Sitelet https://github.com/fullbleed-engine/docs/pull/40/files
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
84 changes: 84 additions & 0 deletions docs/commerce/agreements/2026-10-04.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
---
title: Fullbleed Commerce merchant agreement
description: Version 2026-10-04 of Fullbleed Commerce's hosted Shopify service and data-processing terms.
---

<!-- Generated from shopify/agreements/2026-10-04.js; SHA-256 0be84da15030df45e866371168864aa02785b05e3f774efb6f94517d41711fac. Do not hand-edit this version. -->

# Fullbleed Commerce merchant agreement and data-processing terms

Version 2026-10-04.

[Privacy notice](https://docs.fullbleed.dev/commerce/privacy/) · [Contact Fullbleed](mailto:keenan@fullbleed.dev)

## Parties and service

This agreement is between the business operating the Shopify store that accepts it (the merchant, or you) and Keenan Finkelstein, operating Fullbleed in the United States. Contact keenan@fullbleed.dev for support or privacy matters. The person accepting confirms that they can make this agreement for the merchant.

Fullbleed Commerce formats authorized Shopify order data into order summaries and packing slips. It provides saved branding, editable templates, document activity, plan allowances and merchant-enabled Shopify Flow actions with temporary download links. You control which documents are requested, your templates, your workflows and who receives a link. Review documents before relying on them; the service does not calculate taxes, determine legal invoice requirements or supply legal advice.

This agreement covers the hosted Shopify app. It does not change the licenses of the Fullbleed engine, the free local WooCommerce plugin or other separately licensed software.

## Current preview and plan approval

The current hosted service is a development preview for synthetic test stores. Production merchant admission is closed. Use fictional orders only. The preview can be stopped between attended tests, so it is unsuitable for a live store or time-critical workflow. Accepting this agreement does not enable production access.

Agreement acceptance does not purchase a plan or authorize a charge. Paid plan prices, allowance, billing period and any trial are shown and separately approved in Shopify. Shopify manages payment and plan changes. Fullbleed counts each successfully processed order once in its billing period, including previews, automation and downloads; failures do not count. Reprints in the same period share that unit. Unused units do not roll over and Fullbleed does not add overage charges.

You can manage your plan in Shopify and end use by uninstalling the app. Contact support about service or billing problems. Refunds or other remedies required by applicable law remain available. Production availability and any additional commitments must be established before production admission opens.

## Instructions and responsibility for store data

Your authorized document requests, saved settings, enabled Flow actions and privacy instructions direct the processing described here. Where data-protection law uses these roles, you are the controller of customer data and Fullbleed acts as your processor for this service. If you act for another controller, obtain its authority for these instructions and the providers described below.

You remain responsible for the store’s notices, lawful grounds, any required customer permissions, accuracy of source data and permitted recipients. Provide only data needed for the document. Do not paste customer details into saved templates or branding; use the app’s data fields. Fullbleed will flag an instruction it believes is unlawful and suspend the affected processing while it is resolved. If law requires different processing, Fullbleed will tell you beforehand unless that disclosure is legally prohibited.

## Processing covered by this agreement

The people concerned are store customers and document recipients, plus staff who authorize and operate the app. Processing includes retrieving selected orders, assembling and rendering documents in memory, serving authorized downloads, recording limited workflow and access metadata, and carrying out access and deletion requests.

Document processing uses order identifiers, line items, prices, totals, timestamps, and billing and shipping names and addresses. Order contents and generated PDFs are not stored in the application database. Saved data consists of Shopify authorization sessions, branding and templates, automation metadata, billing-period usage, customer privacy-request records, access history and the latest agreement receipt. The receipt contains the store, agreement version and document hash, acceptance time and verified staff ID; it does not include an IP address or order details.

Fullbleed uses this data to deliver and secure the stated service, manage access and allowances, and handle privacy requests. It does not sell the data, use it for advertising, build customer profiles or train AI models with it. Support messages and the operator’s own business records are handled for their stated support or administration purpose; avoid sending customer data, access tokens or complete private links by email.

## Providers and locations

Railway provides the preview’s hosting, private application volume and independent encrypted recovery bucket in the United States. You authorize that processing for this service. Shopify supplies your authorized order data and runs app authentication, Flow and billing under its own agreements with you.

Before a new or replacement provider processes your data, Fullbleed will identify its role and location, provide notice and an opportunity to object on data-protection grounds, and arrange equivalent protection in its provider agreement. An unresolved objection permits you to stop the affected service and request deletion. Fullbleed remains responsible to you for its providers’ performance of these processing duties.

US hosting is not itself an international-transfer safeguard. Production processing subject to restricted-transfer requirements must wait until the applicable transfer arrangement is documented with you. This agreement does not assert Data Privacy Framework certification, signed standard contractual clauses, or approval of an international transfer.

## Security and confidentiality

Fullbleed will restrict access to authorized people and service processes, require confidentiality, use encrypted network connections, restrict the database volume and separately encrypt recovery copies. Operator accounts use unique passwords and two-factor authentication. Application access history and encrypted maintenance records support review and incident investigation. The privacy notice explains what these records contain.

Keep your Shopify staff access and downloaded files secure. Anyone holding a complete private document link can use it while valid. Revoking or expiring a link stops future access through that link; it cannot remove a copy already downloaded to another device. Fullbleed does not send documents to customers on your behalf; any sharing or messaging step you add to a workflow is your instruction to that service.

