "sharing": under CCPA and similar laws. We do not sell personal information for money. We keep advertising features off in our analytics, so we do not use them for cross-context behavioral advertising; if any such processing were ever treated as "sharing," you can opt out, and we honor Global Privacy Control (GPC) signals as a valid opt-out.
- Opt out of targeted advertising / profiling with significant effects: under various US state laws. We do not use your personal information for targeted advertising or profiling that produces significant effects. You can also turn off analytics and session-behavior tools at any time from our cookie banner.
- Appeal: if we deny a request, residents of Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia (among others) may appeal by replying to our response.
To exercise any right, email [email protected] from the address associated with your account, or reach us through our contact form. We will verify your request and respond within the timeline required by applicable law (typically 30 to 45 days, extendable where permitted). You may use an authorized agent; we may need to verify the agent's authority.
If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection authority. If you are in Quebec, you have the right to complain to the Commission d'accès à l'information (CAI).
11. Children
The Services are intended for business users aged 18 or older. We do not knowingly collect personal information from children under 16. If you believe we have collected information from a child, please contact us and we will delete it. Under the California regulations effective January 1, 2026, information of consumers under 16 is treated as sensitive personal information when collected.
12. Cookies and tracking
We use strictly necessary cookies for our logged-in application. On our marketing site, analytics (Google Analytics 4) and session-behavior tools (Microsoft Clarity) set non-essential cookies and run only after you consent through our cookie banner, where consent is required. We do not run our own advertising or cross-site ad cookies. See the Cookie Policy for the current list, the third-party recipients, and how Global Privacy Control and browser-level controls apply.
13. Third-party sites
Our websites and product may link to or interoperate with third-party sites and services (for example, a Merchant's Shopify store). Those services are governed by their own privacy policies. We are not responsible for the privacy practices of third parties.
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will post an updated version on this page with a new "Last updated" date and, where required, notify you by email or in-product notice. Continued use of the Services after changes take effect constitutes acceptance.
15. Contact us
PrintReactor, LLC
901 H St Ste 120
Sacramento, CA 95814, USA
Privacy and data protection: [email protected]
Security: [email protected]
EU / UK representatives
Where required by GDPR Article 27 or UK GDPR, we will appoint a representative in the EU and UK and publish their contact details here. If you need this information urgently, email [email protected].