Privacy Policy
Last updated: 17 August 2026 · Draft pending legal review
What we collect
- Your email address, used to sign you in and to contact you about your account. Sign-in codes are stored only as a keyed hash and expire after ten minutes.
- Your Printify access token, encrypted at rest with AES-256-GCM. It is used only on our servers to call the Printify API, and it is never sent to a browser.
- Your product data: artwork, titles, SKUs, variants, prices, and job history, so batches can be reviewed, retried, and managed.
- Purchase records, being which pack was bought and when. Card details are handled by Stripe and never reach us.
What we do not do
We do not sell your data, use your artwork to train models, or share your product catalog with anyone. We do not use advertising trackers.
Artwork retention
Uploaded artwork is passed to Printify and, depending on your configuration, the original file is deleted from our storage once Printify confirms it has ingested the image. We retain the resulting Printify image reference, a checksum, and dimensions so batches remain reviewable.
Sub-processors
- Printify, for product and catalog operations you initiate
- Stripe, for payment processing
- Resend, for delivery of sign-in code emails
- Supabase, for database and file storage
- PostHog, for product analytics, so we can see which parts of the tool work
Analytics
We record how the product is used: pages viewed, steps completed, batches created, and where people get stuck. Your email address is stored against your analytics profile so we can support you; it is not attached to individual events. We do not record your artwork, product titles, or SKUs in analytics, and we do not use advertising trackers or sell this data.
Your rights
You can ask for a copy of your data, correct it, or have it deleted. Deleting your account removes your stored artwork, product records, and job history from Bulkify; products already created in your Printify account belong to you and stay there. Email support@upcraft.xyz and we will respond within 30 days.
Security
Access tokens are encrypted at rest, sessions use signed HttpOnly cookies, and every request is authenticated before any data is read. Each account's data is isolated at the database layer.
Contact
Privacy questions: support@upcraft.xyz