## Access requests, incidents and assistance

The app makes customer-data exports and their response deadlines available in Privacy requests without a paid plan. You send the response through your store’s privacy process and mark it handled. Fullbleed will assist with applicable access, correction, deletion and other data rights within the data it holds, and with security assessments, impact assessments and regulator inquiries concerning this processing.

Fullbleed will notify the affected merchant without undue delay after becoming aware of a personal-data breach, provide available facts needed for the merchant’s response, contain and investigate it, and give further information as it becomes available. Fullbleed also follows Shopify’s incident-reporting requirements. These commitments do not imply that an incident has occurred or that the app has independent security certification.

On a reasonable request, Fullbleed will provide information needed to assess these processing commitments and cooperate with appropriate audits or inspections. Arrangements must protect other merchants’ data, credentials and confidential systems. Neither party’s direct duties under applicable data-protection law are removed by this agreement.

## Retention and ending processing

Sessions, branding, templates and the latest agreement receipt remain while needed for the installed service, until replaced or deleted through the available controls, or until uninstall or shop erasure is processed. Automation and access history expire after 30 days. Plan-usage references last for the billing period plus 30 days. Customer erasure removes the related order references sooner. Completed privacy-request receipts last 30 days without the export, customer identity hashes or order references.

Outstanding customer-data exports remain until you mark the request handled or an erasure request clears them; overdue requests require action. On ending the service, you may request a machine-readable return of retained data before deletion. An authenticated uninstall or shop-erasure notification clears the store’s live application records. Fullbleed will remove remaining merchant data when it is no longer needed and within the applicable deletion deadline, except where law requires retention; any legally retained data stays restricted to that purpose.

Encrypted backups cannot be restored after seven days and are scheduled for deletion after eight. Erasure and completion instructions expire after eight days after their changes are applied. Restores preserve deletion decisions and clear sessions and active automation authorizations. Maintenance receipts expire after 30 days and contain no customer or order references. Dataset and recovery-policy markers contain no customer or order references.

Cleanup runs at startup and hourly while the service is running. Downtime delays physical removal, including during the stopped development preview. Hosting connection logs follow the provider’s policy, described in the privacy notice; seven days of visible logs is not a promise that older logs are physically deleted. Continuous cleanup, provider arrangements, independent key recovery and production monitoring must be verified before real merchant data is admitted.

## Shopify’s role

Keenan Finkelstein is responsible for supplying, operating and supporting Fullbleed Commerce, including its handling of merchant data and liabilities arising from the app. Shopify does not take responsibility for app defects or losses caused by installing or using it. Unless Shopify expressly offers otherwise, seek app installation and usage help from Fullbleed. Your separate Shopify agreements continue to apply.

## Changes and acceptance record

Published agreement versions are kept available at their versioned address. Changes requiring new agreement are presented for acceptance before document processing continues. Your Shopify pricing approval remains a separate step. You may decline and stop using the service; privacy-request access remains available while the app is installed.

The latest receipt records agreement for this store, not consent on behalf of individual customers. It is replaced when a later version is accepted and is removed with the store’s records after uninstall or shop erasure. Contact keenan@fullbleed.dev for a copy, correction, processing instructions or questions about these terms.
7 changes: 7 additions & 0 deletions docs/commerce/privacy.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ Fullbleed Commerce is maintained by Keenan Finkelstein in the United States.
Contact [keenan@fullbleed.dev](mailto:keenan@fullbleed.dev) about privacy, access,
correction, deletion, or support.

The [merchant agreement](agreements/2026-10-04.md) describes the hosted service
and processing instructions. The app asks an authorized staff member to accept
the current version before document processing. Acceptance and any Shopify
plan approval are separate steps. Privacy requests and access history remain
available without accepting the agreement or buying a plan.

This notice covers the hosted Shopify integration. The separate
[free WooCommerce plugin](../guides/woocommerce.md) renders locally in the
merchant's browser without sending orders to a Fullbleed service.
Expand Down Expand Up @@ -88,6 +94,7 @@ restoration and deletion process below.
| Information | Retention in the live application database |
| --- | --- |
| Authorization, branding, and saved templates | Until replaced or deleted where the app offers that action, or until an authenticated uninstall or shop-erasure notification is processed. |
| Latest merchant-agreement receipt | Store, agreement version and document hash, acceptance time, and verified Shopify staff ID. Replaced by later acceptance; removed on uninstall or shop erasure. No IP address or order details are recorded in the receipt. |
| Automation job history | 30 days. Customer erasure revokes affected links and clears order references and verification hashes. Empty action-run records can remain for up to 30 days to prevent delayed retries from recreating a document. |
| Plan usage | The billing period plus 30 days. Customer erasure removes affected order references while retaining the period's aggregate count. Uninstall and shop erasure remove all of the store's usage records. |
| Outstanding customer-data exports | Until the merchant marks the request handled or Shopify requests erasure. Overdue requests remain visible and require action. |
Expand Down
1 change: 1 addition & 0 deletions mkdocs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -106,4 +106,5 @@ nav:
- Contribute and support: support.md
- Commerce:
- Shopify preview: commerce/shopify.md
- Merchant agreement: commerce/agreements/2026-10-04.md
- Privacy: commerce/privacy.md
Loading